Latest CVE Feed
-
5.5
MEDIUMCVE-2024-44913
An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).... Read more
- Published: Aug. 28, 2024
- Modified: May. 23, 2025
-
5.5
MEDIUMCVE-2024-45094
IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadin... Read more
- Published: May. 27, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2019-10513
Possibility of Null pointer access if the SPDM commands are executed in the non-standard way in Trustzone in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon In... Read more
Affected Products : ipq8074_firmware qca8081_firmware sdx55_firmware sdm660_firmware sm8150_firmware sxr2130_firmware msm8996au_firmware apq8096au_firmware mdm9150_firmware qcs605_firmware +88 more products- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-13498
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially crafted malformed file can trigger an arbitrary out of bounds memory access which could lead to information disclosure. This vulnerability... Read more
- Published: Dec. 02, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0618
In ape extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561394... Read more
Affected Products : android- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-43614
Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.... Read more
Affected Products : defender_for_endpoint- Published: Oct. 08, 2024
- Modified: Jul. 08, 2025
-
5.5
MEDIUMCVE-2022-47371
In bt driver, there is a thread competition leads to early release of resources to be accessed. This could lead to local denial of service in kernel.... Read more
- Published: Feb. 12, 2023
- Modified: Mar. 26, 2025
-
5.5
MEDIUMCVE-2020-2683
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.0.1-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low pri... Read more
Affected Products : flexcube_universal_banking- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42676
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-33866
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
5.5
MEDIUMCVE-2024-1188
A vulnerability, which was classified as problematic, was found in Rizone Soft Notepad3 1.0.2.350. Affected is an unknown function of the component Encryption Passphrase Handler. The manipulation leads to denial of service. Attacking locally is a requirem... Read more
Affected Products : notepad3- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-47472
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.... Read more
- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0087
In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: ... Read more
Affected Products : android- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-30751
This issue was addressed with improved data protection. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass certain Privacy preferences.... Read more
Affected Products : macos- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-30756
A local attacker may be able to view Now Playing information from the lock screen. This issue is fixed in macOS Big Sur 11.4, iOS 14.6 and iPadOS 14.6. A privacy issue in Now Playing was addressed with improved permissions.... Read more
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-38448
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges... Read more
- Published: Sep. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-20836
Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.... Read more
- Published: Mar. 05, 2024
- Modified: Feb. 10, 2025
-
5.5
MEDIUMCVE-2023-39288
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient p... Read more
Affected Products : mivoice_connect- Published: Aug. 25, 2023
- Modified: Nov. 21, 2024