Filtered by CWE-20
Total 12838 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-32688 1 Parseplatform 1 Parse Server Push Adapter 2025-01-14 4.9 Medium
parse-server-push-adapter is the official Push Notification adapter for Parse Server. The Parse Server Push Adapter can crash Parse Server due to an invalid push notification payload. This issue has been patched in version 4.1.3.
CVE-2024-54100 1 Huawei 2 Emui, Harmonyos 2025-01-14 6.2 Medium
Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
CVE-2023-2942 1 Open-emr 1 Openemr 2025-01-14 8.1 High
Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2024-21473 1 Qualcomm 254 Ar8035, Ar8035 Firmware, Ar9380 and 251 more 2025-01-13 9.8 Critical
Memory corruption while redirecting log file to any file location with any file name.
CVE-2023-33100 1 Qualcomm 100 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 97 more 2025-01-13 7.5 High
Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.
CVE-2024-21452 1 Qualcomm 12 C-v2x 9150, C-v2x 9150 Firmware, Qca6584au and 9 more 2025-01-13 7.3 High
Transient DOS while decoding an ASN.1 OER message containing a SEQUENCE of unknown extensions.
CVE-2024-54121 1 Huawei 1 Harmonyos 2025-01-13 6.2 Medium
Startup control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
CVE-2023-32695 1 Socket 1 Socket.io-parser 2025-01-13 7.3 High
socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. A patch has been released in version 4.2.3.
CVE-2024-56437 1 Huawei 1 Harmonyos 2025-01-13 5.7 Medium
Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2023-34152 3 Fedoraproject, Imagemagick, Redhat 4 Extra Packages For Enterprise Linux, Fedora, Imagemagick and 1 more 2025-01-13 9.8 Critical
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
CVE-2023-51931 1 Alanclarke 1 Urlite 2025-01-13 7.5 High
An issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a crafted payload to the parsing function.
CVE-2022-34159 1 Huawei 2 Cv81-wdm, Cv81-wdm Firmware 2025-01-10 7.5 High
Huawei printers have an input verification vulnerability. Successful exploitation of this vulnerability may cause device service exceptions. (Vulnerability ID: HWPSIRT-2022-80078) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2022-34159.
CVE-2022-32204 1 Huawei 2 Cv81-wdm, Cv81-wdm Firmware 2025-01-10 7.5 High
There is an improper input verification vulnerability in Huawei printer product. Successful exploitation of this vulnerability may cause service abnormal. (Vulnerability ID: HWPSIRT-2022-87185) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2022-32204.
CVE-2024-13136 1 Wangl1989 1 Mysiteforme 2025-01-10 6.3 Medium
A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the function rememberMeManager of the file src/main/java/com/mysiteforme/admin/config/ShiroConfig.java. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2023-33182 1 Nextcloud 1 Contacts 2025-01-10 0 Low
Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can't render. Due to this constellation the missing sanitization does not seem to be exploitable. It is recommended that the Contacts app is upgraded to 5.0.3 or 4.2.4
CVE-2022-4332 1 Sprecher-automation 12 Sprecon-e-c, Sprecon-e-c Firmware, Sprecon-e-p Dl6-1 and 9 more 2025-01-10 6.8 Medium
In Sprecher Automation SPRECON-E-C/P/T3 CPU in variant PU244x a vulnerable firmware verification has been identified. Through physical access and hardware manipulation, an attacker might be able to bypass hardware-based code verification and thus inject and execute arbitrary code and gain full access of the device.
CVE-2023-33103 1 Qualcomm 96 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 93 more 2025-01-10 7.5 High
Transient DOS while processing CAG info IE received from NW.
CVE-2024-39281 1 Freebsd 1 Freebsd 2025-01-10 5.3 Medium
The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel's memory allocator.
CVE-2023-23754 1 Joomla 1 Joomla\! 2025-01-10 6.1 Medium
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.
CVE-2017-15832 1 Qualcomm 10 Mdm9206, Mdm9206 Firmware, Mdm9607 and 7 more 2025-01-09 7.8 High
Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW