Latest CVE Feed
-
5.5
MEDIUMCVE-2025-25872
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function... Read more
Affected Products : openpanel- Published: Mar. 14, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-25873
Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function... Read more
Affected Products : openadmin- Published: Mar. 14, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.5
MEDIUMCVE-2025-2334
A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the file /api/mjkj-chat/chat/ai/delete/chat of the component Chat History Handler. The manipulation of the arg... Read more
Affected Products :- Published: Mar. 15, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-29425
Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.... Read more
- Published: Mar. 17, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-27704
There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.53. Attackers with system administrator permissions can interfere with another system administrator’s use of the manage... Read more
Affected Products : secure_access- Published: Mar. 19, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-20969
Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows local attackers to access data within Samsung Gallery.... Read more
Affected Products : samsung_gallery- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-47691
Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member allows Code Injection. This issue affects Ultimate Member: from n/a through 2.10.3.... Read more
Affected Products : ultimate_member- Published: May. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-30102
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to denial of service.... Read more
- Published: May. 08, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-30440
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to bypass ASLR.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
-
5.5
MEDIUMCVE-2025-32703
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.... Read more
- Published: May. 13, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-20013
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-21003
Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.... Read more
Affected Products : android- Published: Jul. 08, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-21009
Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.... Read more
Affected Products : android- Published: Jul. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-5463
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local authenticated attacker to obtain that information.... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-26636
Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally.... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2019-1143
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system. There a... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +7 more products- EPSS Score: %0.90
- Published: Aug. 14, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-1142
An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'.... Read more
- EPSS Score: %0.46
- Published: Sep. 11, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-7208
A vulnerability was found in 9fans plan9port up to 9da5b44. It has been classified as critical. This affects the function edump in the library /src/plan9port/src/libsec/port/x509.c. The manipulation leads to heap-based buffer overflow. The exploit has bee... Read more
Affected Products :- Published: Jul. 09, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-20021
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.... Read more
Affected Products : openharmony- Published: Mar. 04, 2025
- Modified: Mar. 04, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-22847
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.... Read more
Affected Products : openharmony- Published: Mar. 04, 2025
- Modified: Mar. 04, 2025
- Vuln Type: Denial of Service