Total
27161 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-33072 | 1 Qualcomm | 490 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 487 more | 2025-08-11 | N/A | 9.3 CRITICAL |
Memory corruption in Core while processing control functions. | |||||
CVE-2023-43556 | 1 Qualcomm | 136 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 133 more | 2025-08-11 | N/A | 9.3 CRITICAL |
Memory corruption in Hypervisor when platform information mentioned is not aligned. | |||||
CVE-2023-24855 | 1 Qualcomm | 126 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 123 more | 2025-08-11 | N/A | 9.8 CRITICAL |
Memory corruption in Modem while processing security related configuration before AS Security Exchange. | |||||
CVE-2025-21450 | 1 Qualcomm | 216 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 213 more | 2025-08-11 | N/A | 9.1 CRITICAL |
Cryptographic issue occurs due to use of insecure connection method while downloading. | |||||
CVE-2023-22388 | 1 Qualcomm | 458 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 455 more | 2025-08-11 | N/A | 9.8 CRITICAL |
Memory Corruption in Multi-mode Call Processor while processing bit mask API. | |||||
CVE-2023-21671 | 1 Qualcomm | 48 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 45 more | 2025-08-11 | N/A | 9.3 CRITICAL |
Memory Corruption in Core during syscall for Sectools Fuse comparison feature. | |||||
CVE-2023-33028 | 1 Qualcomm | 352 Ar8035, Ar8035 Firmware, Ar9380 and 349 more | 2025-08-11 | N/A | 9.8 CRITICAL |
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache. | |||||
CVE-2023-43551 | 1 Qualcomm | 482 205 Mobile, 205 Mobile Firmware, 215 Mobile and 479 more | 2025-08-11 | N/A | 9.1 CRITICAL |
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. | |||||
CVE-2023-43552 | 1 Qualcomm | 298 Ar8035, Ar8035 Firmware, Csr8811 and 295 more | 2025-08-11 | N/A | 9.8 CRITICAL |
Memory corruption while processing MBSSID beacon containing several subelement IE. | |||||
CVE-2023-28578 | 1 Qualcomm | 680 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 677 more | 2025-08-11 | N/A | 9.3 CRITICAL |
Memory corruption in Core Services while executing the command for removing a single event listener. | |||||
CVE-2025-40600 | 1 Sonicwall | 23 Nsa 2700, Nsa 3700, Nsa 4700 and 20 more | 2025-08-11 | N/A | 9.8 CRITICAL |
Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption. | |||||
CVE-2025-2512 | 1 File Away Project | 1 File Away | 2025-08-11 | N/A | 9.8 CRITICAL |
The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the upload() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. | |||||
CVE-2025-53606 | 1 Apache | 1 Seata | 2025-08-11 | N/A | 9.8 CRITICAL |
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recommended to upgrade to version 2.5.0, which fixes the issue. | |||||
CVE-2025-24936 | 1 Nokia | 1 Wavesuite Noc | 2025-08-11 | N/A | 9.0 CRITICAL |
The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. An attacker with low privileged access to the application has the potential to execute commands on the operating system under the context of the webserver. | |||||
CVE-2025-24937 | 1 Nokia | 1 Wavesuite Noc | 2025-08-11 | N/A | 9.0 CRITICAL |
File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web application and the container it is running on. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. The web application allows arbitrary files to be included in a file that was downloadable and executable by the web server. | |||||
CVE-2023-41530 | 1 Kishan0725 | 1 Hospital Management System | 2025-08-11 | N/A | 9.8 CRITICAL |
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php. | |||||
CVE-2023-41528 | 1 Kishan0725 | 1 Hospital Management System | 2025-08-11 | N/A | 9.8 CRITICAL |
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters. | |||||
CVE-2023-41527 | 1 Kishan0725 | 1 Hospital Management System | 2025-08-11 | N/A | 9.8 CRITICAL |
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php. | |||||
CVE-2023-41526 | 1 Kishan0725 | 1 Hospital Management System | 2025-08-11 | N/A | 9.8 CRITICAL |
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters. | |||||
CVE-2023-41525 | 1 Kishan0725 | 1 Hospital Management System | 2025-08-11 | N/A | 9.8 CRITICAL |
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php. |