CVE-2018-25097
Last Modified: 21 Nov 2024A vulnerability, which was classified as problematic, was found in Acumos Design Studio up to 2.0.7. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.0.8 is able to address this issue. The name of the patch is 0df8a5e8722188744973168648e4c74c69ce67fd. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-249420.
CVE-2024-0191
Last Modified: 3 Jun 2025A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/uploads/. The manipulation leads to file and directory information exposure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249504.
CVE-2024-0190
Last Modified: 17 Jun 2025A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file add_quiz.php of the component Quiz Handler. The manipulation of the argument Quiz Title/Quiz Description with the input </title><scRipt>alert(x)</scRipt> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249503.
CVE-2017-20188
Last Modified: 3 Jun 2025A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerability is the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js. The manipulation of the argument message leads to cross site scripting. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 8.8.2 is able to address this issue. The identifier of the patch is 8d039d6efe80780adc40c6f670c06d21de272105. It is recommended to upgrade the affected component. The identifier VDB-249421 was assigned to this vulnerability.
CVE-2024-0189
Last Modified: 9 May 2025A vulnerability has been found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This vulnerability affects unknown code of the file teacher_message.php of the component Create Message Handler. The manipulation of the argument Content with the input </title><scRipt>alert(x)</scRipt> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249502 is the identifier assigned to this vulnerability.
CVE-2015-10128
Last Modified: 17 Apr 2025A vulnerability was found in rt-prettyphoto Plugin up to 1.2 on WordPress and classified as problematic. Affected by this issue is the function royal_prettyphoto_plugin_links of the file rt-prettyphoto.php. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.3 is able to address this issue. The patch is identified as 0d3d38cfa487481b66869e4212df1cefc281ecb7. It is recommended to upgrade the affected component. VDB-249422 is the identifier assigned to this vulnerability.
CVE-2024-0198
Last Modified: 11 Feb 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-6436
Last Modified: 20 May 2026Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics Website Template allows SQL Injection. This issue affects Website Template: through 20231215.
CVE-2024-0188
Last Modified: 17 Jun 2025A vulnerability, which was classified as problematic, was found in RRJ Nueva Ecija Engineer Online Portal 1.0. This affects an unknown part of the file change_password_teacher.php. The manipulation leads to weak password requirements. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-249501 was assigned to this vulnerability.
CVE-2023-47858
Last Modified: 17 Jun 2025Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.
CVE-2023-50333
Last Modified: 17 Jun 2025Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.
CVE-2023-48732
Last Modified: 3 Jun 2025Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.
CVE-2023-49142
Last Modified: 17 Jun 2025in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer.
CVE-2023-49135
Last Modified: 21 Nov 2024in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.
CVE-2023-48360
Last Modified: 17 Jun 2025in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.
CVE-2023-47857
Last Modified: 3 Jun 2025in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer.
CVE-2023-47216
Last Modified: 17 Apr 2025in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through occupy all resources
CVE-2023-43514
Last Modified: 11 Aug 2025Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.
CVE-2023-43512
Last Modified: 21 Nov 2024Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual size of the services buffer.
CVE-2023-43511
Last Modified: 11 Aug 2025Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
CVE-2023-33120
Last Modified: 11 Aug 2025Memory corruption in Audio when memory map command is executed consecutively in ADSP.
CVE-2023-33118
Last Modified: 11 Aug 2025Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL.
CVE-2023-33117
Last Modified: 11 Aug 2025Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command.
CVE-2023-33116
Last Modified: 17 Jun 2025Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.
CVE-2023-33114
Last Modified: 11 Aug 2025Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time.
CVE-2023-33113
Last Modified: 11 Aug 2025Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.
CVE-2023-33112
Last Modified: 11 Aug 2025Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element.
CVE-2023-33110
Last Modified: 21 May 2025The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
CVE-2023-33109
Last Modified: 11 Aug 2025Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
CVE-2023-33108
Last Modified: 11 Aug 2025Memory corruption in Graphics Driver when destroying a context with KGSL_GPU_AUX_COMMAND_TIMELINE objects queued.
CVE-2023-33094
Last Modified: 11 Aug 2025Memory corruption while running VK synchronization with KASAN enabled.
CVE-2023-33085
Last Modified: 11 Aug 2025Memory corruption in wearables while processing data from AON.
CVE-2023-33062
Last Modified: 11 Aug 2025Transient DOS in WLAN Firmware while parsing a BTM request.
CVE-2023-33040
Last Modified: 3 Jun 2025Transient DOS in Data Modem during DTLS handshake.
CVE-2023-33038
Last Modified: 21 Nov 2024Memory corruption while receiving a message in Bus Socket Transport Server.
CVE-2023-33037
Last Modified: 17 Jun 2025Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.
CVE-2023-33036
Last Modified: 21 Nov 2024Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.
CVE-2023-33033
Last Modified: 21 May 2025Memory corruption in Audio during playback with speaker protection.
CVE-2023-33032
Last Modified: 16 Jun 2025Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.
CVE-2023-33030
Last Modified: 3 Jun 2025Memory corruption in HLOS while running playready use-case.
CVE-2023-33025
Last Modified: 17 Apr 2025Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.
CVE-2023-33014
Last Modified: 3 Jun 2025Information disclosure in Core services while processing a Diag command.
CVE-2023-28583
Last Modified: 17 Jun 2025Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.
CVE-2023-52319
Last Modified: 17 Mar 2025This CVE Record has been withdrawn by its CNA.
CVE-2023-52320
Last Modified: 17 Mar 2025This CVE Record has been withdrawn by its CNA.
CVE-2023-52321
Last Modified: 17 Mar 2025This CVE Record has been withdrawn by its CNA.
CVE-2023-52315
Last Modified: 17 Mar 2025This CVE Record has been withdrawn by its CNA.
CVE-2023-52316
Last Modified: 17 Mar 2025This CVE Record has been withdrawn by its CNA.
CVE-2023-52317
Last Modified: 17 Mar 2025This CVE Record has been withdrawn by its CNA.
CVE-2023-52318
Last Modified: 17 Mar 2025This CVE Record has been withdrawn by its CNA.
