Latest CVE Feed
-
4.3
MEDIUMCVE-2024-11014
Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the manage... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Jul. 23, 2025
-
7.2
HIGHCVE-2024-11013
Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be ... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Jul. 23, 2025
-
8.8
HIGHCVE-2025-6558
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)... Read more
- Actively Exploited
- Published: Jul. 15, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-2776
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.... Read more
Affected Products : sysaid- Actively Exploited
- Published: May. 07, 2025
- Modified: Jul. 23, 2025
- Vuln Type: XML External Entity
-
9.3
CRITICALCVE-2025-2775
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.... Read more
Affected Products : sysaid- Actively Exploited
- Published: May. 07, 2025
- Modified: Jul. 23, 2025
- Vuln Type: XML External Entity
-
7.8
HIGHCVE-2024-32919
In lwis_add_completion_fence of lwis_fence.c, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati... Read more
Affected Products : android- Published: Jun. 13, 2024
- Modified: Jul. 22, 2025
-
7.4
HIGHCVE-2024-32921
In lwis_initialize_transaction_fences of lwis_fence.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f... Read more
Affected Products : android- Published: Jun. 13, 2024
- Modified: Jul. 22, 2025
-
7.4
HIGHCVE-2024-32922
In gpu_pm_power_on_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a logic error in the code. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interacti... Read more
Affected Products : android- Published: Jun. 13, 2024
- Modified: Jul. 22, 2025
-
4.0
MEDIUMCVE-2024-32923
there is a possible cellular denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Jun. 13, 2024
- Modified: Jul. 22, 2025
-
7.5
HIGHCVE-2024-32924
In DeregAcceptProcINT of cn_NrmmStateDeregInit.cpp, there is a possible denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for expl... Read more
Affected Products : android- Published: Jun. 13, 2024
- Modified: Jul. 22, 2025
-
8.8
HIGHCVE-2024-32925
In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Jun. 13, 2024
- Modified: Jul. 22, 2025
-
5.5
MEDIUMCVE-2024-32926
there is a possible information disclosure due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Jun. 13, 2024
- Modified: Jul. 22, 2025
-
8.1
HIGHCVE-2024-32929
In gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Jun. 13, 2024
- Modified: Jul. 22, 2025
-
5.5
MEDIUMCVE-2024-32930
In plugin_ipc_handler of slc_plugin.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure of 4 bytes of stack memory with no additional execution privileges needed. User interaction is not... Read more
Affected Products : android- Published: Jun. 13, 2024
- Modified: Jul. 22, 2025
-
5.4
MEDIUMCVE-2025-47053
Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A low privileged attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the co... Read more
- Published: Jul. 16, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-46959
Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A low privileged attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the co... Read more
- Published: Jul. 16, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-32920
In set_secure_reg of sac_handler.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of 4 bytes of stack memory with no additional execution privileges needed. User interaction is not ne... Read more
Affected Products : android- Published: Jun. 13, 2024
- Modified: Jul. 22, 2025
-
8.8
HIGHCVE-2023-37933
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3 allows an authenticated attacker to perform an XSS attack via crafted HTTP o... Read more
Affected Products : fortiadc- Published: Mar. 11, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
8.6
HIGHCVE-2025-24470
An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests.... Read more
Affected Products : fortiportal- Published: Feb. 11, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Path Traversal
-
2.3
LOWCVE-2024-52966
An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.... Read more
- Published: Feb. 11, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Information Disclosure