Latest CVE Feed
-
5.5
MEDIUMCVE-2025-21162
Photoshop Elements versions 2025.0 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requ... Read more
- Published: Feb. 11, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2019-10484
Use after free issue occurs when command destructors access dynamically allocated response buffer which is already deallocated during previous command teardwon sequence in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial... Read more
Affected Products : sdm660_firmware sm8150_firmware sm8250_firmware sxr2130_firmware qcs605_firmware sdx24_firmware msm8909w_firmware qcs405_firmware apq8098_firmware sda845_firmware +22 more products- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-5748
External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to disclose the content of local files to logged-in users.... Read more
Affected Products : access_manager- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2022-26841
Insufficient control flow management for the Intel(R) SGX SDK software for Linux before version 2.16.100.1 may allow an authenticated user to potentially enable information disclosure via local access.... Read more
- Published: Feb. 16, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-9287
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: ... Read more
Affected Products : android- Published: Sep. 27, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-36160
An issue was discovered in Qubo Smart Plug10A version HSP02_01_01_14_SYSTEM-10 A, allows local attackers to gain sensitive information and other unspecified impact via UART console.... Read more
- Published: Sep. 16, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-36307
ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField call) via an image of zero width. NOTE: it is unclear whether there are common use cases in which this panic could have any security co... Read more
Affected Products : zplgfa- Published: Sep. 05, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-45314
Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 12, 2024
-
5.5
MEDIUMCVE-2024-41665
Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists in the "Playlists - Democratic - Configure Democratic Playlist" feature. A... Read more
Affected Products : ampache- Published: Jul. 23, 2024
- Modified: Feb. 03, 2025
-
5.5
MEDIUMCVE-2024-3434
A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability is an unknown functionality of the component User Management. The manipulation leads to improper authorization. The attack can be launc... Read more
Affected Products :- Published: Apr. 08, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-22899
Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.... Read more
Affected Products : core_ftp- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-8676
The get_vlc2 function in get_bits.h in Libav 11.9 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted mp3 file. NOTE: this issue exists due to an incomplete fix for CVE-2016-8675.... Read more
Affected Products : libav- Published: Feb. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2024-34353
The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side `key backup` stores encrypted copies of Matrix message keys. This facilitates key sh... Read more
Affected Products : matrix-rust-sdk- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20353
In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need... Read more
Affected Products : android- Published: Aug. 10, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0617
In ape extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561391... Read more
Affected Products : android- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0619
In ape extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561395... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-37142
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees().... Read more
Affected Products : chakracore- Published: Jul. 18, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0622
In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-47402
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read.... Read more
Affected Products : openharmony- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.5
MEDIUMCVE-2024-47459
Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An attacker could exploit this vulnerability to crash the application, resulting i... Read more
Affected Products : substance_3d_sampler- Published: Oct. 17, 2024
- Modified: Oct. 23, 2024