Search

Search Results (313486 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-39957 1 Linux 1 Linux Kernel 2025-10-09 N/A
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: increase scan_ies_len for S1G Currently the S1G capability element is not taken into account for the scan_ies_len, which leads to a buffer length validation failure in ieee80211_prep_hw_scan() and subsequent WARN in __ieee80211_start_scan(). This prevents hw scanning from functioning. To fix ensure we accommodate for the S1G capability length.
CVE-2025-39954 1 Linux 1 Linux Kernel 2025-10-09 N/A
In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: mp: Fix dual-divider clock rate readback When dual-divider clock support was introduced, the P divider offset was left out of the .recalc_rate readback function. This causes the clock rate to become bogus or even zero (possibly due to the P divider being 1, leading to a divide-by-zero). Fix this by incorporating the P divider offset into the calculation.
CVE-2025-47338 1 Qualcomm 1 Snapdragon 2025-10-09 7.8 High
Memory corruption while processing escape commands from userspace.
CVE-2025-27060 1 Qualcomm 1 Snapdragon 2025-10-09 8.8 High
Memory corruption while performing SCM call with malformed inputs.
CVE-2025-47355 1 Qualcomm 1 Snapdragon 2025-10-09 7.8 High
Memory corruption while invoking remote procedure IOCTL calls.
CVE-2025-47349 1 Qualcomm 1 Snapdragon 2025-10-09 7.8 High
Memory corruption while processing an escape call.
CVE-2025-47340 1 Qualcomm 1 Snapdragon 2025-10-09 7.8 High
Memory corruption while processing IOCTL call to get the mapping.
CVE-2025-27059 1 Qualcomm 1 Snapdragon 2025-10-09 8.8 High
Memory corruption while performing SCM call.
CVE-2025-27054 1 Qualcomm 1 Snapdragon 2025-10-09 7.8 High
Memory corruption while processing a malformed license file during reboot.
CVE-2025-27053 1 Qualcomm 1 Snapdragon 2025-10-09 7.8 High
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-27049 1 Qualcomm 1 Snapdragon 2025-10-09 5.5 Medium
Transient DOS while processing IOCTL call for image encoding.
CVE-2025-27048 1 Qualcomm 1 Snapdragon 2025-10-09 7.8 High
Memory corruption while processing camera platform driver IOCTL calls.
CVE-2025-27041 1 Qualcomm 1 Snapdragon 2025-10-09 5.5 Medium
Transient DOS while processing video packets received from video firmware.
CVE-2025-11525 1 Tenda 1 Ac7 2025-10-09 8.8 High
A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg. Such manipulation of the argument upnpEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-11166 2 Wordpress, Wpgmaps 3 Wordpress, Wp Go Maps, Wp Google Maps 2025-10-09 5.4 Medium
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 9.0.46. This is due to the plugin exposing state-changing REST actions through an AJAX bridge without proper CSRF token validation, and having destructive logic reachable via GET requests with no permission_callback. This makes it possible for unauthenticated attackers to force logged-in administrators to create, update, or delete markers and geometry features via CSRF attacks, and allows anonymous users to trigger mass deletion of markers via unsafe GET requests.
CVE-2025-11509 1 Code-projects 1 E-commerce Website 2025-10-09 6.3 Medium
A vulnerability was detected in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/product_add.php. Performing manipulation of the argument prod_name results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
CVE-2025-61913 1 Flowiseai 1 Flowise 2025-10-09 10 Critical
Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in Flowise do not restrict file path access, allowing authenticated attackers to exploit this vulnerability to read and write arbitrary files to any path in the file system, potentially leading to remote command execution. Flowise 3.0.8 fixes this vulnerability.
CVE-2025-11535 2 Microsoft, Mongodb 3 Windows, Connector For Bi, Mongodb 2025-10-09 N/A
MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.
CVE-2025-11503 1 Phpgurukul 1 Beauty Parlour Management System 2025-10-09 7.3 High
A vulnerability was determined in PHPGurukul Beauty Parlour Management System 1.1. This issue affects some unknown processing of the file /admin/manage-services.php. Executing manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
CVE-2025-11494 1 Gnu 1 Binutils 2025-10-09 3.3 Low
A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.