Latest CVE Feed
-
4.2
MEDIUMCVE-2025-53885
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the ... Read more
Affected Products : directus- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Information Disclosure
-
4.2
MEDIUMCVE-2019-12762
Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch.... Read more
Affected Products : mi_5s_plus_firmware xperia_z4_firmware galaxy_s6_edge_firmware galaxy_s4_firmware nexus_7_firmware nexus_9_firmware aquos_zeta_sh-04f_firmware arrows_nx_f05-f_firmware nexus_7 galaxy_s4 +6 more products- Published: Jun. 06, 2019
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2020-14546
Vulnerability in the Hyperion Financial Close Management product of Oracle Hyperion (component: Close Manager). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via ... Read more
Affected Products : hyperion_financial_close_management- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2020-14764
Vulnerability in the Hyperion Planning product of Oracle Hyperion (component: Application Development Framework). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access vi... Read more
Affected Products : hyperion_planning- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2024-55159
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/loginLog/list.... Read more
Affected Products :- Published: Feb. 21, 2025
- Modified: Mar. 12, 2025
- Vuln Type: Injection
-
4.2
MEDIUMCVE-2024-48926
Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. The Backoffice displays the logout page with a ses... Read more
Affected Products : umbraco_cms- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
4.2
MEDIUMCVE-2024-36036
Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.... Read more
Affected Products : manageengine_adaudit_plus- Published: May. 27, 2024
- Modified: May. 16, 2025
-
4.2
MEDIUMCVE-2020-13882
CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker ca... Read more
- Published: Jun. 18, 2020
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2020-13464
The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU or DMA module.... Read more
- Published: Aug. 31, 2020
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2025-1540
An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone inter... Read more
Affected Products : gitlab- Published: Mar. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
4.2
MEDIUMCVE-2018-8435
A security feature bypass vulnerability exists when Windows Hyper-V BIOS loader fails to provide a high-entropy source, aka "Windows Hyper-V Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.... Read more
- Published: Sep. 13, 2018
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2017-8754
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page containing malicious content, due to the way that the Edge Content Security Policy (CSP) validates certain specia... Read more
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
4.2
MEDIUMCVE-2023-42934
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app with root privileges may be able to access private information.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
4.2
MEDIUMCVE-2017-13679
A denial of service (DoS) attack in Symantec Encryption Desktop before SED 10.4.1 MP2HF1 allows remote attackers to make a particular machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a spe... Read more
Affected Products : encryption_desktop- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
4.2
MEDIUMCVE-2023-45920
Xfig v3.2.8 was discovered to contain a NULL pointer dereference when calling XGetWMHints(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server or win... Read more
Affected Products :- Published: Mar. 27, 2024
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2023-36559
Microsoft Edge (Chromium-based) Spoofing Vulnerability... Read more
Affected Products : edge_chromium- Published: Oct. 13, 2023
- Modified: Dec. 12, 2024
-
4.2
MEDIUMCVE-2024-21066
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the in... Read more
- Published: Apr. 16, 2024
- Modified: Jun. 18, 2025
-
4.2
MEDIUMCVE-2023-51710
EMS SQL Manager 3.6.2 (build 55333) for Oracle allows DLL hijacking: a user can trigger the execution of arbitrary code every time the product is executed.... Read more
Affected Products :- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2024-56998
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the parameter $address.... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Scripting
-
4.2
MEDIUMCVE-2024-56997
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Email' parameter.... Read more
Affected Products : hospital_management_system- Published: Jan. 21, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Scripting