Vulnerabilities (CVE)

Filtered by CWE-20
Total 11158 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-20649 2 Google, Mediatek 37 Android, Mt6761, Mt6762 and 34 more 2025-03-05 N/A 4.4 MEDIUM
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628607; Issue ID: ALPS07628607.
CVE-2023-20648 2 Google, Mediatek 38 Android, Mt6761, Mt6762 and 35 more 2025-03-05 N/A 4.4 MEDIUM
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628612; Issue ID: ALPS07628612.
CVE-2023-20647 2 Google, Mediatek 33 Android, Mt6739, Mt6761 and 30 more 2025-03-05 N/A 4.4 MEDIUM
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628547; Issue ID: ALPS07628547.
CVE-2025-0956 2025-03-05 N/A 8.1 HIGH
The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 24.3.0 via deserialization of untrusted input from the 'raccookie_guest_email' cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
CVE-2025-1080 2025-03-04 N/A N/A
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.
CVE-2025-0958 2025-03-04 N/A 5.4 MEDIUM
The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 4.2.9. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary auctions, posts as well as pages and allows them to execute other actions related to auction handling.
CVE-2024-58044 2025-03-04 N/A 8.4 HIGH
Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2023-24033 1 Samsung 10 Exynos 1080, Exynos 1080 Firmware, Exynos 980 and 7 more 2025-03-03 N/A 7.5 HIGH
The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.
CVE-2023-24579 1 Mcafee 1 Total Protection 2025-03-03 N/A 5.5 MEDIUM
McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt.
CVE-2025-21126 3 Adobe, Apple, Microsoft 3 Indesign, Macos, Windows 2025-03-03 N/A 5.5 MEDIUM
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service condition. An attacker could exploit this vulnerability to cause the application to crash, resulting in a denial of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-53029 2025-03-03 N/A 7.8 HIGH
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.
CVE-2024-53012 2025-03-03 N/A 7.8 HIGH
Memory corruption may occur due to improper input validation in clock device.
CVE-2024-6254 1 Brizy 1 Brizy 2025-03-01 N/A 4.3 MEDIUM
The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on form submissions. This makes it possible for unauthenticated attackers to submit forms intended for public use as another user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. On sites where unfiltered_html is enabled, this can lead to the admin unknowingly adding a Stored Cross-Site Scripting payload.
CVE-2021-31198 1 Microsoft 1 Exchange Server 2025-02-28 6.8 MEDIUM 7.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-36888 1 Microsoft 1 Edge Chromium 2025-02-28 N/A 6.3 MEDIUM
Microsoft Edge for Android (Chromium-based) Tampering Vulnerability
CVE-2023-28301 1 Microsoft 1 Edge 2025-02-28 N/A 3.7 LOW
Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2022-20542 1 Google 1 Android 2025-02-28 N/A 7.8 HIGH
In parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238083570
CVE-2022-3767 1 Gitlab 1 Dynamic Application Security Testing Analyzer 2025-02-28 N/A 7.7 HIGH
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
CVE-2025-21350 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-02-28 N/A 5.9 MEDIUM
Windows Kerberos Denial of Service Vulnerability
CVE-2021-30713 1 Apple 2 Mac Os X, Macos 2025-02-28 4.6 MEDIUM 7.8 HIGH
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited..