CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 7.5 | Information disclosure while accessing and modifying the PIB file of a remote device via powerline. |
| 1mo ago | 7.8 | Memory corruption while processing simultaneous requests via escape path. |
| 1mo ago | 7.8 | Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host. |
| 1mo ago | 7.5 | Transient DOS while creating NDP instance. |
| 1mo ago | 7.3 | Memory corruption while processing specific files in Powerline Communication Firmware. |
| 1mo ago | 7.8 | Memory corruption while processing DDI command calls. |
| 1mo ago | 7.8 | Memory corruption while processing an IOCTL command with an arbitrary address. |
| 1mo ago | 7.8 | Memory corruption while processing DDI call with invalid buffer. |
| 1mo ago | 7.5 | Transient DOS while processing an ANQP message. |
| 1mo ago | 7.5 | Transient DOS while processing a frame with malformed shared-key descriptor. |
| 1mo ago | 7.8 | Memory corruption while handling client exceptions, allowing unauthorized channel access. |
| 1mo ago | 7.5 | Transient DOS while processing CCCH data when NW sends data with invalid length. |
| 1mo ago | 7.8 | Memory corruption while processing commands from A2dp sink command queue. |
| 1mo ago | 7.8 | Memory corruption when using Virtual cdm (Camera Data Mover) to write registers. |
| 1mo ago | 7.8 | Memory corruption when programming registers through virtual CDM. |
| 1mo ago | 7.8 | Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously. |
| 1mo ago | 7.8 | Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently. |
| 1mo ago | 7.8 | Memory corruption while submitting blob data to kernel space though IOCTL. |
| 1mo ago | 7.5 | Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network. |
| Exploit 1mo ago | 8.1 | Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called |
| Exploit 1mo ago | 8 | Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Successful exploitation of this vulnerability may affect availability. |
| Exploit 1mo ago | 8.8 | Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. |
| Exploit 1mo ago | 8.8 | Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ReadMVGImage function. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-26313. |
| Exploit 1mo ago | 8.8 | Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwood DMX958XR. Authentication is not required to exploit this vulnerability. The specific flaw exists within the JKRadioService. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-26312. |
| 1mo ago | 7.5 | The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE-2025-49059 may be a duplicate of this issue. |
| Exploit 1mo ago | 8.3 | Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. |
| Exploit 1mo ago | 7.3 | EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. |
| Exploit 1mo ago | 7.7 | Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. |
| Exploit 1mo ago | 7.3 | Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. |
| Exploit 1mo ago | 8.1 | Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization graphics module. |