CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2024-53025

    Last Modified: 6 Mar 2025

    Transient DOS can occur while processing UCI command.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-53024

    Last Modified: 26 Feb 2026

    Memory corruption in display driver while detaching a device.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-53023

    Last Modified: 26 Feb 2026

    Memory corruption may occur while accessing a variable during extended back to back tests.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-53022

    Last Modified: 26 Feb 2026

    Memory corruption may occur during communication between primary and guest VM.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-53014

    Last Modified: 26 Feb 2026

    Memory corruption may occur while validating ports and channels in Audio driver.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-53012

    Last Modified: 26 Feb 2026

    Memory corruption may occur due to improper input validation in clock device.

    Published: 3 Mar 2025
    7.9
    High

    CVE-2024-53011

    Last Modified: 26 Feb 2026

    Information disclosure may occur due to improper permission and access controls to Video Analytics engine.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-49836

    Last Modified: 26 Feb 2026

    Memory corruption may occur during the synchronization of the camera`s frame processing pipeline.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-45580

    Last Modified: 26 Feb 2026

    Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-43062

    Last Modified: 13 Jul 2025

    Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-43061

    Last Modified: 3 Mar 2025

    Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-43060

    Last Modified: 3 Mar 2025

    Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-43059

    Last Modified: 13 Jul 2025

    Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-43057

    Last Modified: 11 Aug 2025

    Memory corruption while processing command in Glink linux.

    Published: 3 Mar 2025
    5.5
    Medium

    CVE-2024-43056

    Last Modified: 11 Aug 2025

    Transient DOS during hypervisor virtual I/O operation in a virtual machine.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-43055

    Last Modified: 3 Mar 2025

    Memory corruption while processing camera use case IOCTL call.

    Published: 3 Mar 2025
    5.5
    Medium

    CVE-2024-43051

    Last Modified: 11 Aug 2025

    Information disclosure while deriving keys for a session for any Widevine use case.

    Published: 3 Mar 2025
    5.4
    Medium

    CVE-2024-38426

    Last Modified: 11 Aug 2025

    While processing the authentication message in UE, improper authentication may lead to information disclosure.

    Published: 3 Mar 2025
    5.4
    Medium

    CVE-2024-8186

    Last Modified: 3 Mar 2025

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations.

    Published: 3 Mar 2025
    6.9
    Medium

    CVE-2025-1859

    Last Modified: 12 Jul 2025

    A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. This issue affects some unknown processing of the file /login.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-24654

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugin by Squirrly SEO: from n/a through <= 12.4.07.

    Published: 3 Mar 2025
    10
    Critical

    CVE-2025-1867

    Last Modified: 15 Apr 2026

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in ithewei libhv allows HTTP Response Smuggling.This issue affects libhv: through 1.3.3.

    Published: 3 Mar 2025
    10
    Critical

    CVE-2025-1866

    Last Modified: 15 Apr 2026

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in warmcat libwebsockets allows Pointer Manipulation, potentially leading to out-of-bounds memory access. This issue affects libwebsockets before 4.3.4 and is present in code built specifically for the Win32 platform. By default, the affected code is not executed unless one of the following conditions is met: LWS_WITHOUT_EXTENSIONS (default ON) is manually set to OFF in CMake. LWS_WITH_HTTP_STREAM_COMPRESSION (default OFF) is manually set to ON in CMake. Despite these conditions, when triggered in affected configurations, this vulnerability may allow attackers to manipulate pointers, potentially leading to memory corruption or unexpected behavior.

    Published: 3 Mar 2025
    6.9
    Medium

    CVE-2025-1858

    Last Modified: 24 Jun 2025

    A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unknown code of the file /success.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-25280

    Last Modified: 15 Apr 2026

    Buffer overflow vulnerability exists in FutureNet AS series (Industrial Routers) and FA series (Protocol Conversion Machine) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may reboot the device by sending a specially crafted request.

    Published: 3 Mar 2025
    7.5
    High

    CVE-2025-24846

    Last Modified: 15 Apr 2026

    Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted request.

