Latest CVE Feed
-
5.6
MEDIUMCVE-2022-22713
Windows Hyper-V Denial of Service Vulnerability... Read more
Affected Products : windows_10 windows_server windows_10_21h2 windows windows_10_21h1 windows_server_20h2- Published: May. 10, 2022
- Modified: Jan. 02, 2025
-
5.6
MEDIUMCVE-2022-21239
Out-of-bounds read in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products : quickassist_technology- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2022-1172
Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.... Read more
Affected Products : gpac- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2021-43246
Windows Hyper-V Denial of Service Vulnerability... Read more
Affected Products : windows_10 windows_server_2016 windows_server_2019 windows_server windows_10_1809 windows_10_21h2 windows_server_2022 windows_11_21h2 windows_10_21h1 windows_10_1909 +2 more products- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2025-7396
In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding configure option is only for the base C implementation of Curve25519. It is not needed, or available with; ARM assembly builds, Intel assem... Read more
Affected Products : wolfssl- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
-
5.6
MEDIUMCVE-2024-35195
Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verificati... Read more
Affected Products :- Published: May. 20, 2024
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2023-3301
A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause ... Read more
- Published: Sep. 13, 2023
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2023-26554
mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a '\0' character. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.... Read more
Affected Products : ntp- Published: Apr. 11, 2023
- Modified: Feb. 11, 2025
-
5.6
MEDIUMCVE-2023-26552
mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a decimal point. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.... Read more
Affected Products : ntp- Published: Apr. 11, 2023
- Modified: Feb. 11, 2025
-
5.6
MEDIUMCVE-2018-12130
Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacte... Read more
- Published: May. 30, 2019
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2021-26401
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.... Read more
Affected Products : epyc_7h12_firmware epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware epyc_7552_firmware +243 more products- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2018-0888
The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2024-36357
A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.... Read more
Affected Products :- Published: Jul. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
5.6
MEDIUMCVE-2024-36350
A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.... Read more
Affected Products :- Published: Jul. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
5.6
MEDIUMCVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.... Read more
Affected Products : ubuntu_linux debian_linux hci_management_node solidfire vm_virtualbox communications_diameter_signaling_router core_i3 core_i5 core_i7 xeon_e3 +211 more products- Published: Jan. 04, 2018
- Modified: May. 06, 2025
-
5.6
MEDIUMCVE-2020-8833
Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible privilege escalation opportunity. If fs.protected_symlinks is disabled, this can be exploited between the os.open and os.chown calls wh... Read more
- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2024-47291
Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 01, 2024
-
5.6
MEDIUMCVE-2018-3620
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysi... Read more
- Published: Aug. 14, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2017-3265
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privilege... Read more
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
5.6
MEDIUMCVE-2017-5754
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.... Read more
Affected Products : core_i3 core_i5 core_i7 xeon_e3 xeon_e3_1220_v5 xeon_e3_1225_v5 xeon_e3_1230_v5 xeon_e3_1235l_v5 xeon_e3_1240_v5 xeon_e3_1240l_v5 +199 more products- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024