Latest CVE Feed
-
5.5
MEDIUMCVE-2025-20952
Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-21082
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-21098
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check.... Read more
Affected Products : openharmony- Published: Mar. 04, 2025
- Modified: Mar. 04, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-21012
Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to modify fall detection configuration.... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-20887
Out-of-bounds read in accessing table used for svp8t in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-20986
Improper access control in ScreenCapture for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to take screenshots.... Read more
Affected Products :- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-20673
In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413200; Issue ID: MSV-33... Read more
Affected Products : mt7902_firmware mt7921_firmware mt7902 mt7921 mt7927 mt7922 mt7925 mt7922_firmware mt7925_firmware mt7927_firmware- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-20933
Out-of-bounds read in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-of-bounds memory.... Read more
Affected Products : notes- Published: Mar. 06, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-20932
Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memory.... Read more
Affected Products : notes- Published: Mar. 06, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-20213
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. To exploit this vulnerability, the attack... Read more
Affected Products : catalyst_sd-wan_manager- Published: May. 07, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2022-20264
In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed.... Read more
Affected Products : android- Published: Oct. 30, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-20042
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read.... Read more
Affected Products : openharmony- Published: Mar. 04, 2025
- Modified: Mar. 04, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-20011
in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.... Read more
Affected Products : openharmony- Published: Mar. 04, 2025
- Modified: Mar. 04, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2023-42631
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Nov. 01, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-1632
A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. T... Read more
Affected Products : libarchive- Published: Feb. 24, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-1349
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus... Read more
- Published: Jun. 18, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-1164
A vulnerability, which was classified as problematic, has been found in code-projects Police FIR Record Management System 1.0. This issue affects some unknown processing of the component Add Record Handler. The manipulation leads to stack-based buffer ove... Read more
Affected Products : police_fir_record_management_system- Published: Feb. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-0913
os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a syml... Read more
- Published: Jun. 11, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2024-9843
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.... Read more
- Published: Nov. 12, 2024
- Modified: Jan. 17, 2025
-
5.5
MEDIUMCVE-2024-9775
The Anih - Creative Agency WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2024 due to an incomplete blacklist, insufficient input sanitization, and output escaping.... Read more
Affected Products : anih- Published: Nov. 09, 2024
- Modified: Nov. 26, 2024