A vulnerability marked as problematic has been reported in Azuriom CMS up to 1.2.6. Affected by this issue is some unknown functionality of the component Admin Dashboard. Performing manipulation results in improper neutralization of special elements used in a template engine.
This vulnerability was named CVE-2025-65271. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability was found in Google Android 16-qpr2 and classified as problematic. The impacted element is an unknown function. Such manipulation leads to resource consumption.
This vulnerability is traded as CVE-2025-48569. An attack has to be approached locally. There is no exploit available.
It is best practice to apply a patch to resolve this issue.
A vulnerability was found in Google Android 16-qpr2. It has been classified as problematic. This affects the function isValidMediaUri of the file SettingsProvider.java. Performing manipulation results in information disclosure.
This vulnerability is known as CVE-2025-48608. Attacking locally is a requirement. No exploit is available.
It is recommended to apply a patch to fix this issue.
A vulnerability described as problematic has been identified in Google Android 16-qpr2. The impacted element is an unknown function of the file UsbDataAdvancedProtectionHook.java. The manipulation results in race condition.
This vulnerability is identified as CVE-2025-48625. The attack is only possible with local access. There is not any exploit available.
It is advisable to implement a patch to correct this issue.
A vulnerability labeled as problematic has been found in Barix Instreamer up to 04.06. This vulnerability affects unknown code of the component Status Page. Executing manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2025-65231. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as problematic has been found in Barix Instreamer 04.05/04.06. The affected element is an unknown function of the component Web UI Configuration Handler. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2025-65230. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.17.5. Affected is the function z_erofs_submit_queue. Executing manipulation of the argument compressed_bvecs[] can lead to out-of-bounds read.
This vulnerability is registered as CVE-2025-40241. The physical device can be targeted for the attack. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.17.5. This affects the function devm_kzalloc of the component hwmon. Such manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2025-40224. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is advised.
A vulnerability categorized as problematic has been discovered in sigstore timestamp-authority up to 2.0.2. Affected by this issue is some unknown functionality. Such manipulation leads to asymmetric resource consumption.
This vulnerability is uniquely identified as CVE-2025-66564. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability labeled as problematic has been found in Linux Kernel up to 6.17.7. This vulnerability affects the function wcd934x_codec_parse_data. The manipulation results in denial of service.
This vulnerability is reported as CVE-2025-40317. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.
A vulnerability was found in Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7 and classified as critical. Impacted is the function do_unregister_framebuffer of the component fbcon. Executing manipulation of the argument fb_display[] can lead to use after free.
This vulnerability is tracked as CVE-2025-40323. The attack is only possible within the local network. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability was found in Ilevia EVE X1 Server up to 4.6.5.0.eden. It has been classified as critical. Impacted is an unknown function of the file /ajax/php/leaf_search.php. This manipulation of the argument line causes command injection.
This vulnerability is handled as CVE-2025-14276. The attack can be initiated remotely. Additionally, an exploit exists.
Upgrading the affected component is recommended.
The vendor confirms the issue and recommends: "We already know that issue and on most devices are already solved, also it’s not needed to open the port to outside world so we advised our customer to close it".
A vulnerability, which was classified as problematic, was found in Google Android 13/14/15/16. The affected element is the function sendCommand of the file MediaSessionRecord.java of the component Foreground Service. Such manipulation leads to execution with unnecessary privileges.
This vulnerability is listed as CVE-2025-48573. The attack must be carried out locally. There is no available exploit.
A vulnerability was found in Ruijie AP_RGOS 11.1.x. It has been rated as critical. The impacted element is an unknown function of the file web_action.do of the component Parameter Handler. Performing manipulation of the argument command results in command injection.
This vulnerability was named CVE-2025-65363. The attack may be initiated remotely. There is no available exploit.
A vulnerability identified as critical has been detected in usememos memos 0.25.2. This impacts an unknown function of the component Identity Provider Service. The manipulation leads to improper access controls.
This vulnerability is referenced as CVE-2025-65797. Remote exploitation of the attack is possible. No exploit is available.
Applying a patch is the recommended action to fix this issue.
A vulnerability categorized as critical has been discovered in IBM Controller and Cognos Controller up to 11.1.1 FP6. Affected by this issue is some unknown functionality. Such manipulation leads to improper validation of specified quantity in input.
This vulnerability is traded as CVE-2025-36015. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.