Latest CVE Feed
-
6.4
MEDIUMCVE-2022-32610
In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203476; Issue ID: ALPS07203476.... Read more
- EPSS Score: %0.03
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
6.7
MEDIUMCVE-2022-21778
In vpu, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06382421; Issue I... Read more
- EPSS Score: %0.01
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
3.3
LOWCVE-2022-20446
In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges ne... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-20445
In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
4.3
MEDIUMCVE-2025-27188
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security m... Read more
- Published: Apr. 08, 2025
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-36740
An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative number exceeds the range of size.... Read more
Affected Products : oneflow- Published: Jun. 06, 2024
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2024-37384
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.... Read more
- Published: Jun. 07, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-37385
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.... Read more
- Published: Jun. 07, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-4620
The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form... Read more
- Published: Jun. 07, 2024
- Modified: May. 01, 2025
-
4.8
MEDIUMCVE-2024-4621
The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered... Read more
- Published: Jun. 07, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-38440
Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue 1097 report stated: 'The latest version... Read more
Affected Products : netatalk- Published: Jun. 16, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-38441
Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.4.1 and 3.1.19 are also fixed versions.... Read more
Affected Products : netatalk- Published: Jun. 16, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-37734
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.... Read more
Affected Products : openemr- Published: Jun. 26, 2024
- Modified: May. 01, 2025
-
5.5
MEDIUMCVE-2024-4934
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform... Read more
Affected Products : quiz_and_survey_master- Published: Jul. 01, 2024
- Modified: May. 01, 2025
-
4.8
MEDIUMCVE-2024-6130
The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : form_maker- Published: Jul. 01, 2024
- Modified: May. 01, 2025
-
10.0
CRITICALCVE-2025-2857
Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sand... Read more
- Published: Mar. 27, 2025
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2025-22869
SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.... Read more
Affected Products : ssh- Published: Feb. 26, 2025
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2025-22868
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.... Read more
- Published: Feb. 26, 2025
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2023-5472
Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- EPSS Score: %0.70
- Published: Oct. 25, 2023
- Modified: May. 01, 2025
-
7.8
HIGHCVE-2023-32356
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.... Read more
Affected Products : macos- EPSS Score: %0.08
- Published: Sep. 06, 2023
- Modified: May. 01, 2025