Latest CVE Feed
-
5.5
MEDIUMCVE-2025-20985
Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse trial items.... Read more
Affected Products :- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2022-38388
IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive information due to improper access control. IBM X-Force ID: 233968.... Read more
Affected Products : navigator_mobile- Published: Oct. 11, 2022
- Modified: May. 15, 2025
-
5.5
MEDIUMCVE-2022-41171
Due to lack of proper memory management, when a victim opens manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes... Read more
Affected Products : 3d_visual_enterprise_author- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-39302
Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Audit-Logging" which contain a channel from another server as a target. This would mean you could send log messages to another Guild chan... Read more
Affected Products : ree6- Published: Oct. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-38677
In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privileges needed.... Read more
- Published: Oct. 14, 2022
- Modified: May. 15, 2025
-
5.5
MEDIUMCVE-2022-39103
In Gallery service, there is a missing permission check. This could lead to local denial of service in Gallery service with no additional execution privileges needed.... Read more
- Published: Oct. 14, 2022
- Modified: May. 15, 2025
-
5.5
MEDIUMCVE-2022-39115
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.... Read more
- Published: Oct. 14, 2022
- Modified: May. 15, 2025
-
5.5
MEDIUMCVE-2022-39126
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.... Read more
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
5.5
MEDIUMCVE-2025-24493
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Race Condition
-
5.5
MEDIUMCVE-2025-27247
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2022-43152
tsMuxer v2.6.16 was discovered to contain a heap overflow via the function BitStreamWriter::flushBits() at /tsMuxer/bitStream.h.... Read more
Affected Products : tsmuxer- Published: Oct. 31, 2022
- Modified: May. 06, 2025
-
5.5
MEDIUMCVE-2022-42815
This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Nov. 01, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2025-49185
The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript code into the Transform Function which will be executed when the widget receives data from its data source... Read more
Affected Products :- Published: Jun. 12, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2019-25099
A vulnerability classified as critical was found in Arthmoor QSF-Portal. This vulnerability affects unknown code of the file index.php. The manipulation of the argument a leads to path traversal. The patch is identified as ea4f61e23ecb83247d174bc2e2cbab52... Read more
Affected Products : qsf-portal- Published: Jan. 06, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-42473
A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and 7.2.0 allows an attacker to disclose information via logging into the database using a privileged account without a password.... Read more
Affected Products : fortisoar- Published: Nov. 02, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-3675
Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the GRUB command-line, modify kernel command-line arguments, or boot non-default OSTree deployments. Recent ... Read more
Affected Products : fedora_coreos- Published: Nov. 03, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-44746
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.... Read more
Affected Products : cyber_protect_home_office- Published: Nov. 07, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-44320
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceFP function in expression.c when called from ExpressionParseFunctionCall.... Read more
Affected Products : picoc- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
5.5
MEDIUMCVE-2021-26393
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker con... Read more
Affected Products : athlon_gold_3150c_firmware athlon_gold_3150u_firmware athlon_pro_3045b_firmware athlon_pro_3145b_firmware athlon_silver_3050c_firmware athlon_silver_3050e_firmware athlon_silver_3050u_firmware ryzen_3_2200g_firmware ryzen_3_2200ge_firmware ryzen_3_2200u_firmware +170 more products- Published: Nov. 09, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-40976
A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availab... Read more
- Published: Nov. 24, 2022
- Modified: Nov. 21, 2024