Search

Search Results (308044 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-21480 1 Samsung 3 Mobile, Samsung, Samsung Mobile 2025-09-03 8.5 High
Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.
CVE-2023-21471 1 Samsung 2 Mobile, Samsung Mobile 2025-09-03 4 Medium
Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.
CVE-2025-9817 1 Wireshark 1 Wireshark 2025-09-03 7.8 High
SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
CVE-2025-21028 1 Samsung 3 Mobile, Samsung, Samsung Mobile 2025-09-03 5.5 Medium
Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
CVE-2025-21038 2 Google, Samsung 5 Android, Assistant, Mobile and 2 more 2025-09-03 5.1 Medium
Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.
CVE-2023-21482 2 Google, Samsung 4 Android, Camera, Mobile and 1 more 2025-09-03 6.1 Medium
Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to install package through Galaxy store before completion of Setup wizard.
CVE-2025-21032 1 Samsung 3 Mobile, One Ui, Samsung Mobile 2025-09-03 5.9 Medium
Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.
CVE-2025-21033 2 Google, Samsung 3 Android, Mobile, Samsung Mobile 2025-09-03 4 Medium
Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.
CVE-2023-21466 2 Google, Samsung 3 Android, Mobile, Samsung Mobile 2025-09-03 5.3 Medium
PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.
CVE-2025-21041 2 Google, Samsung 3 Android, Mobile, Secure Folder 2025-09-03 6.2 Medium
Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.
CVE-2023-21477 1 Samsung 2 Mobile, Samsung Mobile 2025-09-03 7.9 High
Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.
CVE-2023-21483 1 Samsung 1 Galaxy Store 2025-09-03 6.4 Medium
Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.
CVE-2025-58272 2 Ntt-east, Ntt-west 2 Web Caster, Web Caster 2025-09-03 N/A
Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views a malicious page created by an attacker, the settings of the product may be unintentionally changed.
CVE-2023-21481 1 Samsung 1 Account 2025-09-03 5.4 Medium
Improper URL input validation vulnerability in Samsung Account application prior to version 14.1.0.0 allows remote attackers to get sensitive information.
CVE-2023-21478 1 Samsung 2 Mobile, Samsung Mobile 2025-09-03 6 Medium
Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.
CVE-2014-125127 1 Flight Project 1 Flight 2025-09-03 7.5 High
The mikecao/flight PHP framework in versions prior to v1.2 is vulnerable to Denial of Service (DoS) attacks due to eager loading of request bodies in the Request class constructor. The framework automatically reads the entire request body on every HTTP request, regardless of whether the application needs it. An attacker can exploit this by sending requests with large payloads, causing excessive memory consumption and potentially exhausting available server memory, leading to application crashes or service unavailability. The vulnerability was fixed in v1.2 by implementing lazy loading of request bodies.
CVE-2025-58620 2 Wordpress, Wpforms 2 Wordpress, Wpforms 2025-09-03 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org PDF for WPForms allows Stored XSS. This issue affects PDF for WPForms: from n/a through 6.2.1.
CVE-2025-58458 1 Jenkins 1 Git Client Plugin 2025-09-03 4.3 Medium
In Jenkins Git client Plugin 6.3.2 and earlier, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
CVE-2025-58459 1 Jenkins 2 Global-build-stats, Jenkins 2025-09-03 4.3 Medium
Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.
CVE-2025-0878 1 Akinsoft 1 Limondesk 2025-09-03 4.7 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft LimonDesk allows Cross-Site Scripting (XSS).This issue affects LimonDesk: from s1.02.14 before v1.02.17.