Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Angry Yack Logo
Total 34640 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-21327 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-01-22 N/A 6.6 MEDIUM
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21328 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-01-22 N/A 4.3 MEDIUM
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-21326 1 Microsoft 2 Windows Server 2022 23h2, Windows Server 2025 2025-01-22 N/A 7.8 HIGH
Internet Explorer Remote Code Execution Vulnerability
CVE-2025-21323 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-01-22 N/A 5.5 MEDIUM
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2025-21324 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-01-22 N/A 6.6 MEDIUM
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21321 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-01-22 N/A 5.5 MEDIUM
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2025-21320 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-01-22 N/A 5.5 MEDIUM
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2025-21319 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-01-22 N/A 5.5 MEDIUM
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2025-21318 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-01-22 N/A 5.5 MEDIUM
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2025-21317 1 Microsoft 8 Windows 10 21h2, Windows 10 22h2, Windows 11 22h2 and 5 more 2025-01-22 N/A 5.5 MEDIUM
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2025-21316 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-01-22 N/A 5.5 MEDIUM
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2025-21315 1 Microsoft 3 Windows 11 24h2, Windows Server 2022 23h2, Windows Server 2025 2025-01-22 N/A 7.8 HIGH
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2024-34722 1 Google 1 Android 2025-01-21 N/A 8.8 HIGH
In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-33506 1 Fortinet 1 Fortimanager 2025-01-21 N/A 3.3 LOW
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.
CVE-2024-1645 1 Wobbie 1 Mollie Forms 2025-01-21 N/A 4.3 MEDIUM
The Mollie Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportRegistrations function in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with subscriber access or higher, to export payment data collected by this plugin.
CVE-2024-12398 1 Zyxel 46 Nwa110ax, Nwa110ax Firmware, Nwa1123acv3 and 43 more 2025-01-21 N/A 8.8 HIGH
An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them to upload configuration files to a vulnerable device.
CVE-2023-4626 1 Ladipage 1 Ladipage 2025-01-21 N/A 4.3 MEDIUM
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up to, and including, 4.3. This makes it possible for authenticated attackers with subscriber-level access and above to update the 'ladiflow_hook_configs' option.
CVE-2024-49054 1 Microsoft 1 Edge Chromium 2025-01-21 N/A 4.3 MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2023-33240 2 Foxit, Microsoft 3 Pdf Editor, Pdf Reader, Windows 2025-01-21 N/A 7.8 HIGH
Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-default directory because unprivileged users have access to an executable file of a system service. This is fixed in 12.1.2.
CVE-2025-21339 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-01-21 N/A 8.8 HIGH
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21338 1 Microsoft 16 Office, Windows 10 1507, Windows 10 1607 and 13 more 2025-01-21 N/A 7.8 HIGH
GDI+ Remote Code Execution Vulnerability
CVE-2025-21330 1 Microsoft 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more 2025-01-21 N/A 7.5 HIGH
Windows Remote Desktop Services Denial of Service Vulnerability
CVE-2025-21331 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-01-21 N/A 7.3 HIGH
Windows Installer Elevation of Privilege Vulnerability
CVE-2025-21332 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-01-21 N/A 4.3 MEDIUM
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-21344 1 Microsoft 1 Sharepoint Server 2025-01-21 N/A 7.8 HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2025-21343 1 Microsoft 3 Windows 11 22h2, Windows 11 23h2, Windows 11 24h2 2025-01-21 N/A 7.5 HIGH
Windows Web Threat Defense User Service Information Disclosure Vulnerability
CVE-2025-21341 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-01-21 N/A 6.6 MEDIUM
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21340 1 Microsoft 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more 2025-01-21 N/A 5.5 MEDIUM
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
CVE-2025-21348 1 Microsoft 1 Sharepoint Server 2025-01-21 N/A 7.2 HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-24975 1 Mattermost 1 Mattermost Mobile 2025-01-21 N/A 3.5 LOW
Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the syntax highlighter, allowing an attacker to send a very large code block and crash the mobile app.
CVE-2023-6399 1 Zyxel 44 Atp100, Atp100 Firmware, Atp100w and 41 more 2025-01-21 N/A 5.7 MEDIUM
A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1, and USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1 could allow an authenticated IPSec VPN user to cause DoS conditions against the “deviceid” daemon by sending a crafted ho ...

Show More

CVE-2024-3968 1 Microfocus 1 Imanager 2025-01-21 N/A 7.8 HIGH
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task.
CVE-2023-33252 1 0kims 1 Snarkjs 2025-01-21 N/A 7.5 HIGH
iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.
CVE-2023-1696 1 Huawei 2 Emui, Harmonyos 2025-01-21 N/A 7.5 HIGH
The multimedia video module has a vulnerability in data processing.Successful exploitation of this vulnerability may affect availability.
CVE-2024-1382 1 Nicdarkthemes 1 Restaurant Reservations 2025-01-21 N/A 8.8 HIGH
The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the nd_rst_layout attribute of the nd_rst_search shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases ...

Show More

CVE-2024-1169 1 Themekraft 1 Post Form 2025-01-21 N/A 7.5 HIGH
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized media upload due to a missing capability check on the buddyforms_upload_handle_dropped_media function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to upload media files.
CVE-2024-1170 1 Themekraft 1 Post Form 2025-01-21 N/A 8.2 HIGH
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capability check on the handle_deleted_media function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to delete arbitrary media files.
CVE-2024-3872 1 Mattermost 1 Mattermost Mobile 2025-01-21 N/A 3.1 LOW
Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.
CVE-2024-34717 1 Prestashop 1 Prestashop 2025-01-21 N/A 5.3 MEDIUM
PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. This issue is patched in version 8.1.6. No known workarounds are available.
CVE-2024-2966 1 Bdthemes 1 Element Pack 2025-01-21 N/A 5.3 MEDIUM
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.5.6 via the element_pack_ajax_search function. This makes it possible for unauthenticated attackers to extract sensitive data including password protected post details.