CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2025-29627

    Last Modified: 16 Jul 2025

    An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module

    Published: 9 Jun 2025
    7.5
    High

    CVE-2025-45001

    Last Modified: 23 Jun 2025

    react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.

    Published: 9 Jun 2025
    5.4
    Medium

    CVE-2025-45002

    Last Modified: 23 Jun 2025

    Vigybag v1.0 and before is vulnerable to Cross Site Scripting (XSS) via the upload profile picture function under my profile.

    Published: 9 Jun 2025
    5.4
    Medium

    CVE-2025-45055

    Last Modified: 25 Jun 2025

    Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections.

    Published: 9 Jun 2025
    5.4
    Medium

    CVE-2025-46041

    Last Modified: 25 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interface (/admin/pages/add).

    Published: 9 Jun 2025
    6.1
    Medium

    CVE-2025-46178

    Last Modified: 2 Jul 2025

    Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, leading to session hijacking or defacement.

    Published: 9 Jun 2025
    7.4
    High

    CVE-2025-5851

    Last Modified: 9 Jun 2025

    A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been rated as critical. This issue affects the function fromadvsetlanip of the file /goform/AdvSetLanip of the component HTTP POST Request Handler. The manipulation of the argument lanMask leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jun 2025
    7.4
    High

    CVE-2025-5850

    Last Modified: 9 Jun 2025

    A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been declared as critical. This vulnerability affects the function formsetschedled of the file /goform/SetLEDCf of the component HTTP POST Request Handler. The manipulation of the argument Time leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jun 2025
    7.4
    High

    CVE-2025-5849

    Last Modified: 9 Jun 2025

    A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been classified as critical. This affects the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the argument remoteIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jun 2025
    7.4
    High

    CVE-2025-5848

    Last Modified: 9 Jun 2025

    A vulnerability was found in Tenda AC15 15.03.05.19_multi and classified as critical. Affected by this issue is the function formSetPPTPUserList of the file /goform/setPptpUserList of the component HTTP POST Request Handler. The manipulation of the argument list leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jun 2025
    7.1
    High

    CVE-2025-35010

    Last Modified: 12 Jan 2026

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNPINGTM command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.

    Published: 8 Jun 2025
    7.1
    High

    CVE-2025-35009

    Last Modified: 12 Jan 2026

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNNETSP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.

    Published: 8 Jun 2025
    7.1
    High

    CVE-2025-35008

    Last Modified: 12 Jan 2026

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MMNAME command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.

    Published: 8 Jun 2025
    7.1
    High

    CVE-2025-35007

    Last Modified: 12 Jan 2026

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFRULE command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.

    Published: 8 Jun 2025
    7.1
    High

    CVE-2025-35006

    Last Modified: 12 Jan 2026

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFPORTFWD command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.

    Published: 8 Jun 2025
    7.1
    High

    CVE-2025-35005

    Last Modified: 12 Jan 2026

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFMAC command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.

    Published: 8 Jun 2025
    7.1
    High

    CVE-2025-35004

    Last Modified: 12 Jan 2026

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFIP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.

    Published: 8 Jun 2025
    7.7
    High

    CVE-2025-32459

    Last Modified: 21 Jan 2026

    The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the sync_time argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.

    Published: 8 Jun 2025
    7.7
    High

    CVE-2025-32458

    Last Modified: 21 Jan 2026

    The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_syslog_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.

    Published: 8 Jun 2025
    7.7
    High

    CVE-2025-32457

    Last Modified: 13 Jan 2026

    The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_file_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.

    Published: 8 Jun 2025
    7.7
    High

    CVE-2025-32456

    Last Modified: 13 Jan 2026

    The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the put_file_to_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.

    Published: 8 Jun 2025
    7.7
    High

    CVE-2025-32455

    Last Modified: 13 Jan 2026

    The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.

    Published: 8 Jun 2025
    9.1
    Critical

    CVE-2025-3461

    Last Modified: 13 Jan 2026

    The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is estimated as a CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.

    Published: 8 Jun 2025
    7.7
    High

    CVE-2025-3460

    Last Modified: 21 Jan 2026

    The Quantenna Wi-Fi chipset ships with a local control script, set_tx_pow, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.

    Published: 8 Jun 2025
    7.7
    High

    CVE-2025-3459

    Last Modified: 21 Jan 2026

    The Quantenna Wi-Fi chipset ships with a local control script, transmit_file, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.

