Vulnerabilities > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-02-04 | CVE-2025-20889 | Out-of-bounds Write vulnerability in Samsung Android 12.0/13.0/14.0 Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. | 5.5 |
2025-02-04 | CVE-2025-20891 | Out-of-bounds Read vulnerability in Samsung Android 12.0/13.0/14.0 Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. | 5.5 |
2025-02-04 | CVE-2025-20892 | Unspecified vulnerability in Samsung Android 13.0/14.0 Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute fastboot command. low complexity samsung | 5.9 |
2025-02-04 | CVE-2025-20893 | Unspecified vulnerability in Samsung Android 14.0 Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the configuration of notifications. | 5.1 |
2025-02-04 | CVE-2025-20904 | Out-of-bounds Write vulnerability in Samsung Android 12.0/13.0/14.0 Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption. | 6.7 |
2025-02-04 | CVE-2025-20905 | Out-of-bounds Read vulnerability in Samsung Android 12.0/13.0/14.0 Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory. | 6.7 |
2025-02-04 | CVE-2025-20907 | Unspecified vulnerability in Samsung Android 12.0/13.0 Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find. | 4.4 |
2025-02-04 | CVE-2024-12597 | Cross-site Scripting vulnerability in Hasthemes HT Mega The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. | 5.4 |
2025-02-04 | CVE-2024-13607 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.8 via the 'exportusereraserequest' due to missing validation on a user controlled key. | 4.3 |
2025-02-03 | CVE-2024-11132 | The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 |