Latest CVE Feed
-
5.5
MEDIUMCVE-2022-25663
Possible buffer overflow due to lack of buffer length check during management frame Rx handling lead to denial of service in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity... Read more
Affected Products : aqt1000_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6430_firmware wcd9341_firmware wcd9380_firmware wcd9385_firmware wcn3998_firmware wcn6855_firmware +52 more products- EPSS Score: %0.10
- Published: Oct. 19, 2022
- Modified: May. 15, 2025
-
7.5
HIGHCVE-2022-25662
Information disclosure due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables... Read more
Affected Products : qam8295p_firmware qca6390_firmware qca6391_firmware qca6426_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware qcc5100_firmware sa6145p_firmware +146 more products- EPSS Score: %0.27
- Published: Oct. 19, 2022
- Modified: May. 15, 2025
-
8.4
HIGHCVE-2022-22077
Memory corruption in graphics due to use-after-free in graphics dispatcher logic in Snapdragon Mobile... Read more
Affected Products : android sd_8_gen1_5g_firmware wcd9380_firmware wcn6855_firmware wcn6856_firmware wcn7850_firmware wcn7851_firmware wsa8830_firmware wsa8835_firmware wcd9380 +7 more products- EPSS Score: %0.08
- Published: Oct. 19, 2022
- Modified: May. 15, 2025
-
7.5
HIGHCVE-2021-36369
An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass ad... Read more
- EPSS Score: %0.11
- Published: Oct. 12, 2022
- Modified: May. 15, 2025
-
6.1
MEDIUMCVE-2024-10703
The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html ... Read more
Affected Products : registrations_for_the_events_calendar- Published: Mar. 25, 2025
- Modified: May. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-11272
The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the ... Read more
- Published: Mar. 25, 2025
- Modified: May. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-11273
The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the ... Read more
Affected Products : contact_form- Published: Mar. 25, 2025
- Modified: May. 15, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-6024
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make a logged in admin remove them via a CSRF attack... Read more
Affected Products : contentlock- Published: Jul. 12, 2024
- Modified: May. 15, 2025
-
5.4
MEDIUMCVE-2024-3026
The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks... Read more
Affected Products : maxbuttons- Published: Jul. 13, 2024
- Modified: May. 15, 2025
-
7.8
HIGHCVE-2025-30326
Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in... Read more
Affected Products : photoshop- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-30328
Animate versions 24.0.8, 23.0.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ... Read more
- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-30329
Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption of service. E... Read more
- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2025-30330
Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi... Read more
- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43545
Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi... Read more
- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43546
Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in th... Read more
- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43547
Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic... Read more
- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43555
Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in ... Read more
- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43556
Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v... Read more
- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43557
Animate versions 24.0.8, 23.0.11 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a ... Read more
- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4660
A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-bas... Read more
- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Authentication