Latest CVE Feed
-
5.7
MEDIUMCVE-2017-13317
In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed fo... Read more
Affected Products : android- Published: Jan. 28, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2022-39316
FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it like... Read more
- Published: Nov. 16, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2017-12339
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker cou... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2017-12351
A vulnerability in the guest shell feature of Cisco NX-OS System Software could allow an authenticated, local attacker to read and send packets outside the scope of the guest shell container. An attacker would need valid administrator credentials to perfo... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2024-43784
lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating a new user with the same username a... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
5.7
MEDIUMCVE-2024-42491
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion start... Read more
- Published: Sep. 05, 2024
- Modified: Aug. 26, 2025
-
5.7
MEDIUMCVE-2017-10389
Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: PMS). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows low privileged attacker with logon to the ... Read more
Affected Products : hospitality_suite8- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2017-0936
Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords th... Read more
Affected Products : nextcloud_server- Published: Mar. 28, 2018
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-21236
CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the python package CairoSVG uses two regu... Read more
Affected Products : cairosvg- Published: Jan. 06, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2016-3472
Unspecified vulnerability in the Siebel Engineering - Installer and Deployment component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Web Server.... Read more
- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
5.7
MEDIUMCVE-2021-20844
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote a... Read more
Affected Products : rtx830_firmware nvr510_firmware nvr700w_firmware rtx1210_firmware biz_box_rtx830_firmware biz_box_nvr510_firmware biz_box_nvr700w_firmware biz_box_rtx1210_firmware rtx830 nvr510 +6 more products- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-1708
Windows GDI+ Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +10 more products- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2016-6401
Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, allows remote attackers to cause a denial of service (line-card reload) via crafted IPv6-over-MPLS packets, aka Bug ID CSCva32494.... Read more
Affected Products : carrier_routing_system- Published: Sep. 17, 2016
- Modified: Apr. 12, 2025
-
5.7
MEDIUMCVE-2016-6375
Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to cause a denial of service (device reload) by sending crafted Inter-Access Point Protocol (IAPP) packets an... Read more
- Published: Sep. 12, 2016
- Modified: Apr. 12, 2025
-
5.7
MEDIUMCVE-2016-5947
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.... Read more
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.7
MEDIUMCVE-2024-2193
A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from ... Read more
Affected Products : xen- Published: Mar. 15, 2024
- Modified: Apr. 30, 2025
-
5.7
MEDIUMCVE-2023-51589
BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interactio... Read more
Affected Products : bluez- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
5.7
MEDIUMCVE-2016-3037
IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticated attacker with user interaction could obtain this sensitive information. IBM X-Force ID: 114613.... Read more
Affected Products : cognos_business_intelligence- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2022-23504
TYPO3 is an open source PHP based web content management system. Versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are subject to Sensitive Information Disclosure. Due to the lack of handling user-submitted YAML placeholder expressions in the site co... Read more
Affected Products : typo3- Published: Dec. 14, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2024-37895
Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their own attack URL on the frontend and s... Read more
Affected Products : lobe_chat- Published: Jun. 17, 2024
- Modified: Nov. 21, 2024