    Published: 8 Jun 2025
    7.4
    High

    CVE-2025-5847

    Last Modified: 9 Jun 2025

    A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the argument remoteIp leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jun 2025
    5.5
    Medium

    CVE-2025-27247

    Last Modified: 9 Jun 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

    Published: 8 Jun 2025
    3.3
    Low

    CVE-2025-27242

    Last Modified: 9 Jun 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

    Published: 8 Jun 2025
    3.3
    Low

    CVE-2025-27563

    Last Modified: 9 Jun 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

    Published: 8 Jun 2025
    3.3
    Low

    CVE-2025-26693

    Last Modified: 9 Jun 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

    Published: 8 Jun 2025
    5.5
    Medium

    CVE-2025-26691

    Last Modified: 9 Jun 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

    Published: 8 Jun 2025
    6.1
    Medium

    CVE-2025-27131

    Last Modified: 9 Jun 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

    Published: 8 Jun 2025
    5.5
    Medium

    CVE-2025-24493

    Last Modified: 9 Jun 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.

    Published: 8 Jun 2025
    3.3
    Low

    CVE-2025-25217

    Last Modified: 9 Jun 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

    Published: 8 Jun 2025
    3.3
    Low

    CVE-2025-23235

    Last Modified: 9 Jun 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through out-of-bounds read.

    Published: 8 Jun 2025
    3.3
    Low

    CVE-2025-21082

    Last Modified: 9 Jun 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

    Published: 8 Jun 2025
    3.3
    Low

    CVE-2025-20063

    Last Modified: 9 Jun 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

    Published: 8 Jun 2025
    7.8
    High

    CVE-2025-38003

    Last Modified: 30 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procfs content When the procfs content is generated for a bcm_op which is in the process to be removed the procfs output might show unreliable data (UAF). As the removal of bcm_op's is already implemented with rcu handling this patch adds the missing rcu_read_lock() and makes sure the list entries are properly removed under rcu protection.

    Published: 8 Jun 2025
    7.3
    High

    CVE-2025-38004

    Last Modified: 30 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via hrtimer. The content and also the length of the sequence can be changed resp reduced at runtime where the 'currframe' counter is then set to zero. Although this appeared to be a safe operation the updates of 'currframe' can be triggered from user space and hrtimer context in bcm_can_tx(). Anderson Nascimento created a proof of concept that triggered a KASAN slab-out-of-bounds read access which can be prevented with a spin_lock_bh. At the rework of bcm_can_tx() the 'count' variable has been moved into the protected section as this variable can be modified from both contexts too.

    Published: 8 Jun 2025
    6.9
    Medium

    CVE-2025-5840

    Last Modified: 10 Jun 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. The manipulation of the argument uploaded_file leads to unrestricted upload. It is possible to initiate the attack remotely.

    Published: 7 Jun 2025
    7.4
    High

    CVE-2025-5839

    Last Modified: 9 Jun 2025

    A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Handler. The manipulation of the argument lanMask leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jun 2025
    2.1
    Low

    CVE-2025-5838

    Last Modified: 10 Jun 2025

    A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this vulnerability is an unknown functionality of the file /admin/adminprofile.php. The manipulation of the argument AdminName leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jun 2025
    2.1
    Low

    CVE-2025-5837

    Last Modified: 9 Jun 2025

    A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is an unknown function of the file /admin/allemployees.php. The manipulation of the argument delid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jun 2025
    2.1
    Low

    CVE-2025-5836

    Last Modified: 9 Jun 2025

    A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jun 2025
    6.4
    Medium

    CVE-2024-9993

    Last Modified: 8 Apr 2026

    The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of Event Calendar Widget in all versions up to, and including, 6.1.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Jun 2025
    6.4
    Medium

    CVE-2025-5568

    Last Modified: 20 Apr 2026

    The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Jun 2025
    6.1
    Medium

    CVE-2025-5528

    Last Modified: 22 Apr 2026

    The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.75 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action, such as clicking on a link.

    Published: 7 Jun 2025
    6.4
    Medium

    CVE-2024-9994

    Last Modified: 8 Apr 2026

    The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content parameter of the Pricing Table Widget in all versions up to, and including, 6.1.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Jun 2025
    7.2
    High

    CVE-2025-5303

    Last Modified: 15 Apr 2026

    The LTL Freight Quotes – Freightview Edition, LTL Freight Quotes – Daylight Edition and LTL Freight Quotes – Day & Ross Edition plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the expiry_date parameter in all versions up to, and including, 1.0.11, 2.2.6 and 2.1.10 respectively, due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Jun 2025
    7.5
    High

    CVE-2025-5399

    Last Modified: 30 Jul 2025

    Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless busy-loop. There is no other way for the application to escape or exit this loop other than killing the thread/process. This might be used to DoS libcurl-using application.

    Published: 7 Jun 2025