Latest CVE Feed
-
5.5
MEDIUMCVE-2024-47156
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.... Read more
Affected Products : magicos- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2024-47154
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.... Read more
- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2024-47150
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.... Read more
- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2024-31913
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended func... Read more
Affected Products : sterling_b2b_integrator- Published: Jan. 06, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-21615
AAT (Another Activity Tracker) is a GPS-tracking application for tracking sportive activities, with emphasis on cycling. Versions lower than v1.26 of AAT are vulnerable to data exfiltration from malicious apps installed on the same device.... Read more
Affected Products :- Published: Jan. 06, 2025
- Modified: Jan. 06, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2024-49412
Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.... Read more
Affected Products : android- Published: Dec. 03, 2024
- Modified: Dec. 03, 2024
-
5.5
MEDIUMCVE-2018-9379
In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not... Read more
Affected Products : android- Published: Jan. 17, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-0158
IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation.... Read more
- Published: Feb. 06, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-1102
A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability via crafted URLs or HTTP reques... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2024-53311
A Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via a crafted input that exceeds the buffer size.... Read more
Affected Products :- Published: Feb. 13, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2024-13879
The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2 due to insufficient validation on the webhook feature. This makes it possible for authenticated attackers, with administrator-level ac... Read more
Affected Products : stream- Published: Feb. 17, 2025
- Modified: Feb. 17, 2025
- Vuln Type: Server-Side Request Forgery
-
5.5
MEDIUMCVE-2025-24832
Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) befo... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-23234
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.... Read more
Affected Products : openharmony- Published: Mar. 04, 2025
- Modified: Mar. 04, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-2089
A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerability is the function updateUserInfo of the file /personal/updateInfo of the component com.siro.mall.controller.mall.UserController. The ... Read more
Affected Products : starsea-mall- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2024-54473
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Mar. 10, 2025
- Modified: Mar. 14, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2024-13838
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2 via the 'call_webhook' method of the Automator_Send_Webhoo... Read more
Affected Products : uncanny_automator- Published: Mar. 12, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Server-Side Request Forgery
-
5.5
MEDIUMCVE-2024-29409
File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.... Read more
Affected Products : nest- Published: Mar. 14, 2025
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2024-48828
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-23203
Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.3 and 1.11.3 on several director endpoints of REST API. To reproduce this vulnerability an authenticated user with per... Read more
Affected Products : icinga- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-2983
A vulnerability has been found in Legrand SMS PowerView 1.x and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument redirect leads to os command injection. The exploit has been disclosed to ... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Injection