Latest CVE Feed
-
4.4
MEDIUMCVE-2025-25063
An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they do not contain potentially dangerous SVG tags. SVG images can contain clickable links and execu... Read more
Affected Products : backdrop- Published: Feb. 03, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Cross-Site Scripting
-
4.4
MEDIUMCVE-2025-25062
An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaS... Read more
Affected Products : backdrop- Published: Feb. 03, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
5.7
MEDIUMCVE-2025-20643
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained the System privilege. User interactio... Read more
- Published: Feb. 03, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Information Disclosure
-
6.6
MEDIUMCVE-2025-20642
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed fo... Read more
- Published: Feb. 03, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Memory Corruption
-
7.3
HIGHCVE-2025-20641
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed fo... Read more
- Published: Feb. 03, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Memory Corruption
-
6.2
MEDIUMCVE-2025-20640
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for ... Read more
- Published: Feb. 03, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Information Disclosure
-
6.6
MEDIUMCVE-2025-20639
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed fo... Read more
- Published: Feb. 03, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Memory Corruption
-
4.6
MEDIUMCVE-2025-20638
In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is ne... Read more
- Published: Feb. 03, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-20637
In network HW, there is a possible system hang due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00399035; Issue ID: MS... Read more
- Published: Feb. 03, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Denial of Service
-
6.7
MEDIUMCVE-2025-20636
In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: A... Read more
- Published: Feb. 03, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Memory Corruption
-
6.6
MEDIUMCVE-2025-20635
In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed... Read more
- Published: Feb. 03, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-20634
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User inter... Read more
- Published: Feb. 03, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-20633
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patc... Read more
- Published: Feb. 03, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-20632
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR0... Read more
- Published: Feb. 03, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-20631
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR0... Read more
- Published: Feb. 03, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2024-20147
In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR003890... Read more
- Published: Feb. 03, 2025
- Modified: Apr. 22, 2025
-
6.6
MEDIUMCVE-2024-20142
In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed... Read more
- Published: Feb. 03, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Memory Corruption
-
6.8
MEDIUMCVE-2024-20141
In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed... Read more
- Published: Feb. 03, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Memory Corruption
-
5.0
MEDIUMCVE-2025-0974
A vulnerability, which was classified as critical, has been found in MaxD Lightning Module 4.43 on OpenCart. This issue affects some unknown processing. The manipulation of the argument li_op/md leads to deserialization. The attack may be initiated remote... Read more
Affected Products :- Published: Feb. 03, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-0973
A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_action in the library lib/admin/database_admin.php of the file /index.php?case=database&act=backAll&admin_dir=admin&site=default. The mani... Read more
Affected Products : cmseasy- Published: Feb. 03, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Path Traversal