Latest CVE Feed
-
4.2
MEDIUMCVE-2020-27413
An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.... Read more
Affected Products : mahavitaran- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2025-31929
A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions), IEC 1Ph 7.4kW Child socket/ shutter (8EM1310-2EN04-0GA0) (All versions), IEC 1Ph 7.4kW Parent cable 7m (8EM1310-2EJ04-3GA1) (All versions), IEC 1Ph 7.4k... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 13, 2025
- Vuln Type: Authentication
-
4.2
MEDIUMCVE-2025-4542
A vulnerability, which was classified as problematic, has been found in Freeebird Hotel 酒店管理系统 API up to 1.2. Affected by this issue is some unknown functionality of the file /src/main/java/cn/mafangui/hotel/tool/SessionInterceptor.java. The manipulation ... Read more
Affected Products : hotel- Published: May. 11, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Misconfiguration
-
4.2
MEDIUMCVE-2024-6476
Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service restart. Axis has released patched versions for the highlighted... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
4.2
MEDIUMCVE-2025-55013
The Assemblyline 4 Service Client interfaces with the API to fetch tasks and publish the result for a service in Assemblyline 4. In versions below 4.6.1.dev138, the Assemblyline 4 Service Client (task_handler.py) accepts a SHA-256 value returned by the se... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Path Traversal
-
4.2
MEDIUMCVE-2024-37386
An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite the activation of secure boot. The following versions fix this: 4.3.27, ... Read more
Affected Products : stormshield_network_security- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2021-40041
There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Su... Read more
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2024-45678
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is pre... Read more
Affected Products : yubikey_5_nfc_firmware yubikey_5c_nfc_firmware yubikey_5c_nfc yubikey_5_nfc yubikey_5c_firmware yubikey_5c yubikey_5_nano_firmware yubikey_5_nano yubikey_5c_nano_firmware yubikey_5c_nano +26 more products- Published: Sep. 03, 2024
- Modified: Mar. 17, 2025
-
4.2
MEDIUMCVE-2019-2861
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to com... Read more
Affected Products : hyperion_planning- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2021-3047
A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks PAN-OS web interface. This enables an authenticated attacker, with the capability to observe their own authentication secrets over a lon... Read more
Affected Products : pan-os- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2019-2797
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to ... Read more
- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2024-31205
Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attacker may bypass cross-set request forgery (CSRF) validation when calling refresh token mutation with empty ... Read more
Affected Products : saleor- Published: Apr. 08, 2024
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2023-22016
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.46 and Prior to 7.0.10. Easily exploitable vulnerability allows high privileged attacker with logon to th... Read more
Affected Products : vm_virtualbox- Published: Jul. 18, 2023
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2022-21555
Vulnerability in the MySQL Shell for VS Code product of Oracle MySQL (component: Shell: GUI). Supported versions that are affected are 1.1.8 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where... Read more
- Published: Jul. 19, 2022
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2018-12076
A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated, local attacker to access funds within the customer's MarketCard balance, and also could lead to Customer Information Disclosure. The vulnerability is due ... Read more
Affected Products : market_card- Published: Dec. 13, 2018
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2025-54650
Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Memory Corruption
-
4.2
MEDIUMCVE-2025-25586
yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.... Read more
Affected Products : yimioa- Published: Mar. 18, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Information Disclosure
-
4.2
MEDIUMCVE-2024-11197
The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5. This is due to permitting application password logins when user accounts are locked. This makes it possible for authenticated attacke... Read more
Affected Products : lock_user_account- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2023-20844
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354058; Iss... Read more
- Published: Sep. 04, 2023
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2018-12038
An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key.... Read more
- Published: Nov. 20, 2018
- Modified: Nov. 21, 2024