Latest CVE Feed
-
5.5
MEDIUMCVE-2019-19767
The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.... Read more
Affected Products : linux_kernel- EPSS Score: %0.92
- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-58129
In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.... Read more
Affected Products : misp- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-28097
OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.... Read more
- Published: Mar. 28, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-3008
A vulnerability classified as critical has been found in Novastar CX40 up to 2.44.0. Affected is the function system/popen of the file /usr/nova/bin/netconfig of the component NetFilter Utility. The manipulation leads to command injection. The exploit has... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-24215
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-24261
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.... Read more
Affected Products : macos- Published: Mar. 31, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-30455
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.... Read more
Affected Products : macos- Published: Mar. 31, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-30470
A path handling issue was addressed with improved logic. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to read sensitive location information.... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-31191
This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.... Read more
- Published: Mar. 31, 2025
- Modified: May. 10, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-1267
The Groundhogg plugin for Wordpress is vulnerable to Stored Cross-Site Scripting via the ‘label' parameter in versions up to, and including, 3.7.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac... Read more
Affected Products : groundhogg- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-51497
An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went into the MacOS general logs for any unsandboxed process to read. This may be d... Read more
Affected Products :- Published: Jul. 17, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-41458
Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive data via direct access to the app’s filesystem.... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cryptography
-
5.5
MEDIUMCVE-2023-53154
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.... Read more
Affected Products : cjson- Published: May. 23, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-21431
Information disclosure may be there when a guest VM is connected.... Read more
Affected Products : qam8295p_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware sa6155p_firmware sa8145p_firmware sa8150p_firmware sa8155p_firmware +62 more products- Published: Apr. 07, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-31475
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker wit... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-29480
Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that the report is invalid and could not be reproduced.... Read more
Affected Products : gdal- Published: Apr. 07, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-20934
Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.... Read more
Affected Products : android- Published: Apr. 08, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-20947
Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.... Read more
Affected Products :- Published: Apr. 08, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-20950
Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information.... Read more
Affected Products : notes- Published: Apr. 08, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-22014
In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pdr: Fix the potential deadlock When some client process A call pdr_add_lookup() to add the look up for the service and does schedule locator work, later a process B got a ne... Read more
Affected Products : linux_kernel- Published: Apr. 08, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Race Condition