Latest CVE Feed
-
5.6
MEDIUMCVE-2024-10075
The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block.... Read more
Affected Products : jetpack- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
5.6
MEDIUMCVE-2024-12863
Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malicious users to inject code into the system.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
5.6
MEDIUMCVE-2025-2182
A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NGFW cluster. A use... Read more
Affected Products : pan-os- Published: Aug. 13, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Cryptography
-
5.6
MEDIUMCVE-2024-53683
A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use the information to disrupt normal use of the application by changing the translation files and thus weaken the in... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Misconfiguration
-
5.6
MEDIUMCVE-2024-42189
HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.... Read more
Affected Products : bigfix_platform- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Denial of Service
-
5.6
MEDIUMCVE-2019-19751
easyMINE before 2019-12-05 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io.... Read more
Affected Products :- Published: Apr. 30, 2024
- Modified: Mar. 28, 2025
-
5.6
MEDIUMCVE-2025-5916
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a mali... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2025-1055
A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with th... Read more
Affected Products :- Published: Jun. 11, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Misconfiguration
-
5.6
MEDIUMCVE-2024-53423
An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted packets.... Read more
Affected Products : onos- Published: May. 29, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Denial of Service
-
5.6
MEDIUMCVE-2025-2939
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauth... Read more
Affected Products : ninja_tables- Published: Jun. 03, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Injection
-
5.6
MEDIUMCVE-2025-23084
A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path,... Read more
- Published: Jan. 28, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Path Traversal
-
5.6
MEDIUMCVE-2024-56826
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.... Read more
- Published: Jan. 09, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2024-56827
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.... Read more
- Published: Jan. 09, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2019-18373
Norton App Lock, prior to 1.4.0.503, may be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking other apps on the device, thereby allowing the individual to gain ac... Read more
Affected Products : norton_app_lock- Published: Nov. 18, 2019
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2025-47808
In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.... Read more
Affected Products : gstreamer- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
5.6
MEDIUMCVE-2025-23392
A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows execution of arbitrary Javascript code on target systems.This issue affects Container suse/manager/5.0/x86_64/server:5.0.4.7.19.1: from ... Read more
Affected Products :- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.6
MEDIUMCVE-2019-15902
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ... Read more
- Published: Sep. 04, 2019
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2023-52768
In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: use vmm_table as array in wilc struct Enabling KASAN and running some iperf tests raises some memory issues with vmm_table: BUG: KASAN: slab-out-of-bounds in wilc_wlan_... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 02, 2025
-
5.6
MEDIUMCVE-2019-11091
Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A li... Read more
- Published: May. 30, 2019
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2012-3498
PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->inde... Read more
- Published: Nov. 23, 2012
- Modified: Apr. 11, 2025