CVE-2025-49203
Last Modified: 4 Jun 2025Not used
CVE-2025-49204
Last Modified: 4 Jun 2025Not used
CVE-2025-49205
Last Modified: 4 Jun 2025Not used
CVE-2025-21479
Last Modified: 26 Feb 2026Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2025-4567
Last Modified: 1 Aug 2025The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2025-3662
Last Modified: 5 Jun 2025The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a Contributor+ Stored XSS, however one of our researcher (Marc Montpas) escalated it to an Unauthenticated Stored XSS
CVE-2025-3584
Last Modified: 5 Jun 2025The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2025-27038
Last Modified: 26 Feb 2026Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
CVE-2025-27031
Last Modified: 20 Aug 2025memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.
CVE-2025-27029
Last Modified: 20 Aug 2025Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.
CVE-2025-21486
Last Modified: 26 Feb 2026Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.
CVE-2025-21485
Last Modified: 26 Feb 2026Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.
CVE-2025-21480
Last Modified: 26 Feb 2026Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2025-21463
Last Modified: 28 Nov 2025Transient DOS while processing the EHT operation IE in the received beacon frame.
CVE-2024-53026
Last Modified: 28 Nov 2025Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53021
Last Modified: 28 Nov 2025Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2024-53020
Last Modified: 28 Nov 2025Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2024-53019
Last Modified: 20 Aug 2025Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
CVE-2024-53018
Last Modified: 20 Aug 2025Memory corruption may occur while processing the OIS packet parser.
CVE-2024-53017
Last Modified: 20 Aug 2025Memory corruption while handling test pattern generator IOCTL command.
CVE-2024-53016
Last Modified: 20 Aug 2025Memory corruption while processing I2C settings in Camera driver.
CVE-2024-53015
Last Modified: 28 Nov 2025Memory corruption while processing IOCTL command to handle buffers associated with a session.
CVE-2024-53013
Last Modified: 20 Aug 2025Memory corruption may occur while processing voice call registration with user.
CVE-2024-53010
Last Modified: 28 Nov 2025Memory corruption may occur while attaching VM when the HLOS retains access to VM.
CVE-2025-31712
Last Modified: 10 Jun 2025In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed.
CVE-2025-31711
Last Modified: 10 Jun 2025In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additional execution privileges needed.
CVE-2025-31710
Last Modified: 10 Jun 2025In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.
CVE-2025-4797
Last Modified: 21 Apr 2026The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0. This is due to the plugin not properly validating a user's identity prior to setting an authorization cookie. This makes it possible for unauthenticated attackers to log in as any user, including administrators, provided they know the user's email address. CVE-2025-54725 is likely a duplicate of this issue.
CVE-2025-4224
Last Modified: 22 Apr 2026The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2025-2939
Last Modified: 22 Apr 2026The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited.
CVE-2025-4047
Last Modified: 21 Apr 2026The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the ajax_full_status and ajax_dashboard_status functions in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view the plugin's status.
CVE-2025-23102
Last Modified: 10 Jun 2025An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380, 1480 and 2400. A Double Free in the mobile processor leads to privilege escalation.
CVE-2025-32105
Last Modified: 18 Jun 2025A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remote code execution.
CVE-2025-43924
Last Modified: 9 Jun 2025Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (for /fp/admin/settings/loginpage) and the rootserviceurl parameter in FriendsController (for /fp/admin/settings/friends), entered by an admin, allow stored XSS.
CVE-2025-44148
Last Modified: 9 Jun 2025Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component
CVE-2025-23097
Last Modified: 6 Jun 2025An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds writes.
CVE-2025-23098
Last Modified: 6 Jun 2025An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor leads to privilege escalation.
CVE-2025-23100
Last Modified: 6 Jun 2025An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. The absence of a NULL check leads to a Denial of Service.
CVE-2025-23103
Last Modified: 6 Jun 2025An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.
CVE-2025-23107
Last Modified: 6 Jun 2025An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.
CVE-2025-32106
Last Modified: 18 Jun 2025In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.
CVE-2025-43923
Last Modified: 9 Jun 2025An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Focal Point can perform SQL injection via the image parameter during a delete report image operation.
CVE-2025-43925
Last Modified: 11 Jun 2025An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to recover the cleartext data.
CVE-2025-45854
Last Modified: 26 Aug 2025/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.
CVE-2025-45855
Last Modified: 23 Jun 2025An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2025-46154
Last Modified: 9 Jun 2025Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.
CVE-2025-5068
Last Modified: 26 Feb 2026Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5419
Last Modified: 26 Feb 2026Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-5489
Last Modified: 16 Jan 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-3919
Last Modified: 22 Apr 2026The WordPress Comments Import & Export plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings function in all versions up to, and including, 2.4.3. Additionally, the plugin fails to properly sanitize and escape FTP settings parameters. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts on the plugin settings page that will execute whenever an administrative user accesses an injected page. The vulnerability was partially fixed in version 2.4.3 and fully fixed in version 2.4.4
