| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27057 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while handling beacon frames with invalid IE header length. | ||
| CVE-2025-27056 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption during sub-system restart while processing clean-up to free up resources. | ||
| CVE-2025-27055 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption during the image encoding process. | ||
| CVE-2025-27052 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing data packets in diag received from Unix clients. | ||
| CVE-2025-27051 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing command message in WLAN Host. | ||
| CVE-2025-27050 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing event close when client process terminates abruptly. | ||
| CVE-2025-27047 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing the TESTPATTERNCONFIG escape path. | ||
| CVE-2025-27046 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing multiple simultaneous escape calls. | ||
| CVE-2025-27044 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while executing timestamp video decode command with large input values. | ||
| CVE-2025-27043 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing manipulated payload in video firmware. | ||
| CVE-2025-27042 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing video packets received from video firmware. | ||
| CVE-2025-21466 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing a private escape command in an event trigger. | ||
| CVE-2025-21454 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while processing received beacon frame. | ||
| CVE-2025-21449 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS may occur while processing malformed length field in SSID IEs. | ||
| CVE-2025-21446 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. | ||
| CVE-2025-21445 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while copying the result to the transmission queue which is shared between the virtual machine and the host. | ||
| CVE-2025-21444 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while copying the result to the transmission queue in EMAC. | ||
| CVE-2025-21432 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while retrieving the CBOR data from TA. | ||
| CVE-2025-21427 | Hig | 0.53 | 8.2 | 0.00 | Jul 8, 2025 | Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network. | ||
| CVE-2025-21422 | Hig | 0.46 | 7.1 | 0.00 | Jul 8, 2025 | Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses. | ||
| CVE-2025-7176 | Hig | 0.47 | 7.3 | 0.01 | Jul 8, 2025 | A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file view-medhistory.php. The manipulation of the argument viewid leads to sql injection. The attack can be… | ||
| CVE-2025-40718 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Improper error handling vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to send malformed payloads to generate error messages containing sensitive information. | ||
| CVE-2025-7174 | Hig | 0.47 | 7.3 | 0.00 | Jul 8, 2025 | A vulnerability was found in code-projects Library System 1.0 and classified as critical. This issue affects some unknown processing of the file /teacher-issue-book.php. The manipulation of the argument idn leads to sql injection. The attack may be initiated remotely. The… | ||
| CVE-2025-41224 | Hig | 0.57 | 8.8 | 0.00 | Jul 8, 2025 | A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.0), RUGGEDCOM RMC8388NC V5.X (All versions < V5.10.0), RUGGEDCOM RS416NCv2 V5.X (All versions < V5.10.0), RUGGEDCOM RS416PNCv2 V5.X (All versions < V5.10.0), RUGGEDCOM RS416Pv2 V5.X (All versions… | ||
| CVE-2025-40741 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain a stack based overflow vulnerability while parsing specially crafted CFG files. This could allow an attacker to execute code in the context of the… | ||
| CVE-2025-40740 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in… | ||
| CVE-2025-40739 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in… | ||
| CVE-2025-40738 | Hig | 0.58 | 8.8 | 0.09 | Jul 8, 2025 | A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code… | ||
| CVE-2025-40737 | Hig | 0.58 | 8.8 | 0.09 | Jul 8, 2025 | A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code… | ||
| CVE-2025-40735 | Hig | 0.57 | 8.8 | 0.00 | Jul 8, 2025 | A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database. | ||
| CVE-2025-23365 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-privileged users to trigger installations by overwriting cache files and modifying the downloads path. This would allow an attacker to escalate privilege and… | ||
| CVE-2025-21006 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory. | ||
| CVE-2024-31854 | Hig | 0.53 | 8.1 | 0.00 | Jul 8, 2025 | A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check device's certificate common name against an expected value. This could allow… | ||
| CVE-2024-31853 | Hig | 0.53 | 8.1 | 0.00 | Jul 8, 2025 | A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check the extended key usage attribute of that device's certificate. This could… | ||
| CVE-2023-52236 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All versions), RUGGEDCOM i803 (All versions), RUGGEDCOM M2100 (All versions), RUGGEDCOM M2200 (All versions), RUGGEDCOM M969 (All versions), RUGGEDCOM RMC30 (All… | ||
| CVE-2025-7173 | Hig | 0.47 | 7.3 | 0.01 | Jul 8, 2025 | A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-student.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The… | ||
| CVE-2025-7172 | Hig | 0.47 | 7.3 | 0.01 | Jul 8, 2025 | A vulnerability, which was classified as critical, was found in code-projects Crime Reporting System 1.0. This affects an unknown part of the file /headlogin.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The… | ||
| CVE-2025-6744 | Hig | 0.47 | 7.3 | 0.00 | Jul 8, 2025 | The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode through the… | ||
| CVE-2025-7171 | Hig | 0.47 | 7.3 | 0.00 | Jul 8, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Crime Reporting System 1.0. Affected by this issue is some unknown functionality of the file /policelogin.php. The manipulation of the argument email leads to sql injection. The attack may be… | ||
| CVE-2025-7170 | Hig | 0.47 | 7.3 | 0.00 | Jul 8, 2025 | A vulnerability classified as critical was found in code-projects Crime Reporting System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attack can be launched… | ||
| CVE-2025-7169 | Hig | 0.47 | 7.3 | 0.00 | Jul 8, 2025 | A vulnerability classified as critical has been found in code-projects Crime Reporting System 1.0. Affected is an unknown function of the file /complainer_page.php. The manipulation of the argument location leads to sql injection. It is possible to launch the attack remotely.… | ||
| CVE-2025-7168 | Hig | 0.47 | 7.3 | 0.00 | Jul 8, 2025 | A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /userlogin.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The… | ||
| CVE-2025-38236 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't leave consecutive consumed OOB skbs. Jann Horn reported a use-after-free in unix_stream_read_generic(). The following sequences reproduce the issue: $ python3 from socket import * s1, s2… | ||
| CVE-2025-7346 | Hig | 0.50 | — | 0.00 | Jul 8, 2025 | Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages | ||
