Latest CVE Feed
-
8.8
HIGHCVE-2024-20040
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
4.4
MEDIUMCVE-2024-20041
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541746; Issue ID: ALPS08... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
6.6
MEDIUMCVE-2024-20042
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541780; Issue ID: ALPS... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
6.6
MEDIUMCVE-2024-20043
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541781; Issue ID: ALPS... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
6.6
MEDIUMCVE-2024-20044
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541784; Issue ID: ALPS... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
2.3
LOWCVE-2024-20045
In audio, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS080247... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
6.6
MEDIUMCVE-2024-20046
In battery, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08485622; Issue ID... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2024-20047
In battery, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587865; Issue ID: ALPS... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
6.2
MEDIUMCVE-2024-20048
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541769; Issue ID:... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
4.4
MEDIUMCVE-2024-20049
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541765; Issue ID:... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
4.4
MEDIUMCVE-2024-20050
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID:... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
2.3
LOWCVE-2024-20051
In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541758.... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
4.4
MEDIUMCVE-2024-20052
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID:... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
8.4
HIGHCVE-2024-20053
In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: A... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
6.6
MEDIUMCVE-2024-20054
In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
6.3
MEDIUMCVE-2024-20055
In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2023-51312
PHPJabbers Restaurant Booking System v3.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Reservations menu, Schedule section date parameter.... Read more
Affected Products : restaurant_booking_system- Published: Feb. 20, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2023-51313
PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in Syste... Read more
Affected Products : restaurant_booking_system- Published: Feb. 20, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2023-4725
The Simple Posts Ticker WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
Affected Products : simple_posts_ticker- Published: Oct. 16, 2023
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2025-3268
A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file http/http_conn.cpp. The manipulation of the argument m_url_real leads to improper authentication. The attack... Read more
Affected Products : tinywebserver- Published: Apr. 04, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authentication