Latest CVE Feed
-
5.5
MEDIUMCVE-2021-20347
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other... Read more
Affected Products : rational_doors_next_generation rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager rational_quality_manager collaborative_lifecycle_management engineering_lifecycle_management engineering_test_management engineering_lifecycle_optimization engineering_lifecycle_optimization_-_engineering_insights engineering_lifecycle_optimization_-_publishing +1 more products- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-39114
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.... Read more
- Published: Oct. 14, 2022
- Modified: May. 15, 2025
-
5.5
MEDIUMCVE-2021-20607
Integer Underflow vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition ... Read more
- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-35096
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.... Read more
Affected Products : swftools- Published: Sep. 23, 2022
- Modified: May. 23, 2025
-
5.5
MEDIUMCVE-2022-35165
An issue in AP4_SgpdAtom::AP4_SgpdAtom() of Bento4-1.6.0-639 allows attackers to cause a Denial of Service (DoS) via a crafted mp4 input.... Read more
Affected Products : bento4- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-36233
Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd.... Read more
- Published: Aug. 19, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-42412
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Jan. 26, 2023
- Modified: Nov. 27, 2024
-
5.5
MEDIUM- Published: Nov. 09, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-39949
An improper control of a resource through its lifetime vulnerability [CWE-664] in FortiEDR CollectorWindows 4.0.0 through 4.1, 5.0.0 through 5.0.3.751, 5.1.0 may allow a privileged user to terminate the FortiEDR processes with special tools and bypass the... Read more
- Published: Nov. 02, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-13657
An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to improperly handling hard links. The vulnerability allows local users to take control of arbitrary files.... Read more
- Published: Jun. 29, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-42398
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Jan. 26, 2023
- Modified: Nov. 27, 2024
-
5.5
MEDIUMCVE-2022-47474
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.... Read more
- Published: Mar. 10, 2023
- Modified: Mar. 06, 2025
-
5.5
MEDIUMCVE-2021-38488
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute... Read more
Affected Products : dialink- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-4618
IBM Data Risk Manager (iDNA) 2.0.6 could allow a privileged user to cause a denial of service due to improper input validation. IBM X-Force ID: 184937.... Read more
Affected Products : data_risk_manager- Published: Sep. 22, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-33885
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.... Read more
- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-44313
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceUnsignedInteger function in expression.c when called from ExpressionParseFunctionCall.... Read more
Affected Products : picoc- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
5.5
MEDIUMCVE-2023-34042
The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access to the file system. While there are no known exploits, this is an example of “CWE-732:... Read more
- Published: Feb. 05, 2024
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2022-44648
An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privil... Read more
- Published: Dec. 12, 2022
- Modified: Apr. 29, 2025
-
5.5
MEDIUMCVE-2023-35679
In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.... Read more
Affected Products : android- Published: Sep. 11, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5251
There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Su... Read more
Affected Products : p30_pro_firmware p30_firmware honor_v10_firmware mate_20_firmware enjoy_7s_firmware honor_9_lite_firmware honor_9i_firmware m6_firmware honor_20s_firmware honor_9i +8 more products- Published: Dec. 13, 2019
- Modified: Nov. 21, 2024