Latest CVE Feed
-
5.5
MEDIUMCVE-2022-22303
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access to the FortiGate users credentials ... Read more
Affected Products : fortimanager- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9624
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Jun. 26, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0381
In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exp... Read more
Affected Products : android- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12151
Buffer overflow in installer for Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially cause a buffer overflow potentially leading to a denial of service via local access.... Read more
Affected Products : extreme_tuning_utility- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21276
In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. ... Read more
Affected Products : android- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21280
In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for expl... Read more
Affected Products : android- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-43624
CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information ... Read more
Affected Products : cx-designer- Published: Oct. 23, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0414
In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561384... Read more
Affected Products : android- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-4818
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 allows remote authenticated users to affect confidentiality and integrity via vectors related to PIA Core Technology.... Read more
Affected Products : peoplesoft_products- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2021-0152
Improper verification of cryptographic signature in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products : ac_9461_firmware ac_9462_firmware ac_9560_firmware ax210_firmware ax201_firmware ax200_firmware ac_9260_firmware ac_8265_firmware ac_8260_firmware ac_3168_firmware +20 more products- Published: Nov. 17, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0416
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403... Read more
Affected Products : android- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-35421
vmir e8117 was discovered to contain a segmentation violation via the wasm_parse_block function at /src/vmir_wasm_parser.c.... Read more
Affected Products : vmir- Published: Nov. 08, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2023-44127
he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as contact details a... Read more
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-29955
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. This could provide attackers with an additional, less-protected path to acquiring the encryption key. ... Read more
Affected Products : brocade_sannav- Published: Apr. 17, 2024
- Modified: Feb. 04, 2025
-
5.5
MEDIUMCVE-2020-4631
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full control permissions, which could allow a local user to cause interruption of the service operations. IBM X-For... Read more
- Published: Aug. 04, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-6681
Abuse of Functionality vulnerability in the web interface in McAfee Network Security Management (NSM) 9.1.7.11 and earlier allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via appliance web interface.... Read more
Affected Products : network_security_manager- Published: Jul. 17, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-38673
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.... Read more
- Published: Oct. 14, 2022
- Modified: May. 15, 2025
-
5.5
MEDIUMCVE-2022-29028
A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The Tiff_Loader.dll is vulnerable to infinite loop condition whi... Read more
- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-36873
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.... Read more
Affected Products : iq_block_country- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-28123
A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VPN credentials while UID VPN is starting.This vulnerability is fixed in Version 0.62.3 and later.... Read more
Affected Products : desktop- Published: Apr. 19, 2023
- Modified: Feb. 05, 2025