Latest CVE Feed
-
5.5
MEDIUMCVE-2024-26333
swftools v0.9.2 was discovered to contain a segmentation violation via the function free_lines at swftools/lib/modules/swfshape.c.... Read more
Affected Products : swftools- Published: Mar. 05, 2024
- Modified: Apr. 01, 2025
-
5.5
MEDIUMCVE-2023-27754
vox2mesh 1.0 has stack-overflow in main.cpp, this is stack-overflow caused by incorrect use of memcpy() funciton. The flow allows an attacker to cause a denial of service (abort) via a crafted file.... Read more
Affected Products : vox2mesh- Published: Mar. 22, 2023
- Modified: Feb. 26, 2025
-
5.5
MEDIUMCVE-2020-3491
A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker with administrative privileges to conduct a cross-site scripting (XSS) attack against a user of the interface on a... Read more
Affected Products : vision_dynamic_signage_director- Published: Aug. 26, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-23441
Vba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the Vba32m64.sys driver.... Read more
- Published: Jan. 29, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26361
A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory from the ASP stage 2 bootloader potentially leading to information disclosure.... Read more
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-25453
Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.... Read more
Affected Products : bento4- Published: Feb. 09, 2024
- Modified: Jun. 16, 2025
-
5.5
MEDIUMCVE-2022-33685
Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information.... Read more
- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-0772
A vulnerability was found in Nsasoft ShareAlarmPro 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. Local... Read more
Affected Products : sharealarmpro- Published: Jan. 22, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-27237
In wipe_ns_memory of nsmemwipe.c, there is a possible incorrect size calculation due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat... Read more
Affected Products : android- Published: Mar. 11, 2024
- Modified: Mar. 25, 2025
-
5.5
MEDIUMCVE-2021-26737
The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition. ... Read more
Affected Products : client_connector- Published: Oct. 23, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-29085
Improper access control for some BigDL software maintained by Intel(R) before version 2.5.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 15, 2024
-
5.5
MEDIUMCVE-2024-3048
The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators... Read more
Affected Products : bannerlid- Published: Apr. 26, 2024
- Modified: May. 14, 2025
-
5.5
MEDIUMCVE-2023-32470
Dell Digital Delivery versions prior to 5.0.82.0 contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of ... Read more
Affected Products : digital_delivery- Published: Sep. 08, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-5474
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation o... Read more
Affected Products : dolby_vision_provisioning- Published: Oct. 11, 2024
- Modified: Nov. 15, 2024
-
5.5
MEDIUMCVE-2024-35427
vmir e8117 was discovered to contain a segmentation violation via the export_function function at /src/vmir_wasm_parser.c.... Read more
Affected Products : vmir- Published: Nov. 08, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2024-6700
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.... Read more
- Published: Sep. 12, 2024
- Modified: Sep. 13, 2024
-
5.5
MEDIUMCVE-2023-28715
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable denial of service via local access.... Read more
- Published: Feb. 14, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-34742
In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction ... Read more
Affected Products : android- Published: Aug. 15, 2024
- Modified: Nov. 25, 2024
-
5.5
MEDIUMCVE-2024-9483
A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash the application during processing.... Read more
- Published: Oct. 04, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2025-4552
A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/system/user/1/password. The manipulation leads to unverified password change. The a... Read more
Affected Products :- Published: May. 12, 2025
- Modified: May. 12, 2025
- Vuln Type: Authentication