Latest CVE Feed
-
5.5
MEDIUMCVE-2024-20841
Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.... Read more
Affected Products : account- Published: Mar. 05, 2024
- Modified: Feb. 14, 2025
-
5.5
MEDIUMCVE-2024-1900
Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay authenticated after his user is disabled or deleted in the identity provid... Read more
Affected Products : devolutions_server- Published: Mar. 05, 2024
- Modified: Mar. 28, 2025
-
5.5
MEDIUMCVE-2023-41015
code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1.... Read more
Affected Products : online_job_portal- Published: Mar. 07, 2024
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2023-48248
The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP request, or simply by waiting for t... Read more
Affected Products : nexo-os nexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\) nexo_cordless_nutrunner_nxa011s-36v_\(0608842011\) nexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\) nexo_cordless_nutrunner_nxa015s-36v_\(0608842001\) nexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\) nexo_cordless_nutrunner_nxa030s-36v_\(0608842002\) nexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\) nexo_cordless_nutrunner_nxa050s-36v_\(0608842003\) nexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\) +11 more products- Published: Jan. 10, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-22010
In dvfs_plugin_caller of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Mar. 11, 2024
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2024-28429
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archives_do.php... Read more
Affected Products : dedecms- Published: Mar. 13, 2024
- Modified: Apr. 01, 2025
-
5.5
MEDIUMCVE-2024-0313
A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organization. On the contrary, if the victim is legitimately using the temporary bypass to reach out to the Internet for retrieving application... Read more
Affected Products :- Published: Mar. 14, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-24043
Directory Traversal vulnerability in Speedy11CZ MCRPX v.1.4.0 and before allows a local attacker to execute arbitrary code via a crafted file.... Read more
Affected Products :- Published: Mar. 19, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-28570
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the processMakerNote() function when reading images in JPEG format.... Read more
Affected Products : freeimage- Published: Mar. 20, 2024
- Modified: Mar. 28, 2025
-
5.5
MEDIUMCVE-2024-2971
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file. ... Read more
Affected Products : xpdf- Published: Mar. 26, 2024
- Modified: Jan. 29, 2025
-
5.5
MEDIUMCVE-2024-27325
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to expl... Read more
- Published: Apr. 01, 2024
- Modified: Dec. 04, 2024
-
5.5
MEDIUMCVE-2024-22180
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through use after free.... Read more
- Published: Apr. 02, 2024
- Modified: Jan. 27, 2025
-
5.5
MEDIUMCVE-2024-30946
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.... Read more
Affected Products : dedecms- Published: Apr. 02, 2024
- Modified: Apr. 01, 2025
-
5.5
MEDIUMCVE-2024-32743
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SITE LANGUAGE CONFIG parameter under the Security module.... Read more
Affected Products : wondercms- Published: Apr. 17, 2024
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2024-31229
Server-Side Request Forgery (SSRF) vulnerability in Really Simple Plugins Really Simple SSL.This issue affects Really Simple SSL: from n/a through 7.2.3. ... Read more
Affected Products :- Published: Apr. 18, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-125016
A vulnerability was found in FFmpeg 2.0. It has been rated as problematic. This issue affects the function ff_init_buffer_info of the file utils.c. The manipulation leads to memory corruption. The attack may be initiated remotely. It is recommended to app... Read more
Affected Products : ffmpeg- Published: Jun. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-31889
An issue discovered in httpd in ASUS RT-AC51U with firmware version up to and including 3.0.0.4.380.8591 allows local attackers to cause a denial of service via crafted GET request.... Read more
Affected Products :- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42100
Kofax Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit th... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
5.5
MEDIUMCVE-2023-44433
Kofax Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
5.5
MEDIUMCVE-2023-51609
Kofax Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit th... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025