Latest CVE Feed
-
5.5
MEDIUMCVE-2023-37355
Kofax Power PDF JPG File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit this v... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
5.5
MEDIUMCVE-2019-10561
Improper initialization of local variables which are parameters to sfs api may cause invalid pointer dereference and leads to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, ... Read more
Affected Products : sdm660_firmware msm8996au_firmware apq8096au_firmware apq8009_firmware msm8909w_firmware apq8017_firmware mdm9206_firmware mdm9607_firmware apq8098_firmware msm8998_firmware +46 more products- Published: Jan. 21, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-30309
XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue re... Read more
Affected Products : xmp_toolkit_software_development_kit- Published: Apr. 08, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2023-33078
Information Disclosure while processing IOCTL request in FastRPC.... Read more
- Published: Mar. 04, 2024
- Modified: Jan. 10, 2025
-
5.5
MEDIUMCVE-2022-20290
In Midi, there is a possible way to learn about private midi devices due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And... Read more
Affected Products : android- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-1010249
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in Fl... Read more
Affected Products : open_network_operating_system- Published: Jul. 18, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-43584
Substance3D - Viewer versions 0.22 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
Affected Products : substance_3d_viewer- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2021-29365
Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS!AutoCrop_W component. This can cause a denial of service (DOS).... Read more
Affected Products : irfanview- Published: Sep. 28, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-48399
In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not n... Read more
Affected Products : android- Published: Dec. 08, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-4369
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a user. IBM X-Force ID: 179004.... Read more
Affected Products : verify_gateway- Published: Jul. 22, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-33894
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.... Read more
- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29527
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.QuantizedConv2D`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/00e9a4d67d76703fa1aee33dac582a... Read more
Affected Products : tensorflow- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20304
In Content, there is a possible way to determinate the user's account due to side channel information disclosure. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Produc... Read more
Affected Products : android- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-5029
A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classified as critical. Affected by this vulnerability is the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file file... Read more
Affected Products :- Published: May. 21, 2025
- Modified: May. 21, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2024-1190
A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Host/Username/Password leads to denial of service. The attack needs to be appro... Read more
Affected Products : cuteftp- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29604
TensorFlow is an end-to-end open source platform for machine learning. The TFLite implementation of hashtable lookup is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/1a8e885b864c818198a5b2c0cbbeca5a1e833bc8/tensorflo... Read more
Affected Products : tensorflow- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-7573
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. This issue affects the function bs_GetManPwd in the library libblinkapi.so of the file /c... Read more
Affected Products : bl-ac3600_firmware- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2022-45128
Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products : endpoint_management_assistant- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-42754
In npu driver, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
5.5
MEDIUMCVE-2022-45155
An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attackers that can influence the call to the service to delete files and directories on the system of the victim. This issue affects: SUSE op... Read more
Affected Products : opensuse_factory- Published: Mar. 15, 2023
- Modified: Nov. 21, 2024