Latest CVE Feed
-
5.5
MEDIUMCVE-2024-2045
Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments.... Read more
Affected Products : session- Published: Mar. 01, 2024
- Modified: May. 19, 2025
-
5.5
MEDIUMCVE-2023-30087
Buffer Overflow vulnerability found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_mk_string function in mjs.c.... Read more
Affected Products : mjs- Published: May. 09, 2023
- Modified: Jan. 29, 2025
-
5.5
MEDIUMCVE-2022-32602
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388790; I... Read more
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
5.5
MEDIUMCVE-2024-43697
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.... Read more
Affected Products : openharmony- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
5.5
MEDIUMCVE-2023-31292
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack.... Read more
Affected Products : cash_point_\&_transport_optimizer- Published: Dec. 29, 2023
- Modified: Apr. 17, 2025
-
5.5
MEDIUMCVE-2023-31413
Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or Proxy-Authorization header contents to be leaked in the logs when debug logging is enabled.... Read more
Affected Products : filebeat- Published: May. 04, 2023
- Modified: Jan. 29, 2025
-
5.5
MEDIUMCVE-2020-29639
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted font may result in the disclosure of process memory.... Read more
- Published: Apr. 02, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-44915
An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).... Read more
- Published: Aug. 28, 2024
- Modified: May. 23, 2025
-
5.5
MEDIUMCVE-2020-3116
A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attack... Read more
- Published: Sep. 23, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-22463
A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this vulnerability to cause Kernel Information disclosure.... Read more
Affected Products : harmonyos- Published: Oct. 28, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-20826
Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sensitive information via implicit intent.... Read more
Affected Products : uphelper_library- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-39128
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.... Read more
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
5.5
MEDIUMCVE-2024-23453
Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the ass... Read more
Affected Products : spoon- Published: Jan. 24, 2024
- Modified: Jun. 04, 2025
-
5.5
MEDIUMCVE-2022-39407
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows low privileged attacker with logon to the infr... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32013
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2).... Read more
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-25454
Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.... Read more
Affected Products : bento4- Published: Feb. 09, 2024
- Modified: May. 08, 2025
-
5.5
MEDIUMCVE-2024-52998
Substance3D - Stager versions 3.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this i... Read more
- Published: Nov. 22, 2024
- Modified: Dec. 03, 2024
-
5.5
MEDIUMCVE-2024-54001
Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, application_date_format,application_timezone and application_time_forma... Read more
Affected Products : kanboard- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
5.5
MEDIUMCVE-2024-28044
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow.... Read more
- Published: Sep. 02, 2024
- Modified: Sep. 04, 2024
-
5.5
MEDIUMCVE-2023-32421
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app may be able to observe unprotected user data.... Read more
Affected Products : macos- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024