Latest CVE Feed
-
5.6
MEDIUMCVE-2021-23287
The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issue affects: Intelligent Power Manager (IPM 1) versions prior to 1.70.... Read more
Affected Products : intelligent_power_manager- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2023-21983
Vulnerability in the Application Express Administration product of Oracle Application Express (component: None). Supported versions that are affected are Application Express Administration: 18.2-22.2. Difficult to exploit vulnerability allows unauthentic... Read more
Affected Products : application_express- Published: Jul. 18, 2023
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2021-46778
Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an at... Read more
Affected Products : epyc_7h12_firmware epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware epyc_7552_firmware +349 more products- Published: Aug. 10, 2022
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2024-36501
Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.... Read more
- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2023-43798
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions 2.6.12 and 2.7.0-rc.1 disabled foll... Read more
Affected Products : bigbluebutton- Published: Oct. 30, 2023
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2016-0339
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leveraging knowledge of "traffic records."... Read more
- Published: Jul. 15, 2016
- Modified: Apr. 12, 2025
-
5.6
MEDIUMCVE-2022-32483
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.... Read more
Affected Products : cpg_bios edge_gateway_3000_firmware edge_gateway_5000_firmware embedded_box_pc_3000_firmware alienware_area_51m_r1_firmware alienware_area_51m_r2_firmware alienware_aurora_r11_firmware alienware_aurora_r12_firmware alienware_aurora_r13_firmware alienware_m15_r2_firmware +571 more products- Published: Oct. 12, 2022
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2023-52349
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed... Read more
- Published: Apr. 08, 2024
- Modified: Mar. 28, 2025
-
5.6
MEDIUMCVE-2024-30800
PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.... Read more
Affected Products : px4_drone_autopilot- Published: Apr. 23, 2024
- Modified: Jun. 30, 2025
-
5.6
MEDIUMCVE-2018-10593
A vulnerability in DB Manager version 3.0.1.0 and previous and PerformA version 3.0.0.0 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue ... Read more
- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2018-9056
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (... Read more
Affected Products : core_i3 core_i5 core_i7 xeon_e3 xeon_e3_1220_v5 xeon_e3_1225_v5 xeon_e3_1230_v5 xeon_e3_1235l_v5 xeon_e3_1240_v5 xeon_e3_1240l_v5 +199 more products- Published: Mar. 27, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2025-50986
diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its administrative settings interface. Various configuration fields such as ES_HOST, ES_INDEXREFRESH, ES_PORT, ES_SCROLLSIZE, ES_TRANSLOGSIZE,... Read more
Affected Products : diskover- Published: Aug. 27, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.6
MEDIUMCVE-2025-50985
diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web interface. Unsanitized GET parameters including maxage, maxindex, index, path, q (query), and doctype are directly echoed into the HTML r... Read more
Affected Products : diskover- Published: Aug. 27, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.6
MEDIUMCVE-2025-40929
Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact... Read more
Affected Products :- Published: Sep. 08, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Denial of Service
-
5.6
MEDIUMCVE-2022-2366
Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.... Read more
- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2025-5745
The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc6... Read more
Affected Products : glibc- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2025-5702
The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64... Read more
Affected Products : glibc- Published: Jun. 05, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2025-53489
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - GoogleDocs4MW Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GoogleDocs4MW Extension:... Read more
Affected Products :- Published: Jul. 03, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.6
MEDIUMCVE-2025-52993
A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.... Read more
Affected Products : nix- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Race Condition
-
5.6
MEDIUMCVE-2025-48172
CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes.... Read more
Affected Products : chmlib- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption