CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2024-58107

    Last Modified: 7 May 2025

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 7 Apr 2025
    4.6
    Medium

    CVE-2024-58106

    Last Modified: 7 May 2025

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3334

    Last Modified: 29 Apr 2025

    A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/category_save.php. The manipulation of the argument Category leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    7.5
    High

    CVE-2025-20664

    Last Modified: 11 Apr 2025

    In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406217; Issue ID: MSV-2773.

    Published: 7 Apr 2025
    7.5
    High

    CVE-2025-20663

    Last Modified: 11 Apr 2025

    In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00408868; Issue ID: MSV-3031.

    Published: 7 Apr 2025
    6.7
    Medium

    CVE-2025-20662

    Last Modified: 26 Feb 2026

    In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04428276; Issue ID: MSV-3184.

    Published: 7 Apr 2025
    6.7
    Medium

    CVE-2025-20661

    Last Modified: 26 Feb 2026

    In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04436357; Issue ID: MSV-3185.

    Published: 7 Apr 2025
    6.7
    Medium

    CVE-2025-20660

    Last Modified: 26 Feb 2026

    In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04436357; Issue ID: MSV-3186.

    Published: 7 Apr 2025
    6.5
    Medium

    CVE-2025-20659

    Last Modified: 17 Feb 2026

    In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01519028; Issue ID: MSV-2768.

    Published: 7 Apr 2025
    6
    Medium

    CVE-2025-20658

    Last Modified: 9 Apr 2025

    In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09474894; Issue ID: MSV-2597.

    Published: 7 Apr 2025
    6.7
    Medium

    CVE-2025-20657

    Last Modified: 26 Feb 2026

    In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09486425; Issue ID: MSV-2609.

    Published: 7 Apr 2025
    6.8
    Medium

    CVE-2025-20656

    Last Modified: 9 Apr 2025

    In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09625423; Issue ID: MSV-3033.

    Published: 7 Apr 2025
    5.3
    Medium

    CVE-2025-20655

    Last Modified: 9 Apr 2025

    In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04427687; Issue ID: MSV-3183.

    Published: 7 Apr 2025
    9.8
    Critical

    CVE-2025-20654

    Last Modified: 26 Feb 2026

    In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406897; Issue ID: MSV-2875.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3333

    Last Modified: 29 Apr 2025

    A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/menu_update.php. The manipulation of the argument menu leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    3.3
    Low

    CVE-2025-27534

    Last Modified: 16 Oct 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

    Published: 7 Apr 2025
    3.3
    Low

    CVE-2025-25057

    Last Modified: 16 Oct 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

    Published: 7 Apr 2025
    3.3
    Low

    CVE-2025-24304

    Last Modified: 16 Oct 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds write.

    Published: 7 Apr 2025
    6.5
    Medium

    CVE-2025-22851

    Last Modified: 16 Oct 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow.

    Published: 7 Apr 2025
    3.3
    Low

    CVE-2025-22842

    Last Modified: 16 Oct 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

    Published: 7 Apr 2025
    3.3
    Low

    CVE-2025-22452

    Last Modified: 16 Oct 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

    Published: 7 Apr 2025
    3.3
    Low

    CVE-2025-20102

    Last Modified: 16 Oct 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3332

    Last Modified: 7 Apr 2025

    A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. Affected is an unknown function of the file /admin/menu_save.php. The manipulation of the argument menu leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3331

    Last Modified: 7 Apr 2025

    A vulnerability, which was classified as critical, has been found in codeprojects Online Restaurant Management System 1.0. This issue affects some unknown processing of the file /payment_save.php. The manipulation of the argument mode leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3330

    Last Modified: 7 Apr 2025

    A vulnerability classified as critical was found in codeprojects Online Restaurant Management System 1.0. This vulnerability affects unknown code of the file /reservation_save.php. The manipulation of the argument first leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 7 Apr 2025
    —
    Unknown

    CVE-2025-3358

    Last Modified: 29 Apr 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Apr 2025
    2.3
    Low

    CVE-2025-3329

    Last Modified: 8 Apr 2025

    A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3.2/15.0.0.8. This affects an unknown part of the component Restaurant Order Handler. The manipulation of the argument Login/Password leads to cleartext transmission of sensitive information. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    8.7
    High

    CVE-2025-3328

    Last Modified: 7 Apr 2025

    A vulnerability was found in Tenda AC1206 15.03.06.23. It has been classified as critical. Affected is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid/timeZone leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 7 Apr 2025
    5.1
    Medium

    CVE-2025-3327

    Last Modified: 8 Apr 2025

    A vulnerability was found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This issue affects some unknown processing of the file /common/upload/batch of the component File Upload. The manipulation of the argument File leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    3.7
    Low

    CVE-2025-3360

    Last Modified: 30 Jun 2026

    A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.

    Published: 7 Apr 2025
    8.1
    High

    CVE-2025-32409

    Last Modified: 15 Apr 2026

    Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.

    Published: 7 Apr 2025
    6.1
    Medium

    CVE-2025-29594

    Last Modified: 15 Apr 2026

    A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET['errorcode'] parameter can be manipulated to access unauthorized error codes, leading to Cross-Site Scripting (XSS) attacks and information disclosure.

    Published: 7 Apr 2025
    6.2
    Medium

    CVE-2025-2251

    Last Modified: 25 Jun 2026

    A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a specially crafted serialized object, leading to remote code execution without requiring authentication.

    Published: 7 Apr 2025
    8.8
    High

    CVE-2025-28407

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId

    Published: 7 Apr 2025
    5.4
    Medium

    CVE-2024-46494

    Last Modified: 23 Apr 2025

    A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.

    Published: 7 Apr 2025
    6.2
    Medium

    CVE-2025-29481

    Last Modified: 25 Feb 2026

    Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that "no one in their sane mind should be passing untrusted ELF files into libbpf while running under root."

    Published: 7 Apr 2025
    6.2
    Medium

    CVE-2025-3359

    Last Modified: 3 May 2026

    A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.

    Published: 7 Apr 2025
    9.8
    Critical

    CVE-2025-28406

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter

    Published: 7 Apr 2025
    9.8
    Critical

    CVE-2025-28405

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method

    Published: 7 Apr 2025
    6.7
    Medium

    CVE-2025-28400

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method

    Published: 7 Apr 2025
    6.7
    Medium

    CVE-2025-28401

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter

    Published: 7 Apr 2025
    9.8
    Critical

    CVE-2025-28402

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter

    Published: 7 Apr 2025
    7.2
    High

    CVE-2025-28403

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings

    Published: 7 Apr 2025
    9.8
    Critical

    CVE-2025-28408

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter

    Published: 7 Apr 2025
    8.8
    High

    CVE-2025-28409

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId

    Published: 7 Apr 2025
    9.8
    Critical

    CVE-2025-28410

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges

    Published: 7 Apr 2025
    9.8
    Critical

    CVE-2025-28411

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave

    Published: 7 Apr 2025
    9.8
    Critical

    CVE-2025-28412

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController

    Published: 7 Apr 2025
    9.8
    Critical

    CVE-2025-28413

    Last Modified: 9 Apr 2025

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

    Published: 7 Apr 2025
    3.2
    Low

    CVE-2025-29087

    Last Modified: 30 Apr 2025

    In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of the result buffer, and thus malloc may not allocate enough memory.

    Published: 7 Apr 2025