CVE-2025-7202
Last Modified: 15 Apr 2026A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights.
CVE-2025-47324
Last Modified: 18 Aug 2025Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
CVE-2025-27076
Last Modified: 19 Aug 2025Memory corruption while processing simultaneous requests via escape path.
CVE-2025-27075
Last Modified: 18 Aug 2025Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host.
CVE-2025-27073
Last Modified: 20 Aug 2025Transient DOS while creating NDP instance.
CVE-2025-27072
Last Modified: 18 Aug 2025Information disclosure while processing a packet at EAVB BE side with invalid header length.
CVE-2025-27071
Last Modified: 19 Aug 2025Memory corruption while processing specific files in Powerline Communication Firmware.
CVE-2025-27069
Last Modified: 18 Aug 2025Memory corruption while processing DDI command calls.
CVE-2025-27068
Last Modified: 18 Aug 2025Memory corruption while processing an IOCTL command with an arbitrary address.
CVE-2025-27067
Last Modified: 18 Aug 2025Memory corruption while processing DDI call with invalid buffer.
CVE-2025-27066
Last Modified: 28 Nov 2025Transient DOS while processing an ANQP message.
CVE-2025-27065
Last Modified: 20 Aug 2025Transient DOS while processing a frame with malformed shared-key descriptor.
CVE-2025-27062
Last Modified: 28 Nov 2025Memory corruption while handling client exceptions, allowing unauthorized channel access.
CVE-2025-21477
Last Modified: 20 Aug 2025Transient DOS while processing CCCH data when NW sends data with invalid length.
CVE-2025-21474
Last Modified: 19 Aug 2025Memory corruption while processing commands from A2dp sink command queue.
CVE-2025-21473
Last Modified: 26 Feb 2026Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.
CVE-2025-21472
Last Modified: 18 Aug 2025Information disclosure while capturing logs as eSE debug messages are logged.
CVE-2025-21465
Last Modified: 28 Nov 2025Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464
Last Modified: 28 Nov 2025Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2025-21461
Last Modified: 26 Feb 2026Memory corruption when programming registers through virtual CDM.
CVE-2025-21458
Last Modified: 26 Feb 2026Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously.
CVE-2025-21457
Last Modified: 19 Aug 2025Information disclosure while opening a fastrpc session when domain is not sanitized.
CVE-2025-21456
Last Modified: 26 Feb 2026Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
CVE-2025-21455
Last Modified: 26 Feb 2026Memory corruption while submitting blob data to kernel space though IOCTL.
CVE-2025-21452
Last Modified: 20 Aug 2025Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
CVE-2025-7954
Last Modified: 3 Nov 2025A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
CVE-2025-7727
Last Modified: 21 Apr 2026The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun Fact blocks in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2025-7376
Last Modified: 20 Apr 2026Windows Shortcut Following (.LNK) vulnerability in multiple processes of Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric AnalytiX versions 10.97.3 and prior, Mitsubishi Electric IoTWorX version 10.95, Mitsubishi Electric GENESIS version 11.00, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions AnalytiX versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions IoTWorX version 10.95, and Mitsubishi Electric Iconics Digital Solutions GENESIS version 11.00 allows a local authenticated attacker to make an unauthorized write to arbitrary files, by creating a symbolic link from a file used as a write destination by the processes of the affected products to a target file. This could allow the attacker to destroy the file on a PC with the affected products installed, resulting in a denial-of-service (DoS) condition on the PC if the destroyed file is necessary for the operation of the PC.
CVE-2025-21024
Last Modified: 2 Oct 2025Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access sensitive information.
CVE-2025-21023
Last Modified: 15 Apr 2026Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information.
CVE-2025-21022
Last Modified: 8 Dec 2025Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.
CVE-2025-21021
Last Modified: 26 Feb 2026Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
CVE-2025-21020
Last Modified: 26 Feb 2026Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
CVE-2025-21019
Last Modified: 15 Aug 2025Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.
CVE-2025-21018
Last Modified: 15 Aug 2025Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory.
CVE-2025-21017
Last Modified: 26 Feb 2026Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
CVE-2025-21016
Last Modified: 15 Apr 2026Improper access control in PkgPredictorService prior to SMR Aug-2025 Release 1 in Chinese Android 13, 14, 15 and 16 allows local attackers to use the privileged APIs.
CVE-2025-21015
Last Modified: 24 Feb 2026Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.
CVE-2025-21014
Last Modified: 24 Feb 2026Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.
CVE-2025-21013
Last Modified: 15 Apr 2026Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise and sleep time.
CVE-2025-21012
Last Modified: 15 Apr 2026Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to modify fall detection configuration.
CVE-2025-21011
Last Modified: 15 Apr 2026Improper access control in SemSensorService for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to motion and body sensors.
CVE-2025-21010
Last Modified: 12 Aug 2025Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.
CVE-2025-20990
Last Modified: 12 Aug 2025Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.
CVE-2025-6994
Last Modified: 20 Apr 2026The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'listing_user_role' field. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.
CVE-2025-7399
Last Modified: 22 Apr 2026The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via an Elementor display setting in all versions up to, and including, 28.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2025-7498
Last Modified: 21 Apr 2026The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget in all versions up to, and including, 2.7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2025-8100
Last Modified: 21 Apr 2026The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content' parameter in versions up to, and including, 8.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2025-54651
Last Modified: 13 Aug 2025Race condition vulnerability in the kernel hufs module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-54650
Last Modified: 20 Sept 2025Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.
