Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.5

    MEDIUM
    CVE-2023-20910

    In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploi... Read more

    Affected Products : android
    • Published: Mar. 24, 2023
    • Modified: Feb. 28, 2025
  • 5.5

    MEDIUM
    CVE-2023-20952

    In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat... Read more

    Affected Products : android
    • Published: Mar. 24, 2023
    • Modified: Feb. 25, 2025
  • 5.5

    MEDIUM
    CVE-2023-20998

    In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product:... Read more

    Affected Products : android
    • Published: Mar. 24, 2023
    • Modified: Feb. 25, 2025
  • 5.5

    MEDIUM
    CVE-2023-21019

    In ih264e_init_proc_ctxt of ih264e_process.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita... Read more

    Affected Products : android
    • Published: Mar. 24, 2023
    • Modified: Feb. 24, 2025
  • 5.5

    MEDIUM
    CVE-2025-54637

    Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more

    Affected Products : emui harmonyos
    • Published: Aug. 06, 2025
    • Modified: Aug. 11, 2025
    • Vuln Type: Memory Corruption
  • 5.5

    MEDIUM
    CVE-2025-54640

    ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.... Read more

    Affected Products : harmonyos
    • Published: Aug. 06, 2025
    • Modified: Aug. 06, 2025
  • 5.5

    MEDIUM
    CVE-2023-25263

    In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the ... Read more

    Affected Products : designer
    • Published: Mar. 27, 2023
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2023-1550

    Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to priv... Read more

    Affected Products : nginx_instance_manager nginx_agent
    • Published: Mar. 29, 2023
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-37361

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more

    • Published: Mar. 29, 2023
    • Modified: Nov. 27, 2024
  • 5.5

    MEDIUM
    CVE-2022-37370

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more

    • Published: Mar. 29, 2023
    • Modified: Nov. 27, 2024
  • 5.5

    MEDIUM
    CVE-2022-43612

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page ... Read more

    Affected Products : coreldraw
    • Published: Mar. 29, 2023
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-43615

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page ... Read more

    Affected Products : coreldraw
    • Published: Mar. 29, 2023
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2025-24925

    in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.... Read more

    Affected Products : openharmony
    • Published: Aug. 11, 2025
    • Modified: Aug. 12, 2025
    • Vuln Type: Denial of Service
  • 5.5

    MEDIUM
    CVE-2023-26974

    Irfanview v4.62 allows a user-mode write access violation via a crafted JPEG 2000 file starting at JPEG2000+0x0000000000001bf0.... Read more

    Affected Products : irfanview
    • Published: Apr. 04, 2023
    • Modified: Feb. 13, 2025
  • 5.5

    MEDIUM
    CVE-2022-47465

    In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Apr. 11, 2023
    • Modified: Feb. 11, 2025
  • 5.5

    MEDIUM
    CVE-2024-45559

    Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.... Read more

    • Published: Jan. 06, 2025
    • Modified: Jan. 13, 2025
    • Vuln Type: Denial of Service
  • 5.5

    MEDIUM
    CVE-2023-26387

    Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Expl... Read more

    Affected Products : macos windows substance_3d_stager
    • Published: Apr. 12, 2023
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2023-29573

    Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.... Read more

    Affected Products : bento4
    • Published: Apr. 13, 2023
    • Modified: Feb. 07, 2025
  • 5.5

    MEDIUM
    CVE-2023-28085

    An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials... Read more

    Affected Products : oneview_global_dashboard
    • Published: Apr. 14, 2023
    • Modified: Feb. 06, 2025
  • 5.5

    MEDIUM
    CVE-2023-28091

    HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dump... Read more

    Affected Products : oneview oneview
    • Published: Apr. 14, 2023
    • Modified: Feb. 06, 2025
Showing 20 of 294285 Results