| CVE-2025-6746 | Hig | 0.57 | 8.8 | 0.00 | Jul 8, 2025 | The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php… | ||
| CVE-2025-41668 | — | Hig | 0.57 | 8.8 | 0.01 | Jul 8, 2025 | A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and execute access to any file on the device. | |
| CVE-2025-41667 | — | Hig | 0.57 | 8.8 | 0.01 | Jul 8, 2025 | A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to any file on the device. | |
| CVE-2025-41666 | — | Hig | 0.57 | 8.8 | 0.01 | Jul 8, 2025 | A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file on the device after the watchdog has been initialized. | |
| CVE-2025-25271 | Hig | 0.57 | 8.8 | 0.00 | Jul 8, 2025 | An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface. | ||
| CVE-2025-25269 | Hig | 0.55 | 8.4 | 0.00 | Jul 8, 2025 | An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation. |
- risk 0.49cvss 7.5epss 0.00
Transient DOS while handling beacon frames with invalid IE header length.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during sub-system restart while processing clean-up to free up resources.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during the image encoding process.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing data packets in diag received from Unix clients.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing command message in WLAN Host.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing event close when client process terminates abruptly.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing the TESTPATTERNCONFIG escape path.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing multiple simultaneous escape calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while executing timestamp video decode command with large input values.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing manipulated payload in video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing video packets received from video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a private escape command in an event trigger.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing received beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing malformed length field in SSID IEs.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while copying the result to the transmission queue which is shared between the virtual machine and the host.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while copying the result to the transmission queue in EMAC.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while retrieving the CBOR data from TA.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
- risk 0.47cvss 7.3epss 0.01
A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file view-medhistory.php. The manipulation of the argument viewid leads to sql injection. The attack can be…
- risk 0.49cvss 7.5epss 0.00
Improper error handling vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to send malformed payloads to generate error messages containing sensitive information.
- risk 0.47cvss 7.3epss 0.00
A vulnerability was found in code-projects Library System 1.0 and classified as critical. This issue affects some unknown processing of the file /teacher-issue-book.php. The manipulation of the argument idn leads to sql injection. The attack may be initiated remotely. The…
- risk 0.57cvss 8.8epss 0.00
A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.0), RUGGEDCOM RMC8388NC V5.X (All versions < V5.10.0), RUGGEDCOM RS416NCv2 V5.X (All versions < V5.10.0), RUGGEDCOM RS416PNCv2 V5.X (All versions < V5.10.0), RUGGEDCOM RS416Pv2 V5.X (All versions…
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain a stack based overflow vulnerability while parsing specially crafted CFG files. This could allow an attacker to execute code in the context of the…
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in…
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in…
- risk 0.58cvss 8.8epss 0.09
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code…
- risk 0.58cvss 8.8epss 0.09
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code…
- risk 0.57cvss 8.8epss 0.00
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database.
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-privileged users to trigger installations by overwriting cache files and modifying the downloads path. This would allow an attacker to escalate privilege and…
- risk 0.46cvss 7.0epss 0.00
Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory.
- risk 0.53cvss 8.1epss 0.00
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check device's certificate common name against an expected value. This could allow…
- risk 0.53cvss 8.1epss 0.00
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check the extended key usage attribute of that device's certificate. This could…
- risk 0.46cvss 7.0epss 0.00
A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All versions), RUGGEDCOM i803 (All versions), RUGGEDCOM M2100 (All versions), RUGGEDCOM M2200 (All versions), RUGGEDCOM M969 (All versions), RUGGEDCOM RMC30 (All…
- risk 0.47cvss 7.3epss 0.01
A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-student.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The…
- risk 0.47cvss 7.3epss 0.01
A vulnerability, which was classified as critical, was found in code-projects Crime Reporting System 1.0. This affects an unknown part of the file /headlogin.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The…
- risk 0.47cvss 7.3epss 0.00
The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode through the…
- risk 0.47cvss 7.3epss 0.00
A vulnerability, which was classified as critical, has been found in code-projects Crime Reporting System 1.0. Affected by this issue is some unknown functionality of the file /policelogin.php. The manipulation of the argument email leads to sql injection. The attack may be…
- risk 0.47cvss 7.3epss 0.00
A vulnerability classified as critical was found in code-projects Crime Reporting System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attack can be launched…
- risk 0.47cvss 7.3epss 0.00
A vulnerability classified as critical has been found in code-projects Crime Reporting System 1.0. Affected is an unknown function of the file /complainer_page.php. The manipulation of the argument location leads to sql injection. It is possible to launch the attack remotely.…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /userlogin.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The…
- risk 0.51cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't leave consecutive consumed OOB skbs. Jann Horn reported a use-after-free in unix_stream_read_generic(). The following sequences reproduce the issue: $ python3 from socket import * s1, s2…
- risk 0.50cvss —epss 0.00
Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages
- risk 0.57cvss 8.8epss 0.00
The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php…
- risk 0.57cvss 8.8epss 0.01
A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and execute access to any file on the device.
- risk 0.57cvss 8.8epss 0.01
A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to any file on the device.
- risk 0.57cvss 8.8epss 0.01
A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file on the device after the watchdog has been initialized.
- risk 0.57cvss 8.8epss 0.00
An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.
- risk 0.55cvss 8.4epss 0.00
An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.