Latest CVE Feed
-
5.5
MEDIUMCVE-2021-42556
Rasa X before 0.42.4 allows Directory Traversal during archive extraction. In the functionality that allows a user to load a trained model archive, an attacker has arbitrary write capability within specific directories via a crafted archive file.... Read more
Affected Products : rasa_x- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-31916
Jerryscript 3.0 (commit 1a2c047) was discovered to contain an Assertion Failure via the jmem_heap_finalize at jerry-core/jmem/jmem-heap.c.... Read more
Affected Products : jerryscript- Published: May. 12, 2023
- Modified: Jan. 24, 2025
-
5.5
MEDIUMCVE-2022-47337
In media service, there is a missing permission check. This could lead to local denial of service in media service.... Read more
- Published: Apr. 11, 2023
- Modified: Feb. 10, 2025
-
5.5
MEDIUMCVE-2022-47471
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.... Read more
- Published: Mar. 10, 2023
- Modified: Mar. 05, 2025
-
5.5
MEDIUMCVE-2022-42390
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Jan. 26, 2023
- Modified: Nov. 27, 2024
-
5.5
MEDIUMCVE-2023-33656
A memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack by causing the program to consume all available memory resources.... Read more
Affected Products : nanomq- Published: May. 30, 2023
- Modified: Jan. 10, 2025
-
5.5
MEDIUMCVE-2022-44437
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.... Read more
- Published: Jan. 04, 2023
- Modified: Apr. 10, 2025
-
5.5
MEDIUMCVE-2022-36151
tifig v0.2.2 was discovered to contain a segmentation violation via getType() at /common/bbox.cpp.... Read more
Affected Products : tifig- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0384
In Parse_art of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed for ex... Read more
Affected Products : android- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5255
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a DoS vulnerability. An attack... Read more
- Published: Dec. 13, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-47454
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.... Read more
- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-1631
A vulnerability, which was classified as problematic, was found in JiangMin Antivirus 16.2.2022.418. This affects the function 0x222010 in the library kvcore.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking... Read more
Affected Products : jiangmin_antivirus- Published: Mar. 25, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-34634
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted det instructions rather create an exception.... Read more
Affected Products : cva6- Published: Jul. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-0087
The Swifty Page Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘spm_plugin_options_page_tree_max_width’ parameter in versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This m... Read more
Affected Products : swifty_page_manager- Published: Jan. 05, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-40470
PDF-XChange Editor JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to expl... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
5.5
MEDIUMCVE-2023-1010
A vulnerability classified as critical was found in vox2png 1.0. Affected by this vulnerability is an unknown functionality of the file vox2png.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has be... Read more
Affected Products : vox2png- Published: Feb. 24, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42079
PDF-XChange Editor J2K File Parsing Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to ... Read more
- Published: May. 03, 2024
- Modified: May. 16, 2025
-
5.5
MEDIUMCVE-2023-42087
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to expl... Read more
- Published: May. 03, 2024
- Modified: May. 16, 2025
-
5.5
MEDIUMCVE-2020-26800
A stack overflow vulnerability in Aleth Ethereum C++ client version <= 1.8.0 using a specially crafted a config.json file may result in a denial of service.... Read more
Affected Products : aleth- Published: Jan. 11, 2021
- Modified: Nov. 21, 2024