Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2025-60865 — Avanquest Driver Updater Privilege Escalation Vulnerability

Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component.

pc_helpsoft_driver_updater | Authorization
Feb 03, 2026 Feb 10, 2026
Feb 03, 2026
Feb 10, 2026
7.5 HIGH
CVE-2025-59439 — Samsung Modem Exynos Denial of Service Vulnerability

An issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920, W930, W1000 and Modem 5123. Incorrect handling of NAS Registration messages l…

Feb 03, 2026 Feb 05, 2026
Feb 03, 2026
Feb 05, 2026
6.2 MEDIUM
CVE-2025-58348 — Samsung Exynos Wi-Fi Driver Kernel Memory Exhaustion Vulnerability

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory all…

Feb 03, 2026 Feb 09, 2026
Feb 03, 2026
Feb 09, 2026
6.2 MEDIUM
CVE-2025-58347 — Samsung Exynos Wi-Fi Driver Unbounded Memory Allocation Kernel Exhaustion

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory all…

Feb 03, 2026 Feb 09, 2026
Feb 03, 2026
Feb 09, 2026
6.2 MEDIUM
CVE-2025-58346 — Samsung Exynos Wi-Fi Driver Kernel Memory Exhaustion

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory all…

Feb 03, 2026 Feb 09, 2026
Feb 03, 2026
Feb 09, 2026
6.2 MEDIUM
CVE-2025-58345 — Samsung Exynos Wi-Fi Driver Unbounded Memory Allocation Buffer Overflow Vulnerability

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory all…

Feb 03, 2026 Feb 09, 2026
Feb 03, 2026
Feb 09, 2026
6.2 MEDIUM
CVE-2025-58344 — Samsung Exynos Wi-Fi Driver Kernel Memory Exhaustion

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory all…

Feb 03, 2026 Feb 05, 2026
Feb 03, 2026
Feb 05, 2026
6.2 MEDIUM
CVE-2025-58343 — Samsung Exynos Wi-Fi Driver Kernel Memory Exhaustion

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory all…

Feb 03, 2026 Feb 09, 2026
Feb 03, 2026
Feb 09, 2026
6.2 MEDIUM
CVE-2025-58342 — Samsung Exynos Wi-Fi Driver Unbounded Memory Allocation Buffer Overflow

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory all…

Feb 03, 2026 Feb 05, 2026
Feb 03, 2026
Feb 05, 2026
6.2 MEDIUM
CVE-2025-58341 — Samsung Exynos Wi-Fi Driver Kernel Memory Exhaustion

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory all…

Feb 03, 2026 Feb 05, 2026
Feb 03, 2026
Feb 05, 2026
6.2 MEDIUM
CVE-2025-58340 — Samsung Exynos Wi-Fi Driver Unbounded Memory Allocation Denial of Service

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory all…

Feb 03, 2026 Feb 05, 2026
Feb 03, 2026
Feb 05, 2026
9.8 CRITICAL
CVE-2025-57529 — YouDataSum CPAS Audit Management System SQL Injection

YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validation. This allows remote unauthenticated attackers to…

cpas_audit_management_system | Remote | Injection
Feb 03, 2026 Feb 10, 2026
Feb 03, 2026
Feb 10, 2026
6.1 MEDIUM
CVE-2025-52629 — HCL AION is susceptible to Missing Content-Security-Policy

HCL AION is susceptible to Missing Content-Security-Policy.  An The absence of a CSP header may increase the risk of cross-site scripting and other content injection attacks by allowing unsafe scrip…

aion | Remote | Misconfiguration
Feb 03, 2026 Feb 10, 2026
Feb 03, 2026
Feb 10, 2026
7.5 HIGH
CVE-2025-52627 — HCL AION is susceptible to Incorrect Permission Assignment for Critical Resource

Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauth…

aion | Remote | Misconfiguration
Feb 03, 2026 Feb 10, 2026
Feb 03, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2025-52626 — HCL AION is susceptible to Potential Command Injection vulnerability

A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AIO…

aion | Remote | Injection
Feb 03, 2026 Feb 10, 2026
Feb 03, 2026
Feb 10, 2026
9.1 CRITICAL
CVE-2025-46651 — Tiny File Manager SSRF

Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted…

tiny_file_manager | Remote | Server-Side Request Forgery
Feb 03, 2026 Feb 10, 2026
Feb 03, 2026
Feb 10, 2026
8.8 HIGH
CVE-2020-37116 — GUnet OpenEclass 1.7.3 E-learning platform - phpMyAdmin Remote Access

GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploading a shell, view the…

open_eclass_platform | Remote | Authentication
Feb 03, 2026 Feb 10, 2026
Feb 03, 2026
Feb 10, 2026
7.1 HIGH
CVE-2020-37115 — GUnet OpenEclass 1.7.3 E-learning platform - Plaintext Password Storage

GUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users' usernames and passwords without encryption. This vulnerability exposes sensitive inf…

open_eclass_platform | Remote | Information Disclosure
Feb 03, 2026 Feb 10, 2026
Feb 03, 2026
Feb 10, 2026
6.5 MEDIUM
CVE-2020-37114 — GUnet OpenEclass 1.7.3 E-learning platform - Information Disclosure

GUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system information, application version, and other students' uploaded assessments, due…

open_eclass_platform | Remote | Information Disclosure
Feb 03, 2026 Feb 10, 2026
Feb 03, 2026
Feb 10, 2026
8.8 HIGH
CVE-2020-37113 — GUnet OpenEclass 1.7.3 E-learning platform - File Upload Extension Bypass

GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web shell and execute a…

open_eclass_platform | Remote | Authentication
Feb 03, 2026 Feb 12, 2026
Feb 03, 2026
Feb 12, 2026
Showing 20 of 5209 Results