7.2
CVE-2024-10237 - SMC BMC Firmware Image Authentication Design Issue
There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection and bypass the signature verification process
6
CVE-2025-20907 -
Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.
5.5
CVE-2025-20906 -
Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB.
6.3
CVE-2025-20905 -
Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.
6.3
CVE-2025-20904 -
Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.
7.5
CVE-2025-22205 - Extension - admiror-design-studio.com - Path traversal in the Admiror Gallery 4.x component for Jooβ¦
Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.
4.3
CVE-2024-12046 - Medical Addon for Elementor <= 1.6.2 - Insecure Direct Object Reference to Authenticated (Contributβ¦
The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.2 via the 'namedical_elementor_template' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers,β¦
4.3
CVE-2024-13514 - B Slider- Gutenberg Slider Block for WP <= 1.1.23 - Authenticated (Contributor+) Private Post Disclβ¦
The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.5 via the 'bsb-slider' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, withβ¦
9.8
CVE-2025-22204 - Extension - regularlabs.com - Remote code execution vulnerability in the Sourcerer extensions < 12.β¦
Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.
5.1
CVE-2025-20902 -
Improper access control in Media Controller prior to version 1.0.24.5282 allows local attacker to launch activities in MediaController's privilege.