CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2025-53611

    Last Modified: 8 Jul 2025

    Not used

    Published: 7 Jul 2025
    Unknown

    CVE-2025-53612

    Last Modified: 8 Jul 2025

    Not used

    Published: 7 Jul 2025
    Unknown

    CVE-2025-53613

    Last Modified: 8 Jul 2025

    Not used

    Published: 7 Jul 2025
    7.4
    High

    CVE-2025-7118

    Last Modified: 8 Jan 2026

    A vulnerability, which was classified as critical, has been found in UTT HiPER 840G up to 3.1.1-190328. This issue affects some unknown processing of the file /goform/formPictureUrl. The manipulation of the argument importpictureurl leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Jul 2025
    7.4
    High

    CVE-2025-7117

    Last Modified: 8 Jan 2026

    A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknown code of the file /goform/websWhiteList. The manipulation of the argument addHostFilter leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Jul 2025
    7.4
    High

    CVE-2025-7116

    Last Modified: 14 Jan 2026

    A vulnerability classified as critical has been found in UTT 进取 750W up to 3.2.2-191225. This affects an unknown part of the file /goform/Fast_wireless_conf. The manipulation of the argument ssid leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Jul 2025
    10
    Critical

    CVE-2025-41672

    Last Modified: 15 Apr 2026

    A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool and all connected devices.

    Published: 7 Jul 2025
    6.9
    Medium

    CVE-2025-7115

    Last Modified: 15 Apr 2026

    A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as critical. Affected by this issue is the function PUT of the file apps/rowboat/app/api/uploads/[fileId]/route.ts of the component Session Handler. The manipulation of the argument params leads to missing authentication. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. It is expected that this issue will be fixed in the near future.

    Published: 7 Jul 2025
    5.5
    Medium

    CVE-2025-7114

    Last Modified: 14 Nov 2025

    A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulnerability is the function POST of the file apps/sim/app/api/files/upload/route.ts of the component Session Handler. The manipulation of the argument Request leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Jul 2025
    2
    Low

    CVE-2025-7113

    Last Modified: 13 Aug 2025

    A vulnerability was found in Portabilis i-Educar 2.9.0. It has been classified as problematic. Affected is an unknown function of the file /module/ComponenteCurricular/edit?id=ID of the component Curricular Components Module. The manipulation of the argument Nome leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Jul 2025
    6.4
    Medium

    CVE-2025-24508

    Last Modified: 15 Apr 2026

    Extraction of Account Connectivity Credentials (ACCs) from the IT Management Agent secure storage

    Published: 7 Jul 2025
    6.9
    Medium

    CVE-2025-53473

    Last Modified: 15 Apr 2026

    Server-side request forgery (SSRF) vulnerability exists n multiple versions of Nimesa Backup and Recovery, If this vulnerability is exploited, unintended requests may be sent to internal servers.

    Published: 7 Jul 2025
    9.3
    Critical

    CVE-2025-48501

    Last Modified: 15 Apr 2026

    An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be executed on the server where the product is running.

    Published: 7 Jul 2025
    2
    Low

    CVE-2025-7112

    Last Modified: 13 Aug 2025

    A vulnerability was found in Portabilis i-Educar 2.9.0 and classified as problematic. This issue affects some unknown processing of the file /intranet/educar_funcao_det.php?cod_funcao=COD&ref_cod_instituicao=COD of the component Function Management Module. The manipulation of the argument Função leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Jul 2025
    2
    Low

    CVE-2025-7111

    Last Modified: 13 Aug 2025

    A vulnerability has been found in Portabilis i-Educar 2.9.0 and classified as problematic. This vulnerability affects unknown code of the file /intranet/educar_curso_det.php?cod_curso=ID of the component Course Module. The manipulation of the argument Curso leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Jul 2025
    2
    Low

    CVE-2025-7110

    Last Modified: 13 Aug 2025

    A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9.0. This affects an unknown part of the file /intranet/educar_escola_lst.php of the component School Module. The manipulation of the argument Escola leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Jul 2025
    2
    Low

    CVE-2025-7109

    Last Modified: 13 Aug 2025

    A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionality of the file /intranet/educar_aluno_beneficio_lst.php of the component Student Benefits Registration. The manipulation of the argument Benefício leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Jul 2025
    5.9
    Medium

    CVE-2025-53186

    Last Modified: 12 Aug 2025

    Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 7 Jul 2025
    6.6
    Medium

    CVE-2025-53185

    Last Modified: 12 Aug 2025

    Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory Impact: Successful exploitation of this vulnerability may affect service integrity.

    Published: 7 Jul 2025
    6.5
    Medium

    CVE-2025-53184

    Last Modified: 9 Jul 2025

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

    Published: 7 Jul 2025
    2.1
    Low

    CVE-2025-7108

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical was found in risesoft-y9 Digital-Infrastructure up to 9.6.7. Affected by this vulnerability is the function deleteFile of the file /Digital-Infrastructure-9.6.7/y9-digitalbase-webapp/y9-module-filemanager/risenet-y9boot-webapp-filemanager/src/main/java/net/risesoft/y9public/controller/Y9FileController.java. The manipulation of the argument fullPath leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Jul 2025
    6.5
    Medium

    CVE-2025-53183

    Last Modified: 9 Jul 2025

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

    Published: 7 Jul 2025
    6.5
    Medium

    CVE-2025-53182

    Last Modified: 9 Jul 2025

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

    Published: 7 Jul 2025
    6.5
    Medium

    CVE-2025-53181

    Last Modified: 9 Jul 2025

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

    Published: 7 Jul 2025
    6.5
    Medium

    CVE-2025-53180

    Last Modified: 9 Jul 2025

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

    Published: 7 Jul 2025
    6.5
    Medium

    CVE-2025-53179

    Last Modified: 9 Jul 2025

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

    Published: 7 Jul 2025
    4.8
    Medium

    CVE-2025-53178

    Last Modified: 12 Aug 2025

    Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.

