Latest CVE Feed
-
9.1
CRITICALCVE-2024-39335
Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via the 'Current submissions' page: Administration -> Groups -> Submissions.... Read more
Affected Products : mahara- Published: Aug. 26, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2024-35203
Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part of its name, that is uploaded via the Mahara filebrowser system.... Read more
Affected Products : mahara- Published: Aug. 26, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2024-47192
An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.... Read more
Affected Products : mahara- Published: Aug. 26, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Path Traversal
-
5.1
MEDIUMCVE-2025-21038
Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.... Read more
- Published: Sep. 03, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Authorization
-
3.8
LOWCVE-2024-13308
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issue affects Browser Back Button: from 1.0.0 before 2.0.2.... Read more
- Published: Jan. 09, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-21039
Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.... Read more
- Published: Sep. 03, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2023-21471
Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-50597
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this ... Read more
- Published: Apr. 02, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-50596
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this ... Read more
- Published: Apr. 02, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Denial of Service
-
6.8
MEDIUMCVE-2023-21472
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Injection
-
6.8
MEDIUMCVE-2023-21473
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Injection
-
8.0
HIGHCVE-2023-21475
Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Memory Corruption
-
8.0
HIGHCVE-2023-21476
Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Memory Corruption
-
5.1
MEDIUMCVE-2025-21040
Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.... Read more
- Published: Sep. 03, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-50384
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger thi... Read more
- Published: Apr. 02, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-50385
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger thi... Read more
- Published: Apr. 02, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Denial of Service
-
6.8
MEDIUMCVE-2025-21031
Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-9927
A vulnerability was identified in projectworlds Travel Management System 1.0. The affected element is an unknown function of the file /viewpackage.php. Such manipulation of the argument t1 leads to sql injection. The attack may be performed from remote. T... Read more
Affected Products : travel_management_system- Published: Sep. 03, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9928
A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown function of the file /viewcategory.php. Performing manipulation of the argument t1 results in sql injection. It is possible to initiate t... Read more
Affected Products : travel_management_system- Published: Sep. 03, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2024-56190
In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl... Read more
Affected Products : android- Published: Sep. 04, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Memory Corruption