Latest CVE Feed
-
5.5
MEDIUMCVE-2024-34594
Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.... Read more
- Published: Jul. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-31312
In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposing played media with no additional execution privileges needed. User interaction is not needed for exploit... Read more
Affected Products : android- Published: Jul. 09, 2024
- Modified: Dec. 17, 2024
-
5.5
MEDIUMCVE-2015-2179
The xaviershay-dm-rails gem 0.10.3.8 for Ruby allows local users to discover MySQL credentials by listing a process and its arguments.... Read more
Affected Products : xaviershay-dm-rails- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-6625
The WP Total Branding – Complete branding solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. Thi... Read more
Affected Products :- Published: Jul. 12, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-6326
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords... Read more
- Published: Jul. 16, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-41443
A stack overflow in the function cp_dynamic() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.... Read more
Affected Products : hicolor- Published: Jul. 30, 2024
- Modified: Mar. 19, 2025
-
5.5
MEDIUMCVE-2024-41200
A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.... Read more
Affected Products : kmplayer- Published: Aug. 05, 2024
- Modified: Jun. 18, 2025
-
5.5
MEDIUMCVE-2024-37403
Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on th... Read more
Affected Products : docs\@work- Published: Aug. 07, 2024
- Modified: Mar. 25, 2025
-
5.5
MEDIUMCVE-2023-31366
Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service.... Read more
Affected Products : uprof- Published: Aug. 13, 2024
- Modified: Dec. 12, 2024
-
5.5
MEDIUMCVE-2024-28050
Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access.... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
5.5
MEDIUMCVE-2024-43915
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102.... Read more
- Published: Aug. 26, 2024
- Modified: Aug. 28, 2024
-
5.5
MEDIUMCVE-2024-44914
An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).... Read more
- Published: Aug. 28, 2024
- Modified: May. 23, 2025
-
5.5
MEDIUMCVE-2024-45444
Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 06, 2024
-
5.5
MEDIUMCVE-2024-45447
Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 06, 2024
-
5.5
MEDIUMCVE-2024-45449
Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 06, 2024
-
5.5
MEDIUMCVE-2024-34643
Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
5.5
MEDIUMCVE-2024-42344
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information into a log file which is readable by all legitimate users of the underlying system. This could allow an a... Read more
- Published: Sep. 10, 2024
- Modified: Sep. 10, 2024
-
5.5
MEDIUMCVE-2024-40656
In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User intera... Read more
Affected Products : android- Published: Sep. 11, 2024
- Modified: Dec. 17, 2024
-
5.5
MEDIUMCVE-2024-28170
Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products : raid_web_console- Published: Sep. 16, 2024
- Modified: Sep. 23, 2024
-
5.5
MEDIUMCVE-2024-32666
NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products : raid_web_console- Published: Sep. 16, 2024
- Modified: Sep. 23, 2024