Latest CVE Feed
-
5.5
MEDIUMCVE-2021-0562
In RasterIntraUpdate of motion_est.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio... Read more
Affected Products : android- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-39504
PDF-XChange Editor OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exp... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
5.5
MEDIUMCVE-2020-0425
There is a possible way to view notifications even when the "Lockdown" feature is on. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:... Read more
Affected Products : android- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-48504
The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2020-0437
In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial of service of emergency alerts with no additional execution privileges needed. User interaction is not nee... Read more
Affected Products : android- Published: Nov. 10, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0496
In CPDF_RenderStatus::LoadSMask of cpdf_renderstatus.cpp, there is a possible memory corruption due to a use-after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp... Read more
Affected Products : android- Published: Dec. 15, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-40098
In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User... Read more
Affected Products : android- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-45243
Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35739.... Read more
- Published: Oct. 05, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1002203
unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.... Read more
Affected Products : unzipper- Published: Jul. 25, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-41987
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access sensitive user data.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jun. 17, 2025
-
5.5
MEDIUMCVE-2020-0571
Improper conditions check in BIOS firmware for 8th Generation Intel(R) Core(TM) Processors and Intel(R) Pentium(R) Silver Processor Series may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products : bios pentium_silver_j5005 pentium_silver_j5040 pentium_silver_n5000 pentium_silver_n5030 core_i5_8400 core_i5_8400t core_i5_8500 core_i5_8500t core_i5_8600 +12 more products- Published: Oct. 05, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-40646
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Oct. 08, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-22177
in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through get permission.... Read more
- Published: Apr. 02, 2024
- Modified: Jan. 02, 2025
-
5.5
MEDIUMCVE-2023-1487
A vulnerability, which was classified as problematic, has been found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54. This issue affects the function 0x9C40208C/0x9C402000/0x9C402084/0x9C402088/0x9C402004/0x9C4060C4/0x9C4060CC/0x9C4060D0/0x9C4060D4/0x... Read more
Affected Products : wise_system_monitor- Published: Mar. 18, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-29839
Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue... Read more
Affected Products : linux_kernel my_cloud_os my_cloud_firmware my_cloud my_cloud_dl2100 my_cloud_dl4100 my_cloud_ex2_ultra my_cloud_ex2100 my_cloud_ex4100 my_cloud_mirror_g2 +3 more products- Published: Dec. 09, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0293
A vulnerability in Juniper Networks Junos OS caused by Missing Release of Memory after Effective Lifetime leads to a memory leak each time the CLI command 'show system connections extensive' is executed. The amount of memory leaked on each execution depen... Read more
Affected Products : junos- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-38447
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges... Read more
- Published: Sep. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-25663
Possible buffer overflow due to lack of buffer length check during management frame Rx handling lead to denial of service in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity... Read more
Affected Products : aqt1000_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6430_firmware wcd9341_firmware wcd9380_firmware wcd9385_firmware wcn3998_firmware wcn6855_firmware +52 more products- Published: Oct. 19, 2022
- Modified: May. 15, 2025
-
5.5
MEDIUMCVE-2015-4322
Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authentication, which allows remote authenticated users to read or write to an arbitrary user's Spam Quarantine f... Read more
Affected Products : content_security_management_appliance- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2021-24242
The Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusion vulnerability through the maliciously constructed sub_page parameter of the plugin's Tools, allowing high privilege users to include a... Read more
Affected Products : tutor_lms- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024