Latest CVE Feed
-
5.5
MEDIUMCVE-2024-49935
In the Linux kernel, the following vulnerability has been resolved: ACPI: PAD: fix crash in exit_round_robin() The kernel occasionally crashes in cpumask_clear_cpu(), which is called within exit_round_robin(), because when executing clear_bit(nr, addr) ... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Jul. 17, 2025
-
5.5
MEDIUMCVE-2024-44939
In the Linux kernel, the following vulnerability has been resolved: jfs: fix null ptr deref in dtInsertEntry [syzbot reported] general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI KASAN: null-p... Read more
Affected Products : linux_kernel- Published: Aug. 26, 2024
- Modified: Jul. 17, 2025
-
5.5
MEDIUMCVE-2024-26775
In the Linux kernel, the following vulnerability has been resolved: aoe: avoid potential deadlock at set_capacity Move set_capacity() outside of the section procected by (&d->lock). To avoid possible interrupt unsafe locking scenario: CPU0 ... Read more
Affected Products : linux_kernel- Published: Apr. 03, 2024
- Modified: Jul. 17, 2025
-
5.5
MEDIUMCVE-2024-26644
In the Linux kernel, the following vulnerability has been resolved: btrfs: don't abort filesystem when attempting to snapshot deleted subvolume If the source file descriptor to the snapshot ioctl refers to a deleted subvolume, we get the following abort... Read more
- Published: Mar. 26, 2024
- Modified: Jul. 17, 2025
-
5.5
MEDIUMCVE-2022-48703
In the Linux kernel, the following vulnerability has been resolved: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR In some case, the GDDV returns a package with a buffer which has zero length. It causes that kmemdup() returns... Read more
Affected Products : linux_kernel- Published: May. 03, 2024
- Modified: Jul. 17, 2025
-
6.2
MEDIUMCVE-2024-20850
Use of Implicit Intent for Sensitive Communication in Samsung Pay prior to version 5.4.99 allows local attackers to access information of Samsung Pay.... Read more
- Published: Apr. 02, 2024
- Modified: Jul. 17, 2025
-
5.9
MEDIUMCVE-2024-20852
Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to access testing configuration.... Read more
Affected Products : smartthings- Published: Apr. 02, 2024
- Modified: Jul. 17, 2025
-
9.8
CRITICALCVE-2024-24724
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.... Read more
Affected Products : gibbon- Published: Apr. 03, 2024
- Modified: Jul. 17, 2025
-
6.4
MEDIUMCVE-2024-0873
The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'watu-basic-chart' shortcode in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attribute... Read more
Affected Products : watu_quiz- Published: Apr. 09, 2024
- Modified: Jul. 17, 2025
-
5.3
MEDIUMCVE-2020-26939
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OA... Read more
- EPSS Score: %2.35
- Published: Nov. 02, 2020
- Modified: Jul. 17, 2025
-
5.9
MEDIUMCVE-2020-15522
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timi... Read more
- EPSS Score: %0.55
- Published: May. 20, 2021
- Modified: Jul. 17, 2025
-
5.4
MEDIUMCVE-2025-4405
The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticate... Read more
- Published: May. 22, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-4419
The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 via the 'path' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to access arbitrar... Read more
- Published: May. 22, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2022-39983
File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code.... Read more
Affected Products : rd3- EPSS Score: %0.16
- Published: Feb. 22, 2023
- Modified: Jul. 17, 2025
-
8.8
HIGHCVE-2025-48918
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0.... Read more
- Published: Jun. 13, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.0
MEDIUMCVE-2025-48919
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0.... Read more
- Published: Jun. 13, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-12063
A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this by ... Read more
- Published: Mar. 20, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Denial of Service
-
4.8
MEDIUMCVE-2025-52497
Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.... Read more
- Published: Jul. 04, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-49601
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, allowing a possible out-of-bounds read on truncated input. Specifically, an out-of-bounds read in mbedtls_... Read more
- Published: Jul. 04, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Memory Corruption
-
4.9
MEDIUMCVE-2025-49600
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in a fault scenario. Specifically, unchecked return values in mbed... Read more
- Published: Jul. 04, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cryptography