Latest CVE Feed
-
5.5
MEDIUMCVE-2024-36476
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Ensure 'ib_sge list' is accessible Move the declaration of the 'ib_sge list' variable outside the 'always_invalidate' block to ensure it remains accessible for use throughout... Read more
Affected Products : linux_kernel- Published: Jan. 15, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2024-13215
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authentica... Read more
Affected Products : elementor_addon_elements- Published: Jan. 15, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2024-11029
A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator pass... Read more
Affected Products : enterprise_linux- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Information Disclosure
-
6.4
MEDIUMCVE-2024-12593
The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yeepdf_dotab shortcode in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output es... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-11851
The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the nitropack_rml_notification function in all versions up to, and including, 1.17.0. This makes it possible for authenticated... Read more
Affected Products : nitropack- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2024-11848
The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all versions up to, and including, 1.17.0. This makes it possible for authenti... Read more
Affected Products : nitropack- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-0448
Inappropriate implementation in Compositing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
-
8.8
HIGHCVE-2025-0447
Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-0446
Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-0443
Insufficient data validation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted HTML page. (Chromium security severity: Mediu... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-0442
Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-0441
Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtain potentially sensitive information from the system via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-0440
Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-0439
Race in Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Race Condition
-
8.8
HIGHCVE-2025-0438
Stack buffer overflow in Tracing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-0437
Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-0436
Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-0435
Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-0434
Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
5.2
MEDIUMCVE-2025-0193
A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administ... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting