Latest CVE Feed
-
5.5
MEDIUMCVE-2025-24142
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to access sensitive user data.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
6.6
MEDIUMCVE-2023-31493
RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.... Read more
Affected Products : zoneminder- Published: Oct. 15, 2024
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2024-30807
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.... Read more
Affected Products : bento4- Published: Apr. 02, 2024
- Modified: May. 27, 2025
-
5.5
MEDIUMCVE-2025-24111
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.3, visionOS 2.3, iPadOS 17.7.7, watchOS 11.3, macOS Sonoma 14.7.5, iOS 18.3 and iPadOS 18.3, tvOS 18.3, macOS Ventura 13.7.5. An app may be abl... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-24144
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, visionOS 2.3, iPadOS 17.7.7, watchOS 11.3, macOS Ventura 13.7.6, iOS 18.3 and iPadOS 18.3, tvOS 18.3. An app may... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-24155
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to disclose kernel memory.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2024-30806
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.... Read more
Affected Products : bento4- Published: Apr. 02, 2024
- Modified: May. 27, 2025
-
5.5
MEDIUMCVE-2025-24220
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4. An app may be able to read a persistent device identifier.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-24222
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously crafted web content may lead to an unexpected process crash.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
7.6
HIGHCVE-2024-31621
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.... Read more
Affected Products : flowise- Published: Apr. 29, 2024
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2024-23076
JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /labels/BubbleXYItemLabelGenerator.java. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vu... Read more
Affected Products : jfreechart- Published: Apr. 10, 2024
- Modified: May. 27, 2025
-
4.3
MEDIUMCVE-2024-34047
O-RAN RIC I-Release e2mgr lacks array size checks in RicServiceUpdateHandler.... Read more
Affected Products : ric-plt-e2mgr- Published: Apr. 30, 2024
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2024-34048
O-RAN RIC I-Release e2mgr lacks array size checks in E2nodeConfigUpdateNotificationHandler.... Read more
Affected Products : ric-plt-e2mgr- Published: Apr. 30, 2024
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2024-34049
Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0:3], plmnIdString[3:]" in reader.go.... Read more
Affected Products : traffic_steering_xapplication- Published: Apr. 30, 2024
- Modified: May. 27, 2025
-
6.1
MEDIUMCVE-2023-4709
A vulnerability classified as problematic has been found in TOTVS RM 12.1. Affected is an unknown function of the file Login.aspx of the component Portal. The manipulation of the argument VIEWSTATE leads to cross site scripting. It is possible to launch t... Read more
Affected Products : rm- Published: Sep. 01, 2023
- Modified: May. 27, 2025
-
10.0
CRITICALCVE-2025-46337
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using A... Read more
Affected Products : adodb- Published: May. 01, 2025
- Modified: May. 26, 2025
- Vuln Type: Injection
-
4.1
MEDIUMCVE-2024-13176
Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an at... Read more
Affected Products : openssl- Published: Jan. 20, 2025
- Modified: May. 26, 2025
- Vuln Type: Cryptography
-
4.3
MEDIUMCVE-2025-4035
A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections an... Read more
- Published: Apr. 29, 2025
- Modified: May. 26, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-1926
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validation on the pagelayer_save_post funct... Read more
Affected Products : pagelayer- Published: Mar. 10, 2025
- Modified: May. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2024-13228
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, with Contributor-lev... Read more
Affected Products : qubely- Published: Mar. 11, 2025
- Modified: May. 26, 2025
- Vuln Type: Information Disclosure