Latest CVE Feed
-
7.5
HIGHCVE-2025-20915
Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.... Read more
Affected Products : notes- Published: Mar. 06, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-20914
Out-of-bounds read in applying binary of hand writing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.... Read more
Affected Products : notes- Published: Mar. 06, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-20913
Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.... Read more
Affected Products : notes- Published: Mar. 06, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Information Disclosure
-
4.4
MEDIUMCVE-2025-20901
Out-of-bounds read in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to read out-of-bounds memory.... Read more
Affected Products : blockchain_keystore- Published: Feb. 04, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Memory Corruption
-
6.3
MEDIUMCVE-2025-20900
Out-of-bounds write in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to write out-of-bounds memory.... Read more
Affected Products : blockchain_keystore- Published: Feb. 04, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Memory Corruption
-
4.6
MEDIUMCVE-2025-20898
Improper input validation in Samsung Members prior to version 5.2.00.12 allows physical attackers to access data across multiple user profiles.... Read more
Affected Products : members- Published: Feb. 04, 2025
- Modified: Jul. 17, 2025
-
4.6
MEDIUMCVE-2025-20894
Improper access control in Samsung Email prior to version 6.1.97.1 allows physical attackers to access data across multiple user profiles.... Read more
Affected Products : email- Published: Feb. 04, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authorization
-
5.9
MEDIUMCVE-2025-6200
The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform... Read more
- Published: Jul. 11, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-2942
The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information... Read more
Affected Products : order_delivery_date_for_woocommerce- Published: Jul. 11, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-28245
Cross-site scripting (XSS) vulnerability in Alteryx Server 2023.1.1.460 allows remote attackers to inject arbitrary web script or HTML via the notification body.... Read more
Affected Products : alteryx_server- Published: Jul. 10, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-28244
Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localStorage, leading to account takeover... Read more
Affected Products : alteryx_server- Published: Jul. 10, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-49715
Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network.... Read more
- Published: Jun. 20, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2025-20949
Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Samsung Members.... Read more
Affected Products : members- Published: May. 07, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-20976
Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to read out-of-bounds memory.... Read more
Affected Products : notes- Published: May. 07, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2025-40923
Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbe... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Cryptography
-
6.5
MEDIUMCVE-2025-40919
Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and th... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Cryptography
-
6.5
MEDIUMCVE-2025-40913
Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net::Dropbear embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
6.0
MEDIUMCVE-2025-53026
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracl... Read more
Affected Products : vm_virtualbox- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authorization
-
8.2
HIGHCVE-2025-53027
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracl... Read more
Affected Products : vm_virtualbox- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authorization
-
8.2
HIGHCVE-2025-53028
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracl... Read more
Affected Products : vm_virtualbox- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authorization