    Published: 3 Mar 2025
    10
    Critical

    CVE-2025-1864

    Last Modified: 1 Jul 2025

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects radare2: before <5.9.9.

    Published: 3 Mar 2025
    6.9
    Medium

    CVE-2025-1857

    Last Modified: 24 Jun 2025

    A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file /check_availability.php. The manipulation of the argument employeeid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    8.1
    High

    CVE-2025-1723

    Last Modified: 30 Sept 2025

    Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.

    Published: 3 Mar 2025
    6.9
    Medium

    CVE-2025-1856

    Last Modified: 24 Jun 2025

    A vulnerability was found in Codezips Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /dashboard/admin/gen_invoice.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2024-10925

    Last Modified: 26 Aug 2025

    A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-1855

    Last Modified: 24 Jun 2025

    A vulnerability was found in PHPGurukul Online Shopping Portal 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /product-details.php. The manipulation of the argument quality/price/value/name/summary/review leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-1854

    Last Modified: 24 Jun 2025

    A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/del_member.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    8.7
    High

    CVE-2025-1853

    Last Modified: 12 Jul 2025

    A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. This issue affects the function sub_49E098 of the file /goform/SetIpMacBind of the component Parameter Handler. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    8.7
    High

    CVE-2025-1852

    Last Modified: 3 Apr 2025

    A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    8.7
    High

    CVE-2025-1851

    Last Modified: 10 Apr 2025

    A vulnerability, which was classified as critical, was found in Tenda AC7 up to 15.03.06.44. This affects the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    6.9
    Medium

    CVE-2025-1850

    Last Modified: 4 Apr 2025

    A vulnerability, which was classified as critical, has been found in Codezips College Management System 1.0. Affected by this issue is some unknown functionality of the file /university.php. The manipulation of the argument book_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-1849

    Last Modified: 26 May 2025

    A vulnerability classified as critical was found in zj1983 zz up to 2024-8. Affected by this vulnerability is an unknown functionality of the file /import_data_todb. The manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-1848

    Last Modified: 26 May 2025

    A vulnerability classified as critical has been found in zj1983 zz up to 2024-8. Affected is an unknown function of the file /import_data_check. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-1847

    Last Modified: 26 May 2025

    A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-1846

    Last Modified: 28 May 2025

    A vulnerability was found in zj1983 zz up to 2024-8. It has been declared as problematic. This vulnerability affects the function deleteLocalFile of the file src/main/java/com/futvan/z/system/zfile/ZfileAction.java of the component File Handler. The manipulation of the argument zids leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Mar 2025
    6.5
    Medium

    CVE-2025-20653

    Last Modified: 22 Apr 2025

    In da, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291064; Issue ID: MSV-2046.

    Published: 3 Mar 2025
    4.6
    Medium

    CVE-2025-20652

    Last Modified: 22 Apr 2025

    In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291215; Issue ID: MSV-2052.

    Published: 3 Mar 2025
    4.1
    Medium

    CVE-2025-20651

    Last Modified: 22 Apr 2025

    In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291294; Issue ID: MSV-2062.

    Published: 3 Mar 2025
    6.8
    Medium

    CVE-2025-20650

    Last Modified: 26 Feb 2026

    In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291294; Issue ID: MSV-2061.

    Published: 3 Mar 2025
    6.5
    Medium

    CVE-2025-20649

    Last Modified: 22 Apr 2025

    In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00396437; Issue ID: MSV-2184.

    Published: 3 Mar 2025
    5.5
    Medium

    CVE-2025-20648

    Last Modified: 22 Apr 2025

    In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09456673; Issue ID: MSV-2584.

    Published: 3 Mar 2025
    6.5
    Medium

    CVE-2025-20647

    Last Modified: 17 Feb 2026

    In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00791311 / MOLY01067019; Issue ID: MSV-2721.

    Published: 3 Mar 2025
    9.8
    Critical

    CVE-2025-20646

    Last Modified: 26 Feb 2026

    In wlan AP FW, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389074; Issue ID: MSV-1803.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2025-20645

    Last Modified: 26 Feb 2026

    In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue ID: MSV-2599.

    Published: 3 Mar 2025