Vulnerabilities (CVE)

Total 27161 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-33072 1 Qualcomm 490 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 487 more 2025-08-11 N/A 9.3 CRITICAL
Memory corruption in Core while processing control functions.
CVE-2023-43556 1 Qualcomm 136 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 133 more 2025-08-11 N/A 9.3 CRITICAL
Memory corruption in Hypervisor when platform information mentioned is not aligned.
CVE-2023-24855 1 Qualcomm 126 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 123 more 2025-08-11 N/A 9.8 CRITICAL
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
CVE-2025-21450 1 Qualcomm 216 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 213 more 2025-08-11 N/A 9.1 CRITICAL
Cryptographic issue occurs due to use of insecure connection method while downloading.
CVE-2023-22388 1 Qualcomm 458 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 455 more 2025-08-11 N/A 9.8 CRITICAL
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
CVE-2023-21671 1 Qualcomm 48 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 45 more 2025-08-11 N/A 9.3 CRITICAL
Memory Corruption in Core during syscall for Sectools Fuse comparison feature.
CVE-2023-33028 1 Qualcomm 352 Ar8035, Ar8035 Firmware, Ar9380 and 349 more 2025-08-11 N/A 9.8 CRITICAL
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
CVE-2023-43551 1 Qualcomm 482 205 Mobile, 205 Mobile Firmware, 215 Mobile and 479 more 2025-08-11 N/A 9.1 CRITICAL
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
CVE-2023-43552 1 Qualcomm 298 Ar8035, Ar8035 Firmware, Csr8811 and 295 more 2025-08-11 N/A 9.8 CRITICAL
Memory corruption while processing MBSSID beacon containing several subelement IE.
CVE-2023-28578 1 Qualcomm 680 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 677 more 2025-08-11 N/A 9.3 CRITICAL
Memory corruption in Core Services while executing the command for removing a single event listener.
CVE-2025-40600 1 Sonicwall 23 Nsa 2700, Nsa 3700, Nsa 4700 and 20 more 2025-08-11 N/A 9.8 CRITICAL
Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.
CVE-2025-2512 1 File Away Project 1 File Away 2025-08-11 N/A 9.8 CRITICAL
The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the upload() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVE-2025-53606 1 Apache 1 Seata 2025-08-11 N/A 9.8 CRITICAL
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recommended to upgrade to version 2.5.0, which fixes the issue.
CVE-2025-24936 1 Nokia 1 Wavesuite Noc 2025-08-11 N/A 9.0 CRITICAL
The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. An attacker with low privileged access to the application has the potential to execute commands on the operating system under the context of the webserver.
CVE-2025-24937 1 Nokia 1 Wavesuite Noc 2025-08-11 N/A 9.0 CRITICAL
File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web application and the container it is running on. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. The web application allows arbitrary files to be included in a file that was downloadable and executable by the web server.
CVE-2023-41530 1 Kishan0725 1 Hospital Management System 2025-08-11 N/A 9.8 CRITICAL
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.
CVE-2023-41528 1 Kishan0725 1 Hospital Management System 2025-08-11 N/A 9.8 CRITICAL
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.
CVE-2023-41527 1 Kishan0725 1 Hospital Management System 2025-08-11 N/A 9.8 CRITICAL
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.
CVE-2023-41526 1 Kishan0725 1 Hospital Management System 2025-08-11 N/A 9.8 CRITICAL
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.
CVE-2023-41525 1 Kishan0725 1 Hospital Management System 2025-08-11 N/A 9.8 CRITICAL
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.