Latest CVE Feed
-
9.8
CRITICALCVE-2024-20011
In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146;... Read more
- Published: Feb. 05, 2024
- Modified: Jun. 20, 2025
-
8.8
HIGHCVE-2024-20009
In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441... Read more
- Published: Feb. 05, 2024
- Modified: Jun. 20, 2025
-
5.3
MEDIUMCVE-2024-0853
curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped th... Read more
Affected Products : curl- Published: Feb. 03, 2024
- Modified: Jun. 20, 2025
-
8.8
HIGHCVE-2024-0813
Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)... Read more
- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-7089
The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.... Read more
Affected Products : easy_svg_support- Published: Jan. 29, 2024
- Modified: Jun. 20, 2025
-
8.8
HIGHCVE-2023-6390
The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.... Read more
Affected Products : wordpress_users- Published: Jan. 29, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUMCVE-2023-6389
The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing... Read more
Affected Products : wordpress_toolbar- Published: Jan. 29, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUMCVE-2023-6278
The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting them back in the page, leading to a Reflected Cross-Site Scrip... Read more
Affected Products : biteship- Published: Jan. 29, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51951
SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file.... Read more
Affected Products : stock_management_system- Published: Feb. 05, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51887
Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.... Read more
Affected Products : mathtex- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
9.1
CRITICALCVE-2023-51839
DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm.... Read more
Affected Products : smartphone_test_farm- Published: Jan. 29, 2024
- Modified: Jun. 20, 2025
-
6.8
MEDIUMCVE-2023-51820
An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.... Read more
- Published: Feb. 02, 2024
- Modified: Jun. 20, 2025
-
6.5
MEDIUMCVE-2023-51813
Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.... Read more
Affected Products : free_and_open_source_inventory_management_system- Published: Jan. 30, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-48132
An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 26, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-48129
An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 26, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2023-47355
The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthori... Read more
Affected Products : root_quick_reboot- Published: Feb. 05, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-43997
An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-43996
An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-43995
An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-43992
An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025