Latest CVE Feed
-
4.3
MEDIUMCVE-2024-12879
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'qc_wp_latest_update_check_pro' function in all versions up to, and including, 13.5.5. This makes it possible ... Read more
- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
-
8.6
HIGHCVE-2024-11218
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the e... Read more
Affected Products : enterprise_linux openshift_container_platform international_components_for_unicode- Published: Jan. 22, 2025
- Modified: Apr. 16, 2025
-
6.4
MEDIUMCVE-2024-13590
The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' shortcode in all versions up to, and including, 0.1.2 due to insufficient input sanitization and output escaping on user supplied attributes... Read more
Affected Products : ketchup_shortcodes- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
-
6.4
MEDIUMCVE-2024-13584
The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_pictures' shortcode in all versions up to, and including, 1.5.19 due to insufficient input sanit... Read more
Affected Products : picture_gallery- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
-
5.4
MEDIUMCVE-2024-13426
The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes ... Read more
Affected Products : wp-polls- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
-
7.7
HIGHCVE-2025-23083
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be g... Read more
Affected Products : node.js- Published: Jan. 22, 2025
- Modified: Jul. 22, 2025
-
3.1
LOWCVE-2025-0625
A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. This affects an unknown part of the component Attachment Handler. The manipulation leads to improper control of resource identifiers. It is possib... Read more
Affected Products : school_management_software- Published: Jan. 22, 2025
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2024-13091
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qcld_wpcfb_file_upload' function in all versions up to, and including, 13.5.4. This makes it possible for unauthentica... Read more
Affected Products : wpot- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
-
6.5
MEDIUMCVE-2023-37039
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allow network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet miss... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Mar. 14, 2025
-
8.8
HIGHCVE-2024-49749
In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-49748
In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploita... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-49747
In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploita... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
7.8
HIGHCVE-2024-49745
In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
7.8
HIGHCVE-2024-49744
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
7.8
HIGHCVE-2024-49742
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privi... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
7.8
HIGHCVE-2024-49738
In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
7.8
HIGHCVE-2024-49737
In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privi... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
5.5
MEDIUMCVE-2024-49736
In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is n... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
7.8
HIGHCVE-2024-49735
In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
7.5
HIGHCVE-2024-49734
In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to through a VPN due to side channel information disclosure. This could lead to remote information disclosure with no a... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025