Latest CVE Feed
-
5.5
MEDIUMCVE-2023-48346
In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2023-48344
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2023-48343
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
4.4
MEDIUMCVE-2023-48342
In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2023-48341
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2023-48340
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
4.4
MEDIUMCVE-2023-48339
In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUMCVE-2023-48104
Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.... Read more
Affected Products : sogo- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
4.3
MEDIUMCVE-2024-30370
RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in tha... Read more
Affected Products : winrar- Published: Apr. 02, 2024
- Modified: Jun. 20, 2025
-
4.8
MEDIUMCVE-2024-37773
An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen.... Read more
Affected Products : dctrack- Published: Dec. 16, 2024
- Modified: Jun. 20, 2025
-
7.8
HIGHCVE-2023-40477
RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit ... Read more
Affected Products : winrar- Published: May. 03, 2024
- Modified: Jun. 20, 2025
-
5.3
MEDIUMCVE-2024-56128
Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Salted Challenge Response Authentication Mechanism (SCRAM) did not fully adhere to the requirements of RFC 58... Read more
Affected Products : kafka- Published: Dec. 18, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2025-2056
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function. This makes it possible for unauthenticated attackers to read the contents of... Read more
Affected Products : hide_my_wp_ghost- Published: Mar. 14, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2024-55897
IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes ... Read more
- Published: Jan. 03, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Misconfiguration
-
9.3
CRITICALCVE-2025-22275
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote log... Read more
Affected Products : iterm2- Published: Jan. 03, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2024-33894
Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.... Read more
- Published: Aug. 02, 2024
- Modified: Jun. 20, 2025
-
3.1
LOWCVE-2024-51472
IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensiti... Read more
- Published: Jan. 06, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Information Disclosure
-
8.1
HIGHCVE-2024-38447
NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to an arbitrary user).... Read more
Affected Products : advisor_network- Published: Jul. 17, 2024
- Modified: Jun. 20, 2025
-
6.5
MEDIUMCVE-2024-38446
NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of that report to an arbitrary user (without their consent or knowledge) via a modified UUID in a POST request.... Read more
Affected Products : advisor_network- Published: Jul. 17, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2025-21616
Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profi... Read more
Affected Products : plane- Published: Jan. 06, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cross-Site Scripting