CVE Feed

    Dashboard / CVE

    4.5
    Medium

    CVE-2025-54649

    Last Modified: 13 Aug 2025

    Vulnerability of using incompatible types to access resources in the location service. Impact: Successful exploitation of this vulnerability may cause some location information attributes to be incorrect.

    Published: 6 Aug 2025
    5.4
    Medium

    CVE-2025-54648

    Last Modified: 13 Aug 2025

    Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    5.4
    Medium

    CVE-2025-54647

    Last Modified: 13 Aug 2025

    Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    5.1
    Medium

    CVE-2025-54646

    Last Modified: 13 Aug 2025

    Vulnerability of inadequate packet length check in the BLE module. Impact: Successful exploitation of this vulnerability may affect performance.

    Published: 6 Aug 2025
    5
    Medium

    CVE-2025-54645

    Last Modified: 13 Aug 2025

    Out-of-bounds array access issue due to insufficient data verification in the location service module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    6.6
    Medium

    CVE-2025-54644

    Last Modified: 20 Sept 2025

    Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Aug 2025
    6.6
    Medium

    CVE-2025-54643

    Last Modified: 20 Sept 2025

    Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Aug 2025
    6.7
    Medium

    CVE-2025-54642

    Last Modified: 11 Aug 2025

    Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    6.7
    Medium

    CVE-2025-54641

    Last Modified: 11 Aug 2025

    Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    5.5
    Medium

    CVE-2025-54640

    Last Modified: 20 Sept 2025

    ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.

    Published: 6 Aug 2025
    5.5
    Medium

    CVE-2025-54639

    Last Modified: 8 Dec 2025

    ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.

    Published: 6 Aug 2025
    5.5
    Medium

    CVE-2025-54638

    Last Modified: 11 Aug 2025

    Issue of inconsistent read/write serialization in the ad module. Impact: Successful exploitation of this vulnerability may affect the availability of the ad service.

    Published: 6 Aug 2025
    4.4
    Medium

    CVE-2025-54637

    Last Modified: 11 Aug 2025

    Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Aug 2025
    4.4
    Medium

    CVE-2025-54636

    Last Modified: 11 Aug 2025

    Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    5.9
    Medium

    CVE-2025-54635

    Last Modified: 11 Aug 2025

    Vulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    8.1
    High

    CVE-2025-8420

    Last Modified: 21 Apr 2026

    Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called

    Published: 6 Aug 2025
    4.3
    Medium

    CVE-2025-8595

    Last Modified: 21 Apr 2026

    The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo settings.

    Published: 6 Aug 2025
    8
    High

    CVE-2025-54634

    Last Modified: 11 Aug 2025

    Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    6.7
    Medium

    CVE-2025-54633

    Last Modified: 11 Aug 2025

    Out-of-bounds read vulnerability in the register configuration of the DMA module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Aug 2025
    6.8
    Medium

    CVE-2025-54632

    Last Modified: 20 Sept 2025

    Vulnerability of insufficient data length verification in the HVB module. Impact: Successful exploitation of this vulnerability may affect service integrity.

    Published: 6 Aug 2025
    6.7
    Medium

    CVE-2025-54631

    Last Modified: 20 Aug 2025

    Vulnerability of insufficient data length verification in the partition module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    6.8
    Medium

    CVE-2025-54630

    Last Modified: 20 Sept 2025

    :Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    6.7
    Medium

    CVE-2025-54629

    Last Modified: 8 Dec 2025

    Race condition issue occurring in the physical page import process of the memory management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

    Published: 6 Aug 2025
    5.3
    Medium

    CVE-2025-54628

    Last Modified: 20 Sept 2025

    Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    8.8
    High

    CVE-2025-54627

    Last Modified: 20 Aug 2025

    Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Aug 2025
    6.7
    Medium

    CVE-2025-54625

    Last Modified: 20 Aug 2025

    Race condition vulnerability in the kernel file system module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    4.4
    Medium

    CVE-2025-54626

    Last Modified: 8 Dec 2025

    Pointer dangling vulnerability in the cjwindow module. Impact: Successful exploitation of this vulnerability may affect function stability.

    Published: 6 Aug 2025
    5.7
    Medium

    CVE-2025-54624

    Last Modified: 20 Aug 2025

    Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    6.4
    Medium

    CVE-2025-7502

    Last Modified: 20 Apr 2026

    The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Aug 2025
    6.5
    Medium

    CVE-2025-6986

    Last Modified: 20 Apr 2026

    The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 6.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 6 Aug 2025
    6.4
    Medium

    CVE-2025-6256

    Last Modified: 20 Apr 2026

    The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ parameter in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Aug 2025
    6.4
    Medium

    CVE-2025-6690

    Last Modified: 20 Apr 2026

    The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-7036

    Last Modified: 21 Apr 2026

    The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE-2025-49059 may be a duplicate of this issue.

    Published: 6 Aug 2025
    6.4
    Medium

    CVE-2025-6259

    Last Modified: 21 Apr 2026

    The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Aug 2025
    6.3
    Medium

    CVE-2025-54623

    Last Modified: 20 Aug 2025

    Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    8.3
    High

    CVE-2025-54622

    Last Modified: 20 Aug 2025

    Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Aug 2025
    5.3
    Medium

    CVE-2025-54621

    Last Modified: 8 Dec 2025

    Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures.

    Published: 6 Aug 2025
    5.5
    Medium

    CVE-2025-54620

    Last Modified: 20 Aug 2025

    Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    5.3
    Medium

    CVE-2025-54619

    Last Modified: 20 Aug 2025

    Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability.

    Published: 6 Aug 2025
    5.7
    Medium

    CVE-2025-54618

    Last Modified: 20 Aug 2025

    Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Aug 2025
    6.8
    Medium

    CVE-2025-54617

    Last Modified: 20 Sept 2025

    Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability can cause RCE.

    Published: 6 Aug 2025
    4
    Medium

    CVE-2025-54616

    Last Modified: 12 Aug 2025

    Out-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    6.2
    Medium

    CVE-2025-54615

    Last Modified: 12 Aug 2025

    Vulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Aug 2025
    6.2
    Medium

    CVE-2025-54614

    Last Modified: 12 Aug 2025

    Input verification vulnerability in the home screen module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Aug 2025
    5.9
    Medium

    CVE-2025-54613

    Last Modified: 8 Dec 2025

    Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.

    Published: 6 Aug 2025
    5.9
    Medium

    CVE-2025-54612

    Last Modified: 8 Dec 2025

    Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.

    Published: 6 Aug 2025
    6.8
    Medium

    CVE-2025-8656

    Last Modified: 7 Aug 2025

    Kenwood DMX958XR Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows physically present attackers to downgrade software on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the libSystemLib library. The issue results from the lack of proper validation of version information before performing an update. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-26355.

    Published: 6 Aug 2025
    6.8
    Medium

    CVE-2025-8655

    Last Modified: 7 Aug 2025

    Kenwood DMX958XR libSystemLib Command injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware update process. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-26314.

    Published: 6 Aug 2025
    8.8
    High

    CVE-2025-8654

    Last Modified: 7 Aug 2025

    Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ReadMVGImage function. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-26313.

    Published: 6 Aug 2025
    8.8
    High

    CVE-2025-8653

    Last Modified: 7 Aug 2025

    Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwood DMX958XR. Authentication is not required to exploit this vulnerability. The specific flaw exists within the JKRadioService. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-26312.

    Published: 6 Aug 2025