Latest CVE Feed
-
8.1
HIGHCVE-2025-24761
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme DSK allows PHP Local File Inclusion. This issue affects DSK: from n/a through 2.2.... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2024-27592
Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via appending a crafted link to /login/ in the login page URL.... Read more
Affected Products : corezoid- Published: Apr. 11, 2024
- Modified: Jun. 17, 2025
-
6.5
MEDIUMCVE-2023-48865
An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.... Read more
Affected Products : reportico- Published: Apr. 11, 2024
- Modified: Jun. 17, 2025
-
4.8
MEDIUMCVE-2025-2524
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (... Read more
Affected Products : ninja_forms- Published: May. 19, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-1627
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site ... Read more
Affected Products : qi_blocks- Published: May. 19, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-1626
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored C... Read more
Affected Products : qi_blocks- Published: May. 19, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.7
MEDIUMCVE-2024-29783
In tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025
-
5.5
MEDIUMCVE-2024-29782
In tmu_get_tr_num_thresholds of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025
-
7.3
HIGHCVE-2024-29757
there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-29756
In afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025
-
4.4
MEDIUMCVE-2024-29755
In tmu_get_pi of tmu.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025
-
6.2
MEDIUMCVE-2024-29754
In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025
-
7.7
HIGHCVE-2024-29753
In tmu_set_control_temp_step of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025
-
7.8
HIGHCVE-2024-29752
In tmu_set_tr_num_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025
-
5.5
MEDIUMCVE-2024-29751
In asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025
-
5.5
MEDIUMCVE-2024-29750
In km_exp_did_inner of kmv.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025
-
8.4
HIGHCVE-2024-29749
In tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025
-
5.9
MEDIUMCVE-2024-29747
In _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025
-
5.4
MEDIUMCVE-2025-1625
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cro... Read more
Affected Products : qi_blocks- Published: May. 19, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.4
HIGHCVE-2024-29746
In lpm_req_handler of lpm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Apr. 05, 2024
- Modified: Jun. 17, 2025