Latest CVE Feed
-
5.5
MEDIUMCVE-2023-49118
in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read. ... Read more
- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-1194
A vulnerability classified as problematic has been found in Armcode AlienIP 2.41. Affected is an unknown function of the component Locate Host Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The... Read more
Affected Products : alienip- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-0659
The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the variable pricing option title in all versions up to, and including, 3.2.6 due to insufficient ... Read more
- Published: Feb. 05, 2024
- Modified: Feb. 07, 2025
-
5.5
MEDIUMCVE-2024-24943
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image... Read more
Affected Products : toolbox- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-25452
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.... Read more
Affected Products : bento4- Published: Feb. 09, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-23607
A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.... Read more
- Published: Feb. 14, 2024
- Modified: Jan. 24, 2025
-
5.5
MEDIUMCVE-2023-40105
In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not... Read more
Affected Products : android- Published: Feb. 15, 2024
- Modified: Dec. 13, 2024
-
5.5
MEDIUMCVE-2024-22335
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279975.... Read more
- Published: Feb. 17, 2024
- Modified: Dec. 04, 2024
-
5.5
MEDIUMCVE-2024-25129
The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser used by the CodeQL CLI to read various auxiliary files is vulnerable to an XML External Entity attack. If a vulnerable version of the CL... Read more
Affected Products : codeql_cli- Published: Feb. 22, 2024
- Modified: Feb. 05, 2025
-
5.5
MEDIUMCVE-2024-1192
A vulnerability was found in South River WebDrive 18.00.5057. It has been declared as problematic. This vulnerability affects unknown code of the component New Secure WebDAV. The manipulation leads to denial of service. Local access is required to approac... Read more
Affected Products : webdrive- Published: Feb. 29, 2024
- Modified: Jan. 08, 2025
-
5.5
MEDIUMCVE-2024-20841
Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.... Read more
Affected Products : account- Published: Mar. 05, 2024
- Modified: Feb. 14, 2025
-
5.5
MEDIUMCVE-2024-1900
Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay authenticated after his user is disabled or deleted in the identity provid... Read more
Affected Products : devolutions_server- Published: Mar. 05, 2024
- Modified: Mar. 28, 2025
-
5.5
MEDIUMCVE-2023-41015
code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1.... Read more
Affected Products : online_job_portal- Published: Mar. 07, 2024
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2023-48248
The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP request, or simply by waiting for t... Read more
Affected Products : nexo-os nexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\) nexo_cordless_nutrunner_nxa011s-36v_\(0608842011\) nexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\) nexo_cordless_nutrunner_nxa015s-36v_\(0608842001\) nexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\) nexo_cordless_nutrunner_nxa030s-36v_\(0608842002\) nexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\) nexo_cordless_nutrunner_nxa050s-36v_\(0608842003\) nexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\) +11 more products- Published: Jan. 10, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-22010
In dvfs_plugin_caller of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Mar. 11, 2024
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2024-28429
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archives_do.php... Read more
Affected Products : dedecms- Published: Mar. 13, 2024
- Modified: Apr. 01, 2025
-
5.5
MEDIUMCVE-2024-0313
A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organization. On the contrary, if the victim is legitimately using the temporary bypass to reach out to the Internet for retrieving application... Read more
Affected Products :- Published: Mar. 14, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-24043
Directory Traversal vulnerability in Speedy11CZ MCRPX v.1.4.0 and before allows a local attacker to execute arbitrary code via a crafted file.... Read more
Affected Products :- Published: Mar. 19, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-28570
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the processMakerNote() function when reading images in JPEG format.... Read more
Affected Products : freeimage- Published: Mar. 20, 2024
- Modified: Mar. 28, 2025
-
5.5
MEDIUMCVE-2024-2971
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file. ... Read more
Affected Products : xpdf- Published: Mar. 26, 2024
- Modified: Jan. 29, 2025