Latest CVE Feed
-
7.8
HIGHCVE-2024-47898
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.... Read more
Affected Products : ddk- Published: Jan. 31, 2025
- Modified: Mar. 20, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2024-47891
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.... Read more
Affected Products : ddk- Published: Jan. 31, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Memory Corruption
-
6.4
MEDIUMCVE-2024-13463
The SeatReg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'seatreg' shortcode in all versions up to, and including, 1.56.0 due to insufficient input sanitization and output escaping on user supplied attributes. This ma... Read more
Affected Products :- Published: Jan. 31, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2024-46974
Software installed and run as a non-privileged user may conduct improper read/write operations on imported/exported DMA buffers.... Read more
Affected Products : ddk- Published: Jan. 31, 2025
- Modified: Mar. 20, 2025
- Vuln Type: Misconfiguration
-
8.1
HIGHCVE-2024-13767
The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ClearFiles() function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with ... Read more
Affected Products :- Published: Jan. 31, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Path Traversal
-
6.4
MEDIUMCVE-2024-13399
The Gosign – Posts Slider Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'posts-slider-block' block in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it poss... Read more
Affected Products :- Published: Jan. 31, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-13397
The WPRadio – WordPress Radio Streaming Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpradio_player' shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output esca... Read more
Affected Products :- Published: Jan. 31, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-13396
The Frictionless plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'frictionless_form' shortcode[s] in all versions up to, and including, 0.0.23 due to insufficient input sanitization and output escaping on user supplied a... Read more
Affected Products :- Published: Jan. 31, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Cross-Site Scripting
-
4.9
MEDIUMCVE-2023-0092
An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.... Read more
Affected Products : juju- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2022-1736
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.... Read more
- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Misconfiguration
-
3.1
LOW- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2024-23929
This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-WT7600NEX devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypa... Read more
- Published: Jan. 31, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2024-23921
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanapp... Read more
- Published: Jan. 31, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2024-23920
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the onboard... Read more
- Published: Jan. 31, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2022-28653
Users can consume unlimited disk space in /var/crash... Read more
Affected Products : apport- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Denial of Service
-
3.3
LOWCVE-2025-24336
SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may be crashed.... Read more
Affected Products :- Published: Jan. 31, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-24731
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the htt... Read more
Affected Products : gecko_os- Published: Jan. 31, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2024-23973
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HTTP GET req... Read more
Affected Products : gecko_os- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2024-23971
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handlin... Read more
- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2024-23970
This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ... Read more
- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cryptography