    Published: 7 Jul 2025
    8.6
    High

    CVE-2025-7145

    Last Modified: 15 Apr 2026

    ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers with product platform intermediate privileges to inject arbitrary OS commands and execute them on the server, thereby gaining administrative access to the remote host.

    Published: 7 Jul 2025
    3.9
    Low

    CVE-2025-53177

    Last Modified: 12 Aug 2025

    Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule syncing function of watches.

    Published: 7 Jul 2025
    3.3
    Low

    CVE-2025-53176

    Last Modified: 14 Jul 2025

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

    Published: 7 Jul 2025
    4
    Medium

    CVE-2025-53175

    Last Modified: 14 Jul 2025

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

    Published: 7 Jul 2025
    4
    Medium

    CVE-2025-53174

    Last Modified: 14 Jul 2025

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

    Published: 7 Jul 2025
    5.3
    Medium

    CVE-2025-53173

    Last Modified: 14 Jul 2025

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

    Published: 7 Jul 2025
    4
    Medium

    CVE-2025-53172

    Last Modified: 14 Jul 2025

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

    Published: 7 Jul 2025
    4
    Medium

    CVE-2025-53171

    Last Modified: 14 Jul 2025

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

    Published: 7 Jul 2025
    5.5
    Medium

    CVE-2025-7107

    Last Modified: 1 Oct 2025

    A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLocalFile of the file apps/sim/app/api/files/parse/route.ts. The manipulation of the argument filePath leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as b2450530d1ddd0397a11001a72aa0fde401db16a. It is recommended to apply a patch to fix this issue.

    Published: 7 Jul 2025
    4
    Medium

    CVE-2024-58117

    Last Modified: 15 Jul 2025

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

    Published: 7 Jul 2025
    4
    Medium

    CVE-2025-53170

    Last Modified: 15 Jul 2025

    Null pointer dereference vulnerability in the application exit cause module Impact: Successful exploitation of this vulnerability may affect function stability.

    Published: 7 Jul 2025
    7.6
    High

    CVE-2025-53169

    Last Modified: 12 Aug 2025

    Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this vulnerability may allow the peer device to use the camera without user awareness.

    Published: 7 Jul 2025
    5.7
    Medium

    CVE-2025-53168

    Last Modified: 12 Aug 2025

    Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this vulnerability may allow the peer device to use the camera without user awareness.

    Published: 7 Jul 2025
    6.9
    Medium

    CVE-2025-53167

    Last Modified: 15 Jul 2025

    Authentication vulnerability in the distributed collaboration framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 7 Jul 2025
    2.1
    Low

    CVE-2025-7103

    Last Modified: 15 Sept 2025

    A vulnerability was found in BoyunCMS up to 1.4.20. It has been rated as critical. This issue affects some unknown processing of the file /application/pay/controller/Index.php of the component curl. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jul 2025
    2.1
    Low

    CVE-2025-7102

    Last Modified: 15 Sept 2025

    A vulnerability was found in BoyunCMS up to 1.4.20. It has been declared as critical. This vulnerability affects unknown code of the file application/update/controller/Server.php. The manipulation of the argument phone leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jul 2025
    2.1
    Low

    CVE-2025-7101

    Last Modified: 15 Sept 2025

    A vulnerability was found in BoyunCMS up to 1.4.20. It has been classified as critical. This affects an unknown part of the file /install/install_ok.php of the component Configuration File Handler. The manipulation of the argument db_pass leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jul 2025
    2.1
    Low

    CVE-2025-7100

    Last Modified: 15 Sept 2025

    A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown functionality of the file /application/user/controller/Index.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jul 2025
    7.5
    High

    CVE-2025-52492

    Last Modified: 15 Apr 2026

    A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz, contains hard-coded credentials for the Twilio API. A remote attacker who obtains a copy of the firmware can extract these credentials. This could allow the attacker to gain unauthorized access to the associated Twilio account, leading to information disclosure, potential service disruption, and unauthorized use of the Twilio services.

    Published: 7 Jul 2025
    9.8
    Critical

    CVE-2025-43932

    Last Modified: 15 Apr 2026

    JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.

    Published: 7 Jul 2025
    7.5
    High

    CVE-2024-25177

    Last Modified: 3 Nov 2025

    LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS).

    Published: 7 Jul 2025
    9.1
    Critical

    CVE-2025-47202

    Last Modified: 27 Oct 2025

    In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400, the lack of a length check leads to out-of-bounds writes.

    Published: 7 Jul 2025
    9.8
    Critical

    CVE-2025-45479

    Last Modified: 10 Oct 2025

    Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted content into a container.

    Published: 7 Jul 2025