CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2025-1221

    Last Modified: 15 Apr 2026

    A Zigbee Radio Co-Processor (RCP), which is using SiLabs EmberZNet Zigbee stack, was unable to send messages to the host system (CPCd) due to heavy Zigbee traffic, resulting in a Denial of Service (DoS) attack, Only hard reset will bring the device to normal operation

    Published: 30 Jul 2025
    8.7
    High

    CVE-2025-8323

    Last Modified: 15 Apr 2026

    The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

    Published: 30 Jul 2025
    8.7
    High

    CVE-2025-8322

    Last Modified: 15 Apr 2026

    The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to access administrator functions, including creating, modifying, and deleting accounts. They can even escalate any account to system administrator privilege.

    Published: 30 Jul 2025
    8.8
    High

    CVE-2025-8292

    Last Modified: 26 Feb 2026

    Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2025
    8.8
    High

    CVE-2025-8320

    Last Modified: 12 Aug 2025

    Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of the HTTP Content-Length header. The issue results from the lack of proper validation of user-supplied data, which can result in memory access past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-26300.

    Published: 30 Jul 2025
    6.8
    Medium

    CVE-2025-8321

    Last Modified: 12 Aug 2025

    Tesla Wall Connector Firmware Downgrade Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware upgrade feature. The issue results from the lack of an anti-downgrade mechanism. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the device. Was ZDI-CAN-26299.

    Published: 30 Jul 2025
    6
    Medium

    CVE-2025-4426

    Last Modified: 15 Apr 2026

    The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability.  https://support.lenovo.com/us/en/product_security/home

    Published: 30 Jul 2025
    8.2
    High

    CVE-2025-4425

    Last Modified: 15 Apr 2026

    The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability.  https://support.lenovo.com/us/en/product_security/home

    Published: 30 Jul 2025
    6
    Medium

    CVE-2025-4424

    Last Modified: 15 Apr 2026

    The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability.  https://support.lenovo.com/us/en/product_security/home

    Published: 30 Jul 2025
    8.2
    High

    CVE-2025-4423

    Last Modified: 15 Apr 2026

    The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability.  https://support.lenovo.com/us/en/product_security/home

    Published: 30 Jul 2025
    8.2
    High

    CVE-2025-4422

    Last Modified: 15 Apr 2026

    The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability.  https://support.lenovo.com/us/en/product_security/home

    Published: 30 Jul 2025
    8.2
    High

    CVE-2025-4421

    Last Modified: 15 Apr 2026

    The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability.  https://support.lenovo.com/us/en/product_security/home

    Published: 30 Jul 2025
    5.1
    Medium

    CVE-2025-8217

    Last Modified: 15 Apr 2026

    The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API call to the Q Developer CLI. To mitigate this issue, users should upgrade to version v1.85.0. All installations of v1.84.0 should be removed from use.

    Published: 30 Jul 2025
    7
    High

    CVE-2025-25011

    Last Modified: 15 Apr 2026

    An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.

    Published: 30 Jul 2025
    7
    High

    CVE-2025-0712

    Last Modified: 15 Apr 2026

    An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.

    Published: 30 Jul 2025
    8.6
    High

    CVE-2025-53022

    Last Modified: 15 Apr 2026

    TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmware upgrade. While processing a new image, the Firmware Upgrade (FWU) module does not validate the length field of the Type-Length-Value (TLV) structure for dependent components against the maximum allowed size. If the length specified in the TLV exceeds the size of the buffer allocated on the stack, the FWU module will overwrite the buffer (and potentially other stack data) with the TLV's value content. An attacker could exploit this by crafting a malicious TLV entry in the unprotected section of the MCUBoot upgrade image. By setting the length field to exceed the expected structure size, the attacker can manipulate the stack memory of the system during the upgrade process.

    Published: 30 Jul 2025
    7.8
    High

    CVE-2025-38498

    Last Modified: 30 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: do_change_type(): refuse to operate on unmounted/not ours mounts Ensure that propagation settings can only be changed for mounts located in the caller's mount namespace. This change aligns permission checking with the rest of mount(2).

    Published: 30 Jul 2025
    8.2
    High

    CVE-2025-52187

    Last Modified: 3 Nov 2025

    GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_form1.php.

    Published: 30 Jul 2025
    9.8
    Critical

    CVE-2025-50578

    Last Modified: 25 Aug 2025

    LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.

    Published: 30 Jul 2025
    7.8
    High

    CVE-2025-50777

    Last Modified: 6 Aug 2025

    The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in plaintext, enabling further compromise of the network and connected systems.

    Published: 30 Jul 2025
    6.1
    Medium

    CVE-2025-51954

    Last Modified: 6 Aug 2025

    playground.electronhub.ai v1.1.9 was discovered to contain a cross-site scripting (XSS) vulnerability.

    Published: 30 Jul 2025
    6.1
    Medium

    CVE-2024-45515

    Last Modified: 7 Aug 2025

    An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. Attackers can exploit this issue by crafting a file with manipulated metadata, allowing them to bypass content type checks and execute arbitrary JavaScript within the victim's session.

