CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-21421

    Last Modified: 26 Feb 2026

    Memory corruption while processing escape code in API.

    Published: 7 Apr 2025
    6.7
    Medium

    CVE-2024-49848

    Last Modified: 26 Feb 2026

    Memory corruption while processing multiple IOCTL calls from HLOS to DSP.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2024-45557

    Last Modified: 26 Feb 2026

    Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.

    Published: 7 Apr 2025
    6.5
    Medium

    CVE-2024-45556

    Last Modified: 19 Aug 2025

    Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.

    Published: 7 Apr 2025
    8.2
    High

    CVE-2024-45552

    Last Modified: 6 Oct 2025

    Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.

    Published: 7 Apr 2025
    6.2
    Medium

    CVE-2024-45551

    Last Modified: 6 Oct 2025

    Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.

    Published: 7 Apr 2025
    7.7
    High

    CVE-2024-45549

    Last Modified: 6 Oct 2025

    Information disclosure while creating MQ channels.

    Published: 7 Apr 2025
    6.6
    Medium

    CVE-2024-45544

    Last Modified: 6 Oct 2025

    Memory corruption while processing IOCTL calls to add route entry in the HW.

    Published: 7 Apr 2025
    6.6
    Medium

    CVE-2024-45543

    Last Modified: 6 Oct 2025

    Memory corruption while accessing MSM channel map and mixer functions.

    Published: 7 Apr 2025
    6.6
    Medium

    CVE-2024-45540

    Last Modified: 6 Oct 2025

    Memory corruption while invoking IOCTL map buffer request from userspace.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2024-43067

    Last Modified: 26 Feb 2026

    Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2024-43066

    Last Modified: 6 Oct 2025

    Memory corruption while handling file descriptor during listener registration/de-registration.

    Published: 7 Apr 2025
    7.1
    High

    CVE-2024-43065

    Last Modified: 6 Oct 2025

    Cryptographic issues while generating an asymmetric key pair for RKP use cases.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2024-43058

    Last Modified: 20 Aug 2025

    Memory corruption while processing IOCTL calls.

    Published: 7 Apr 2025
    5.5
    Medium

    CVE-2024-43046

    Last Modified: 6 Oct 2025

    There may be information disclosure during memory re-allocation in TZ Secure OS.

    Published: 7 Apr 2025
    7.5
    High

    CVE-2024-33058

    Last Modified: 3 Oct 2025

    Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.

    Published: 7 Apr 2025
    5.3
    Medium

    CVE-2025-3347

    Last Modified: 28 May 2025

    A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dental_pending.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    8.7
    High

    CVE-2025-3346

    Last Modified: 27 May 2025

    A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. Affected by this issue is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument pptp_server_start_ip/pptp_server_end_ip leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3345

    Last Modified: 30 Apr 2025

    A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/combo.php. The manipulation of the argument del leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    8.8
    High

    CVE-2025-30473

    Last Modified: 26 Feb 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using the partition clause in SQLTableCheckOperator as parameter (which was a recommended pattern), Authenticated UI User could inject arbitrary SQL command when triggering DAG exposing partition_clause to the user. This allowed the DAG Triggering user to escalate privileges to execute those arbitrary commands which they normally would not have. This issue affects Apache Airflow Common SQL Provider: before 1.24.1. Users are recommended to upgrade to version 1.24.1, which fixes the issue.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3344

    Last Modified: 30 Apr 2025

    A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/assign_save.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    8.4
    High

    CVE-2024-11859

    Last Modified: 15 Apr 2026

    DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicious dynamic-link library and execute its code.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3343

    Last Modified: 30 Apr 2025

    A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/reservation_update.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3342

    Last Modified: 30 Apr 2025

    A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/payment_save.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3341

    Last Modified: 30 Apr 2025

    A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. This affects an unknown part of the file /admin/reservation_view.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3340

    Last Modified: 29 Apr 2025

    A vulnerability, which was classified as critical, has been found in codeprojects Online Restaurant Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/combo_update.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    7.7
    High

    CVE-2024-11071

    Last Modified: 15 Apr 2026

    Permissive Cross-domain Policy with Untrusted Domains vulnerability in local API server of DestinyECM solution(versions described below) which is developed and maintained by Cyberdigm may allow Cross-Site Request Forgery (CSRF) attack, which probabilistically enables JSON Hijacking (aka JavaScript Hijacking) via forgery web page.* Due to product customization, version information may differ from the following version description. For further inquiries, please contact the vendor.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3339

    Last Modified: 29 Apr 2025

    A vulnerability classified as critical was found in codeprojects Online Restaurant Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user_update.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3338

    Last Modified: 29 Apr 2025

    A vulnerability classified as critical has been found in codeprojects Online Restaurant Management System 1.0. Affected is an unknown function of the file /admin/user_save.php. The manipulation of the argument Name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3337

    Last Modified: 11 Apr 2025

    A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/member_update.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3336

    Last Modified: 11 Apr 2025

    A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/member_save.php. The manipulation of the argument last leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3335

    Last Modified: 11 Apr 2025

    A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/category_update.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    8.4
    High

    CVE-2025-31175

    Last Modified: 7 May 2025

    Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect service integrity.

    Published: 7 Apr 2025
    6.8
    Medium

    CVE-2025-31174

    Last Modified: 26 Sept 2025

    Path traversal vulnerability in the DFS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 7 Apr 2025
    8.8
    High

    CVE-2025-31173

    Last Modified: 7 May 2025

    Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2025-31172

    Last Modified: 7 May 2025

    Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 7 Apr 2025
    6.8
    Medium

    CVE-2025-31171

    Last Modified: 26 Sept 2025

    File read permission bypass vulnerability in the kernel file system module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 7 Apr 2025
    8.4
    High

    CVE-2025-31170

    Last Modified: 7 May 2025

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

    Published: 7 Apr 2025
    8.4
    High

    CVE-2024-58127

    Last Modified: 7 May 2025

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

    Published: 7 Apr 2025
    8.4
    High

    CVE-2024-58126

    Last Modified: 7 May 2025

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

    Published: 7 Apr 2025
    8.4
    High

    CVE-2024-58125

    Last Modified: 7 May 2025

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

    Published: 7 Apr 2025
    8.4
    High

    CVE-2024-58124

    Last Modified: 7 May 2025

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

    Published: 7 Apr 2025
    4
    Medium

    CVE-2024-58116

    Last Modified: 7 May 2025

    Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 7 Apr 2025
    4
    Medium

    CVE-2024-58115

    Last Modified: 7 May 2025

    Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 7 Apr 2025
    5.3
    Medium

    CVE-2024-58113

    Last Modified: 7 May 2025

    Vulnerability of improper resource management in the memory management module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 7 Apr 2025
    7.5
    High

    CVE-2024-58112

    Last Modified: 7 May 2025

    Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 7 Apr 2025
    7.5
    High

    CVE-2024-58111

    Last Modified: 7 May 2025

    Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 7 Apr 2025
    4.6
    Medium

    CVE-2024-58110

    Last Modified: 7 May 2025

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 7 Apr 2025
    4.6
    Medium

    CVE-2024-58109

    Last Modified: 7 May 2025

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 7 Apr 2025
    4.6
    Medium

    CVE-2024-58108

    Last Modified: 7 May 2025

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 7 Apr 2025