Latest CVE Feed
-
6.4
MEDIUMCVE-2024-49200
An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM varia... Read more
Affected Products : kernel- Published: Apr. 15, 2025
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2025-29088
In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may... Read more
Affected Products : sqlite- Published: Apr. 10, 2025
- Modified: Apr. 30, 2025
-
7.2
HIGHCVE-2024-20057
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2025-29017
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.... Read more
- Published: Apr. 10, 2025
- Modified: Apr. 30, 2025
-
4.4
MEDIUMCVE-2024-20058
In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580204; Issue ID... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-22926
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.... Read more
Affected Products : opensis- Published: Apr. 03, 2025
- Modified: Apr. 30, 2025
-
6.7
MEDIUMCVE-2024-20059
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue I... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2024-38985
janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via in... Read more
Affected Products : depath- Published: Mar. 28, 2025
- Modified: Apr. 30, 2025
-
5.9
MEDIUMCVE-2024-20060
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue I... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2024-37765
Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-37764
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-37763
MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
9.9
CRITICALCVE-2024-37762
MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-48951
An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.... Read more
Affected Products : siem- Published: Nov. 07, 2024
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2024-48952
An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for una... Read more
Affected Products : soar- Published: Nov. 07, 2024
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-48953
An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoi... Read more
Affected Products : siem- Published: Nov. 07, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2025-46228
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows DOM-Based XSS. This issue affects Event post: from n/a through 5.9.11.... Read more
Affected Products : event_post- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
-
5.5
MEDIUMCVE-2021-47172
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers Channel numbering must start at 0 and then not have any holes, or it is possible to overflow the available... Read more
Affected Products : linux_kernel- Published: Mar. 25, 2024
- Modified: Apr. 30, 2025
-
6.3
MEDIUMCVE-2021-47189
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory ordering between normal and ordered work functions Ordered work functions aren't guaranteed to be handled by the same thread which executed the normal work functions. ... Read more
Affected Products : linux_kernel- Published: Apr. 10, 2024
- Modified: Apr. 30, 2025
-
5.9
MEDIUMCVE-2025-46229
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics allows Stored XSS. This issue affects Textmetrics: from n/a through 3.6.2.... Read more
Affected Products : textmetrics- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025