    Published: 30 Jul 2025
    7.3
    High

    CVE-2024-45955

    Last Modified: 6 Aug 2025

    Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.

    Published: 30 Jul 2025
    6.5
    Medium

    CVE-2025-25691

    Last Modified: 6 Aug 2025

    A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

    Published: 30 Jul 2025
    6.5
    Medium

    CVE-2025-25692

    Last Modified: 6 Aug 2025

    A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

    Published: 30 Jul 2025
    6.5
    Medium

    CVE-2025-45619

    Last Modified: 6 Aug 2025

    An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction function

    Published: 30 Jul 2025
    8.1
    High

    CVE-2025-45620

    Last Modified: 6 Aug 2025

    An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request

    Published: 30 Jul 2025
    6.5
    Medium

    CVE-2025-50464

    Last Modified: 6 Aug 2025

    A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability arises due to the unsafe use of the strcpy function to copy attacker-controlled data from the CONTENT_TYPE HTTP header into a fixed-size stack buffer (v8, allocated 8 bytes) without bounds checking. Since this operation occurs before authentication logic is executed, the vulnerability is exploitable pre-authentication.

    Published: 30 Jul 2025
    6.1
    Medium

    CVE-2025-51951

    Last Modified: 6 Aug 2025

    andisearch v0.5.249 was discovered to contain a cross-site scripting (XSS) vulnerability.

    Published: 30 Jul 2025
    6.2
    Medium

    CVE-2025-43191

    Last Modified: 2 Apr 2026

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause a denial-of-service.

    Published: 29 Jul 2025
    9.8
    Critical

    CVE-2025-43237

    Last Modified: 28 Apr 2026

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause unexpected system termination.

    Published: 29 Jul 2025
    4
    Medium

    CVE-2025-43197

    Last Modified: 28 Apr 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.

    Published: 29 Jul 2025
    4
    Medium

    CVE-2025-43206

    Last Modified: 28 Apr 2026

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.

    Published: 29 Jul 2025
    7.8
    High

    CVE-2025-43196

    Last Modified: 28 Apr 2026

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to gain root privileges.

    Published: 29 Jul 2025
    4
    Medium

    CVE-2025-43265

    Last Modified: 2 Apr 2026

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose internal states of the app.

    Published: 29 Jul 2025
    9.8
    Critical

    CVE-2025-43233

    Last Modified: 28 Apr 2026

    This issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A malicious app acting as a HTTPS proxy could get access to sensitive user data.

    Published: 29 Jul 2025
    5.5
    Medium

    CVE-2025-43218

    Last Modified: 28 Apr 2026

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted USD file may disclose memory contents.

    Published: 29 Jul 2025
    6.5
    Medium

    CVE-2025-24188

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published: 29 Jul 2025
    6.5
    Medium

    CVE-2025-43216

    Last Modified: 2 Apr 2026

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published: 29 Jul 2025
    9.8
    Critical

    CVE-2025-43186

    Last Modified: 28 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Parsing a file may lead to an unexpected app termination.

    Published: 29 Jul 2025
    4
    Medium

    CVE-2025-43217

    Last Modified: 28 Apr 2026

    The issue was addressed by adding additional logic. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Privacy Indicators for microphone or camera access may not be correctly displayed.

    Published: 29 Jul 2025
    5.3
    Medium

    CVE-2025-43276

    Last Modified: 28 Apr 2026

    A logic error was addressed with improved error handling. This issue is fixed in macOS Sequoia 15.6. iCloud Private Relay may not activate when more than one user is logged in at the same time.

    Published: 29 Jul 2025
    5.3
    Medium

    CVE-2025-31276

    Last Modified: 28 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Remote content may be loaded even when the 'Load Remote Images' setting is turned off.

    Published: 29 Jul 2025
    5.1
    Medium

    CVE-2025-43260

    Last Modified: 28 Apr 2026

    This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to hijack entitlements granted to other privileged apps.

    Published: 29 Jul 2025
    5.5
    Medium

    CVE-2025-43247

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A malicious app with root privileges may be able to modify the contents of system files.

    Published: 29 Jul 2025
    4
    Medium

    CVE-2025-43230

    Last Modified: 28 Apr 2026

    The issue was addressed with additional permissions checks. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able to access user-sensitive data.

    Published: 29 Jul 2025
    4
    Medium

    CVE-2025-43226

    Last Modified: 28 Apr 2026

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted image may result in disclosure of process memory.

    Published: 29 Jul 2025
    7.5
    High

    CVE-2025-24224

    Last Modified: 28 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.9, macOS Sequoia 15.5, macOS Ventura 13.7.7, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker may be able to cause unexpected system termination.

    Published: 29 Jul 2025
    7.5
    High

    CVE-2025-43227

    Last Modified: 2 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose sensitive user information.

    Published: 29 Jul 2025
    8.8
    High

    CVE-2025-43270

    Last Modified: 28 Apr 2026

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may gain unauthorized access to Local Network.

    Published: 29 Jul 2025