Latest CVE Feed
-
8.5
HIGHCVE-2025-43595
An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22).... Read more
Affected Products :- Published: May. 01, 2025
- Modified: May. 22, 2025
- Vuln Type: Misconfiguration
-
4.6
MEDIUMCVE-2018-18984
Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .... Read more
- Published: Dec. 14, 2018
- Modified: May. 22, 2025
-
5.3
MEDIUMCVE-2018-14781
Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the re... Read more
Affected Products : 508_minimed_insulin_pump_firmware 522_paradigm_real-time_firmware 722_paradigm_real-time_firmware 523_paradigm_revel_firmware 723_paradigm_revel_firmware 523k_paradigm_revel_firmware 723k_paradigm_revel_firmware 551_minimed_530g_firmware 751_minimed_530g_firmware 508_minimed_insulin_pump +8 more products- Published: Aug. 13, 2018
- Modified: May. 22, 2025
-
5.3
MEDIUMCVE-2018-10634
Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently skilled attacker could capture these transmissions and extract sensitive information, such as device serial numbers.... Read more
Affected Products : minimed_paradigm_revel_mmt-523k_firmware minimed_paradigm_revel_mmt-723k_firmware minimed_paradigm_revel_mmt-723_firmware minimed_530g_mmt-551_firmware minimed_paradigm_real-time_mmt-522_firmware minimed_paradigm_real-time_mmt-722_firmware minimed_530g_mmt-751_firmware minimed_paradigm_revel_mmt-523_firmware minimed_paradigm_508_insulin_pump_firmware minimed_paradigm_revel_mmt-523k +8 more products- Published: Aug. 13, 2018
- Modified: May. 22, 2025
-
5.9
MEDIUMCVE-2025-3516
The Simple Lightbox WordPress plugin before 2.9.4 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : simple_lightbox- Published: May. 16, 2025
- Modified: May. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2019-25220
Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain Width Expansion" attack) because a node does not first verify that a presented chain has enough work b... Read more
Affected Products : bitcoin_core- Published: Nov. 18, 2024
- Modified: May. 22, 2025
-
5.3
MEDIUMCVE-2024-55563
Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example, the outcome of an HTLC (Hashed Timelock Contract) can be changed because a flood of transaction traffic prevents p... Read more
Affected Products : bitcoin_core- Published: Dec. 09, 2024
- Modified: May. 22, 2025
-
4.3
MEDIUMCVE-2025-32728
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.... Read more
- Published: Apr. 10, 2025
- Modified: May. 22, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-35202
Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn message that are not committed to in a block's merkle root. FillBlock can be called t... Read more
- Published: Oct. 10, 2024
- Modified: May. 22, 2025
-
7.5
HIGHCVE-2019-3728
RSA BSAFE Crypto-C Micro Edition versions from 4.0.0.0 before 4.0.5.4 and from 4.1.0 before 4.1.4, RSA BSAFE Micro Edition Suite versions from 4.0.0 before 4.0.13 and from 4.1.0 before 4.4 and RSA Crypto-C versions from 6.0.0 through 6.4.* are vulnerable ... Read more
- Published: Sep. 30, 2019
- Modified: May. 22, 2025
-
7.5
HIGHCVE-2022-40106
Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the set_local_time function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
7.2
HIGHCVE-2022-3076
The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for exampl... Read more
Affected Products : cm_download_manager- Published: Sep. 26, 2022
- Modified: May. 22, 2025
-
7.8
HIGHCVE-2022-32829
This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
7.8
HIGHCVE-2022-32826
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to gain root pri... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
7.8
HIGHCVE-2022-32798
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.5. An app may be able to gain elevated privileges.... Read more
Affected Products : macos- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
4.4
MEDIUMCVE-2022-32782
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.... Read more
Affected Products : macos- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
4.4
MEDIUMCVE-2022-32781
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8. An app with root privileges may be able to access private information.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
5.5
MEDIUMCVE-2022-26707
An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in macOS Monterey 12.4. A user may be able to view sensitive user information.... Read more
Affected Products : macos- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
8.8
HIGHCVE-2022-22637
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
8.8
HIGHCVE-2022-22628
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code executio... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025