Latest CVE Feed
-
5.5
MEDIUMCVE-2024-2752
The Where Did You Hear About Us Checkout Field for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via order meta in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This ma... Read more
Affected Products :- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-1620
A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.... Read more
Affected Products : junos_os_evolved- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0975
In USB Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure of installed packages with no additional execution pri... Read more
Affected Products : android- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46628
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-41610
Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access.... Read more
- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-42528
In ffa_mrd_prot of shared_mem.c, there is a possible ID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi... Read more
Affected Products : android- Published: Mar. 24, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-17483
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and viewing the driver's license column, an attacker could exploit this vulnerability to view the dr... Read more
Affected Products : lobby_track- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-17486
Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor function while in kiosk mode. By visiting the kiosk and selecting find visitor, an attacker could exploit this vulnerability to delete... Read more
Affected Products : lobby_track- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0312
In Battery Saver, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Androi... Read more
Affected Products : android- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46654
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-16855
<p>An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view o... Read more
Affected Products : office- Published: Sep. 11, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1602
A potential security vulnerability has been identified in HP ThinPro 7.2 Service Pack 8 (SP8). The security vulnerability in SP8 is not remedied after upgrading from SP8 to Service Pack 9 (SP9). HP has released Service Pack 10 (SP10) to remediate the pote... Read more
- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-16355
The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.... Read more
Affected Products : beego- Published: Sep. 16, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4197
member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors.... Read more
Affected Products : plone- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2017-2744
The vulnerability allows attacker to extract binaries into protected file system locations in HP Support Assistant before 12.7.26.1.... Read more
Affected Products : support_assistant- Published: Jan. 23, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-22552
An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall number in MessageReader that is then used by sysno() and can bypass validation. This can allow the attacker to read memory from within the ... Read more
Affected Products : asylo- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38164
SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that... Read more
Affected Products : erp_financial_accounting- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2005-1880
everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.... Read more
Affected Products : everybuddy- Published: Jun. 06, 2005
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2023-48341
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2023-48344
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025