Latest CVE Feed
-
7.5
HIGHCVE-2024-10864
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
-
6.6
MEDIUMCVE-2025-30664
Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-4639
CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: XML External Entity
-
6.5
MEDIUMCVE-2025-30667
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
6.9
MEDIUMCVE-2025-0132
A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM. The attacker must have network access to the Broker VM to exploit this issue.... Read more
Affected Products : cortex_xdr_broker_vm- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
5.7
MEDIUMCVE-2025-20047
Improper locking in the Intel(R) Integrated Connectivity I/O interface (CNVi) for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2024-45333
Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
6.8
MEDIUMCVE-2025-20071
NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products : graphics_drivers- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
6.7
MEDIUMCVE-2024-39833
Uncontrolled search path for some Intel(R) QAT software before version 2.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
-
9.4
CRITICALCVE-2024-10865
Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-30663
Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
-
6.8
MEDIUMCVE-2025-24495
Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2024-28956
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Information Disclosure
-
6.7
MEDIUMCVE-2024-31073
Uncontrolled search path for some Intel(R) oneAPI Level Zero software may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
4.7
MEDIUMCVE-2025-46398
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.... Read more
Affected Products :- Published: Apr. 23, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
4.7
MEDIUMCVE-2025-46400
In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function.... Read more
Affected Products :- Published: Apr. 23, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
4.7
MEDIUMCVE-2025-46397
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation at the bezier_spline function.... Read more
Affected Products :- Published: Apr. 23, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-4574
In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.... Read more
Affected Products : crossbeam-channel- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Race Condition
-
9.6
CRITICALCVE-2025-47777
5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to 0.11.1 are vulnerable to stored cross-site scripting in chatbot responses due to insufficient sanitization. This, in turn, can lead to ... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
9.5
CRITICALCVE-2025-47292
Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the `DebateAlternateArgumentsResolver` deserializes a `Cursor`, allowing any classes and which can be controlled by ... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication