Latest CVE Feed
-
5.5
MEDIUMCVE-2023-4968
The WPLegalPages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wplegalpage' shortcode in versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po... Read more
Affected Products : wplegalpages- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39541
An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Analyze::AnalyzeXref() located in analyze.cpp. It allows an attacker to cause Denial of Service.... Read more
Affected Products : pdftools- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39549
An issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function file::WavFile::WavFile() located in wav_file.c. It allows an attacker to cause Denial of Service.... Read more
Affected Products : sela- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-50440
ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL fo... Read more
- Published: Dec. 13, 2023
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2023-51433
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. ... Read more
Affected Products : magic_ui- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-4658
The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.... Read more
Affected Products : ansible- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45861
There is an Assertion `num <= INT_BIT' failed at BitStreamReader::skipBits in /bitStream.h:132 of tsMuxer git-c6a0277.... Read more
Affected Products : tsmuxer- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45937
wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and MqttClient_Connect).... Read more
Affected Products : wolfmqtt- Published: Jan. 01, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-34627
Out-of-bounds read in parsing implemention in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.... Read more
Affected Products : notes- Published: Aug. 07, 2024
- Modified: Aug. 09, 2024
-
5.5
MEDIUMCVE-2024-34631
Out-of-bounds read in applying new binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.... Read more
Affected Products : notes- Published: Aug. 07, 2024
- Modified: Aug. 09, 2024
-
5.5
MEDIUMCVE-2022-20020
In libvcodecdrv, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05943... Read more
- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46350
There is an Assertion 'ecma_is_value_object (value)' failed at jerryscript/jerry-core/ecma/base/ecma-helpers-value.c in JerryScript 3.0.0.... Read more
Affected Products : jerryscript- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20355
In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe... Read more
Affected Products : android- Published: Aug. 10, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20414
In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for ex... Read more
Affected Products : android- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
5.5
MEDIUMCVE-2024-3757
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through integer overflow.... Read more
- Published: May. 07, 2024
- Modified: Jan. 02, 2025
-
5.5
MEDIUMCVE-2023-51777
Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error.... Read more
Affected Products : gx_works3 windriver gt_softgot2000 cpu_module_logging_configuration_tool cw_configurator gx_logviewer gx_works2 mi_configurator mr_configurator2 rt_toolbox3 +33 more products- Published: Jul. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20570
Product: AndroidVersions: Android kernelAndroid ID: A-230660904References: N/A... Read more
Affected Products : android- Published: Dec. 16, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2024-1343
A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allows any authenticated user to read backup files in the directory '%programfiles(x86)% LaborOfficeFree BackUp'.... Read more
Affected Products : laborofficefree- Published: Feb. 19, 2024
- Modified: Mar. 24, 2025
-
5.5
MEDIUMCVE-2024-39733
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 295972.... Read more
Affected Products : datacap- Published: Jul. 14, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-51564
Kofax Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit th... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025