Latest CVE Feed
-
8.3
HIGHCVE-2025-54622
Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-54627
Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025
-
5.7
MEDIUMCVE-2025-54618
Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-54623
Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-54619
Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-54620
Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
6.3
MEDIUMCVE-2025-0784
A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of the component Registered User Handler. The manipulation leads to cleartext transmission ... Read more
Affected Products : incontrol_web- Published: Jan. 28, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Cryptography
-
5.5
MEDIUMCVE-2025-24791
snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access t... Read more
- Published: Jan. 29, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
5.7
MEDIUMCVE-2025-54624
Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Injection
-
6.7
MEDIUMCVE-2025-54625
Race condition vulnerability in the kernel file system module. Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025
-
6.7
MEDIUMCVE-2025-54631
Vulnerability of insufficient data length verification in the partition module. Impact: Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2025-24789
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method ... Read more
- Published: Jan. 29, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-32740
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or over the network.... Read more
- Published: May. 14, 2024
- Modified: Aug. 20, 2025
-
7.6
HIGHCVE-2024-32742
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains an unrestricted USB port. An attacker with local access to the device could potentially misuse the port for booting another operating system and gai... Read more
- Published: May. 14, 2024
- Modified: Aug. 20, 2025
-
6.5
MEDIUMCVE-2024-34191
htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php. This vulnerability allows attackers to delete arbitrary files via a crafted request.... Read more
Affected Products : htmly- Published: May. 14, 2024
- Modified: Aug. 20, 2025
-
9.8
CRITICALCVE-2024-31510
An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /pqcrystals-dilithium-standard_ml-dsa-44-ipd_avx2/sign.c component.... Read more
Affected Products : liboqs- Published: May. 24, 2024
- Modified: Aug. 20, 2025
-
5.9
MEDIUMCVE-2024-39150
vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet.... Read more
Affected Products : vditor- Published: Jul. 05, 2024
- Modified: Aug. 20, 2025
-
7.5
HIGHCVE-2024-36405
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A control-flow timing lean has been identified in the reference implementation of the Kyber key encapsulation mechanism when it is compiled... Read more
Affected Products : liboqs- Published: Jun. 10, 2024
- Modified: Aug. 20, 2025
-
5.3
MEDIUMCVE-2024-56342
IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.... Read more
- Published: Jun. 06, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2024-56343
IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a specially crafted POST request.... Read more
- Published: Jun. 06, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Denial of Service