Search Results (101001 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-43060 1 Qualcomm 82 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 79 more 2025-03-03 7.8 High
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
CVE-2024-43061 1 Qualcomm 60 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 57 more 2025-03-03 7.8 High
Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.
CVE-2024-45710 1 Solarwinds 1 Solarwinds Platform 2025-03-01 7.8 High
SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the affected node machine.
CVE-2025-23089 2025-03-01 8.8 High
This Record was REJECTED after determining it is not in compliance with CVE Program requirements regarding assignment for vulnerabilities
CVE-2024-12960 1 1000projects 1 Portfolio Management System Mca 2025-02-28 7.3 High
A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0. This issue affects some unknown processing of the file /update_edu_details.php. The manipulation of the argument q leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2023-27161 1 Jellyfin 1 Jellyfin 2025-02-28 7.5 High
Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.
CVE-2023-24709 1 Paradox 2 Ipr512, Ipr512 Firmware 2025-02-28 7.5 High
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.
CVE-2023-26109 1 Node-bluetooth-serial-port Project 1 Node-bluetooth-serial-port 2025-02-28 7.3 High
All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.
CVE-2023-26110 1 Node-bluetooth Project 1 Node-bluetooth 2025-02-28 7.3 High
All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.
CVE-2023-0050 1 Gitlab 1 Gitlab 2025-02-28 8.7 High
An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.
CVE-2023-36887 1 Microsoft 1 Edge Chromium 2025-02-28 7.8 High
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2023-33157 1 Microsoft 1 Sharepoint Server 2025-02-28 8.8 High
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2023-33131 1 Microsoft 4 Office, Office Long Term Servicing Channel, Outlook and 1 more 2025-02-28 8.8 High
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2023-24860 1 Microsoft 1 Malware Protection Engine 2025-02-28 7.5 High
Microsoft Defender Denial of Service Vulnerability
CVE-2023-20947 1 Google 1 Android 2025-02-28 7.8 High
In getGroupState of GrantPermissionsViewModel.kt, there is a possible way to keep a one-time permission granted due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237405974
CVE-2023-20931 1 Google 1 Android 2025-02-28 7.8 High
In avdt_scb_hdl_write_req of avdt_scb_act.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242535997
CVE-2023-20917 1 Google 1 Android 2025-02-28 7.8 High
In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242605257
CVE-2023-20911 1 Google 1 Android 2025-02-28 7.8 High
In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242537498
CVE-2023-20906 1 Google 1 Android 2025-02-28 7.8 High
In onPackageAddedInternal of PermissionManagerService.java, there is a possible way to silently grant a permission after a Target SDK update due to a permissions bypass. This could lead to local escalation of privilege after updating an app to a higher Target SDK with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-221040577
CVE-2022-41032 3 Fedoraproject, Microsoft, Redhat 7 Fedora, .net, .net Core and 4 more 2025-02-28 7.8 High
NuGet Client Elevation of Privilege Vulnerability