Latest CVE Feed
-
5.5
MEDIUMCVE-2023-41316
Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from the Tolgee instance to other users.... Read more
Affected Products : tolgee- Published: Sep. 07, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-22409
An Unchecked Input for Loop Condition vulnerability in a NAT library of Juniper Networks Junos OS allows a local authenticated attacker with low privileges to cause a Denial of Service (DoS). When an inconsistent "deterministic NAT" configuration is prese... Read more
- Published: Jan. 13, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42109
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to expl... Read more
- Published: May. 03, 2024
- Modified: May. 16, 2025
-
5.5
MEDIUMCVE-2023-23437
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak ... Read more
Affected Products : vmall- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-23021
The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644.... Read more
Affected Products : nginx_controller- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-20706
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767860; Issue ID... Read more
- Published: May. 15, 2023
- Modified: Jan. 24, 2025
-
5.5
MEDIUMCVE-2023-20996
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product:... Read more
Affected Products : android- Published: Mar. 24, 2023
- Modified: Feb. 25, 2025
-
5.5
MEDIUMCVE-2023-21243
In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed. Us... Read more
Affected Products : android- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21350
In Media Projection, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U... Read more
Affected Products : android- Published: Oct. 30, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-35080
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c.... Read more
Affected Products : swftools- Published: Oct. 13, 2022
- Modified: May. 15, 2025
-
5.5
MEDIUMCVE-2022-1018
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a r... Read more
- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-4753
OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the error input.... Read more
- Published: Sep. 21, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-27557
Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video streaming username and password via SQLite files containing plain text credentials.... Read more
- Published: Nov. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-49135
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.... Read more
- Published: Jan. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-24882
Microsoft OneDrive for Android Information Disclosure Vulnerability... Read more
Affected Products : onedrive- Published: Mar. 14, 2023
- Modified: Feb. 28, 2025
-
5.5
MEDIUMCVE-2021-44992
There is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object.c in Jerryscript 3.0.0.... Read more
Affected Products : jerryscript- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-50442
Encrypted folders created by PRIMX ZONECENTRAL through 2023.5 can be modified by a local attacker (with appropriate privileges) so that specific file types are excluded from encryption temporarily. (This modification can, however, be detected, as describe... Read more
Affected Products : zonecentral- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-50974
In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.... Read more
- Published: Jan. 09, 2024
- Modified: Jun. 17, 2025
-
5.5
MEDIUMCVE-2023-52350
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed... Read more
- Published: Apr. 08, 2024
- Modified: Mar. 27, 2025
-
5.5
MEDIUMCVE-2022-20019
In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP... Read more
- Published: Jan. 04, 2022
- Modified: May. 22, 2025