CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2025-7202

    Last Modified: 15 Apr 2026

    A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-47324

    Last Modified: 18 Aug 2025

    Information disclosure while accessing and modifying the PIB file of a remote device via powerline.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-27076

    Last Modified: 19 Aug 2025

    Memory corruption while processing simultaneous requests via escape path.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-27075

    Last Modified: 18 Aug 2025

    Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-27073

    Last Modified: 20 Aug 2025

    Transient DOS while creating NDP instance.

    Published: 6 Aug 2025
    5.5
    Medium

    CVE-2025-27072

    Last Modified: 18 Aug 2025

    Information disclosure while processing a packet at EAVB BE side with invalid header length.

    Published: 6 Aug 2025
    7.3
    High

    CVE-2025-27071

    Last Modified: 19 Aug 2025

    Memory corruption while processing specific files in Powerline Communication Firmware.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-27069

    Last Modified: 18 Aug 2025

    Memory corruption while processing DDI command calls.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-27068

    Last Modified: 18 Aug 2025

    Memory corruption while processing an IOCTL command with an arbitrary address.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-27067

    Last Modified: 18 Aug 2025

    Memory corruption while processing DDI call with invalid buffer.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-27066

    Last Modified: 28 Nov 2025

    Transient DOS while processing an ANQP message.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-27065

    Last Modified: 20 Aug 2025

    Transient DOS while processing a frame with malformed shared-key descriptor.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-27062

    Last Modified: 28 Nov 2025

    Memory corruption while handling client exceptions, allowing unauthorized channel access.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-21477

    Last Modified: 20 Aug 2025

    Transient DOS while processing CCCH data when NW sends data with invalid length.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-21474

    Last Modified: 19 Aug 2025

    Memory corruption while processing commands from A2dp sink command queue.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-21473

    Last Modified: 26 Feb 2026

    Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.

    Published: 6 Aug 2025
    5.5
    Medium

    CVE-2025-21472

    Last Modified: 18 Aug 2025

    Information disclosure while capturing logs as eSE debug messages are logged.

    Published: 6 Aug 2025
    6.5
    Medium

    CVE-2025-21465

    Last Modified: 28 Nov 2025

    Information disclosure while processing the hash segment in an MBN file.

    Published: 6 Aug 2025
    6.5
    Medium

    CVE-2025-21464

    Last Modified: 28 Nov 2025

    Information disclosure while reading data from an image using specified offset and size parameters.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-21461

    Last Modified: 26 Feb 2026

    Memory corruption when programming registers through virtual CDM.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-21458

    Last Modified: 26 Feb 2026

    Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously.

    Published: 6 Aug 2025
    6.1
    Medium

    CVE-2025-21457

    Last Modified: 19 Aug 2025

    Information disclosure while opening a fastrpc session when domain is not sanitized.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-21456

    Last Modified: 26 Feb 2026

    Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-21455

    Last Modified: 26 Feb 2026

    Memory corruption while submitting blob data to kernel space though IOCTL.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-21452

    Last Modified: 20 Aug 2025

    Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.

    Published: 6 Aug 2025
    6
    Medium

    CVE-2025-7954

    Last Modified: 3 Nov 2025

    A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.

    Published: 6 Aug 2025
    6.4
    Medium

    CVE-2025-7727

    Last Modified: 21 Apr 2026

    The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun Fact blocks in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Aug 2025
    5.9
    Medium

    CVE-2025-7376

    Last Modified: 20 Apr 2026

    Windows Shortcut Following (.LNK) vulnerability in multiple processes of Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric AnalytiX versions 10.97.3 and prior, Mitsubishi Electric IoTWorX version 10.95, Mitsubishi Electric GENESIS version 11.00, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions AnalytiX versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions IoTWorX version 10.95, and Mitsubishi Electric Iconics Digital Solutions GENESIS version 11.00 allows a local authenticated attacker to make an unauthorized write to arbitrary files, by creating a symbolic link from a file used as a write destination by the processes of the affected products to a target file. This could allow the attacker to destroy the file on a PC with the affected products installed, resulting in a denial-of-service (DoS) condition on the PC if the destroyed file is necessary for the operation of the PC.

    Published: 6 Aug 2025
    3.3
    Low

    CVE-2025-21024

    Last Modified: 2 Oct 2025

    Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access sensitive information.

    Published: 6 Aug 2025
    3.3
    Low

    CVE-2025-21023

    Last Modified: 15 Apr 2026

    Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information.

    Published: 6 Aug 2025
    3.3
    Low

    CVE-2025-21022

    Last Modified: 8 Dec 2025

    Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.

    Published: 6 Aug 2025
    5.7
    Medium

    CVE-2025-21021

    Last Modified: 26 Feb 2026

    Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

    Published: 6 Aug 2025
    5.7
    Medium

    CVE-2025-21020

    Last Modified: 26 Feb 2026

    Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

    Published: 6 Aug 2025
    5.5
    Medium

    CVE-2025-21019

    Last Modified: 15 Aug 2025

    Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.

    Published: 6 Aug 2025
    4.4
    Medium

    CVE-2025-21018

    Last Modified: 15 Aug 2025

    Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory.

    Published: 6 Aug 2025
    6.3
    Medium

    CVE-2025-21017

    Last Modified: 26 Feb 2026

    Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

    Published: 6 Aug 2025
    4.3
    Medium

    CVE-2025-21016

    Last Modified: 15 Apr 2026

    Improper access control in PkgPredictorService prior to SMR Aug-2025 Release 1 in Chinese Android 13, 14, 15 and 16 allows local attackers to use the privileged APIs.

    Published: 6 Aug 2025
    4
    Medium

    CVE-2025-21015

    Last Modified: 24 Feb 2026

    Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.

    Published: 6 Aug 2025
    4.3
    Medium

    CVE-2025-21014

    Last Modified: 24 Feb 2026

    Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.

    Published: 6 Aug 2025
    6.2
    Medium

    CVE-2025-21013

    Last Modified: 15 Apr 2026

    Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise and sleep time.

    Published: 6 Aug 2025
    5.5
    Medium

    CVE-2025-21012

    Last Modified: 15 Apr 2026

    Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to modify fall detection configuration.

    Published: 6 Aug 2025
    5.5
    Medium

    CVE-2025-21011

    Last Modified: 15 Apr 2026

    Improper access control in SemSensorService for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to motion and body sensors.

    Published: 6 Aug 2025
    6
    Medium

    CVE-2025-21010

    Last Modified: 12 Aug 2025

    Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.

    Published: 6 Aug 2025
    4
    Medium

    CVE-2025-20990

    Last Modified: 12 Aug 2025

    Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.

    Published: 6 Aug 2025
    9.8
    Critical

    CVE-2025-6994

    Last Modified: 20 Apr 2026

    The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'listing_user_role' field. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.

    Published: 6 Aug 2025
    6.4
    Medium

    CVE-2025-7399

    Last Modified: 22 Apr 2026

    The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via an Elementor display setting in all versions up to, and including, 28.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Aug 2025
    6.4
    Medium

    CVE-2025-7498

    Last Modified: 21 Apr 2026

    The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget in all versions up to, and including, 2.7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Aug 2025
    5.4
    Medium

    CVE-2025-8100

    Last Modified: 21 Apr 2026

    The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content' parameter in versions up to, and including, 8.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Aug 2025
    4.8
    Medium

    CVE-2025-54651

    Last Modified: 13 Aug 2025

    Race condition vulnerability in the kernel hufs module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Aug 2025
    4.2
    Medium

    CVE-2025-54650

    Last Modified: 20 Sept 2025

    Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.

    Published: 6 Aug 2025