Latest CVE Feed
-
5.5
MEDIUMCVE-2020-4290
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID:... Read more
Affected Products : security_information_queue- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-3644
u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display session' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon... Read more
Affected Products : sa6155p_firmware sdx55_firmware sdm660_firmware sm8150_firmware sm8250_firmware sxr2130_firmware msm8996au_firmware sa515m_firmware apq8096au_firmware mdm9150_firmware +74 more products- Published: Sep. 08, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-34390
Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow through a specific SMC call that is triggered by the user, which may lead to denial of service.... Read more
- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-11601
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is unauthorized access to applications in the Secure Folder via floating icons. The Samsung ID is SVE-2019-16195 (April 2020).... Read more
Affected Products : android- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46535
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0xe533e. This vulnerability can lead to a Denial of Service (DoS).... Read more
Affected Products : mjs- Published: Jan. 27, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11948
Exceeding the limit of usage entries are not tracked and the information will be lost causing the content to lose continuity in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer... Read more
Affected Products : sd_8cx_firmware sdm660_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware qcs605_firmware sd_675_firmware +50 more products- Published: Feb. 25, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46528
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x5361e. This vulnerability can lead to a Denial of Service (DoS).... Read more
Affected Products : mjs- Published: Jan. 27, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-33069
Ethereum Solidity v0.8.14 contains an assertion failure via SMTEncoder::indexOrMemberAssignment() at SMTEncoder.cpp.... Read more
Affected Products : solidity- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9629
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Jun. 26, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-35111
SWFTools commit 772e55a2 was discovered to contain a stack overflow via __sanitizer::StackDepotNode::hash(__sanitizer::StackTrace const&) at /sanitizer_common/sanitizer_stackdepot.cpp.... Read more
Affected Products : swftools- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-32441
A memory corruption in Hex Rays Ida Pro v6.6 allows attackers to cause a Denial of Service (DoS) via a crafted file. Related to Data from Faulting Address controls subsequent Write Address starting at msvcrt!memcpy+0x0000000000000056.... Read more
Affected Products : ida- Published: Jul. 07, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-48678
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.... Read more
- Published: Feb. 27, 2024
- Modified: Feb. 06, 2025
-
5.5
MEDIUMCVE-2023-0747
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6. ... Read more
Affected Products : btcpayserver- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-1184
A vulnerability was found in Nsasoft Network Sleuth 3.0.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. The manipulation leads to denial of service. It is possible to launc... Read more
Affected Products : network_sleuth- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0410
In flv extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561... Read more
Affected Products : android- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-8949
An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attribute UUIDs but attribute IDs set) c... Read more
Affected Products : misp- Published: Mar. 23, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-29737
An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files.... Read more
Affected Products : wave_animated_keyboard_emoji- Published: May. 30, 2023
- Modified: Jan. 14, 2025
-
5.5
MEDIUMCVE-2023-44300
Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance. A local attacker with privileges could potentially exploit this vulnerability, leading to the disclosure of certain service credentials. The attacker may be abl... Read more
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-1259
The Hotjar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hotjar_site_id in versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi... Read more
Affected Products : hotjar- Published: Oct. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0436
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds read due to integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P... Read more
Affected Products : android- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024