Loading HuntDB...

Recently Updated CVEs

Latest Updates

Most recently updated vulnerabilities, including new information, EPSS scores, and exploit discoveries.

CVE-2025-23235 Updated 4 days, 4 hours ago

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through out-of-bounds read.

LOW (3.3)
CVE-2025-21082 Updated 4 days, 4 hours ago

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

LOW (3.3)
CVE-2025-20063 Updated 4 days, 4 hours ago

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

LOW (3.3)
CVE-2025-5859 Updated 4 days, 4 hours ago

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /test-details.php. The manipulation of the argument assignto leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

UNKNOWN (6.3)
CVE-2025-5856 Updated 4 days, 5 hours ago

A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /registration.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

UNKNOWN (7.3)
CVE-2025-5855 Updated 4 days, 6 hours ago

A vulnerability, which was classified as critical, was found in Tenda AC6 15.03.05.16. This affects the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

UNKNOWN (8.8)
CVE-2025-5853 Updated 4 days, 7 hours ago

A vulnerability classified as critical was found in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg. The manipulation of the argument remoteIp leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

UNKNOWN (8.8)
CVE-2025-5852 Updated 4 days, 7 hours ago

A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

UNKNOWN (8.8)
CVE-2025-27563 Updated 4 days, 20 hours ago

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

LOW (3.3)
CVE-2025-27247 Updated 4 days, 20 hours ago

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

MEDIUM (5.5)
CVE-2025-38004 Updated 4 days, 21 hours ago

In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via hrtimer. The content and also the length of the sequence can be changed resp reduced at runtime where the 'currframe' counter is then set to zero. Although this appeared to be a safe operation the updates of 'currframe' can be triggered from user space and hrtimer context in bcm_can_tx(). Anderson Nascimento created a proof of concept that triggered a KASAN slab-out-of-bounds read access which can be prevented with a spin_lock_bh. At the rework of bcm_can_tx() the 'count' variable has been moved into the protected section as this variable can be modified from both contexts too.

UNKNOWN (0.0)
CVE-2025-38003 Updated 4 days, 21 hours ago

In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procfs content When the procfs content is generated for a bcm_op which is in the process to be removed the procfs output might show unreliable data (UAF). As the removal of bcm_op's is already implemented with rcu handling this patch adds the missing rcu_read_lock() and makes sure the list entries are properly removed under rcu protection.

UNKNOWN (0.0)
CVE-2025-30084 Updated 5 days, 3 hours ago

A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code into text fields or other input points, which is subsequently executed in the browser of any user who clicks on the crafted text in the dashboard.

UNKNOWN (0.0)
CVE-2025-27754 Updated 5 days, 3 hours ago

A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows authenticated users to inject malicious JavaScript into the plugin's resource. The injected payload is stored by the application and later executed when other users view the affected content.

MEDIUM (6.5)
CVE-2025-27753 Updated 5 days, 3 hours ago

A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to the use of unescaped user-supplied parameters in SQL queries within the dashboard component. This allows an authenticated attacker to inject malicious SQL code through unsanitized input fields, which are used directly in SQL queries. Exploiting this flaw can lead to unauthorized database access, data leakage, or modification of records.

UNKNOWN (0.0)
CVE-2025-27445 Updated 5 days, 3 hours ago

A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allows authenticated users to read arbitrary files outside the Joomla root directory. The flaw is caused by insufficient sanitization of user-supplied input in file path parameters, allowing attackers to exploit directory traversal sequences (e.g., ../) to access sensitive files

UNKNOWN (0.0)
CVE-2025-5242 Updated 5 days, 9 hours ago

No description available

UNKNOWN (0.0)
CVE-2025-5223 Updated 5 days, 9 hours ago

No description available

UNKNOWN (0.0)
CVE-2025-5097 Updated 5 days, 9 hours ago

No description available

UNKNOWN (0.0)
CVE-2025-5026 Updated 5 days, 9 hours ago

No description available

UNKNOWN (0.0)