Latest CVE Feed
-
7.7
HIGHCVE-2025-32455
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Inj... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-5847
A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the... Read more
- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-27563
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-27247
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-27242
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-27131
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-26693
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-26691
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-25217
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-24493
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Race Condition
-
5.5
MEDIUMCVE-2025-23235
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through out-of-bounds read.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-21082
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-20063
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service
-
0.0
NACVE-2025-38004
In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via hrtimer. The content and also the length of the sequence can b... Read more
Affected Products : linux_kernel- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Race Condition
-
0.0
NACVE-2025-38003
In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procfs content When the procfs content is generated for a bcm_op which is in the process to be removed the procfs output might show unrelia... Read more
Affected Products : linux_kernel- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
9.0
CRITICALCVE-2024-55585
In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated by /api/v1/users/resetpassword.... Read more
Affected Products :- Published: Jun. 07, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-5840
A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. The manipulation of the argument uploaded_file leads to unrestr... Read more
- Published: Jun. 07, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Misconfiguration
-
9.0
HIGHCVE-2025-5839
A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Handler. The manipulation of the argument lanM... Read more
- Published: Jun. 07, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-5838
A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this vulnerability is an unknown functionality of the file /admin/adminprofile.php. The manipulation of the argument AdminName leads to sql i... Read more
Affected Products : employee_record_management_system- Published: Jun. 07, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-5837
A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is an unknown function of the file /admin/allemployees.php. The manipulation of the argument delid leads to sql injection. It is possible t... Read more
Affected Products : employee_record_management_system- Published: Jun. 07, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection