CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27248
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

May 6, 2025
CVE-2025-27241
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

May 6, 2025
CVE-2025-27132
3.8 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only …

May 6, 2025
CVE-2025-25218
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

May 6, 2025
CVE-2025-25052
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through buffer overflow.

May 6, 2025
CVE-2025-22886
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

May 6, 2025
CVE-2025-21475
7.8 HIGH

Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.

May 6, 2025
CVE-2025-21470
7.8 HIGH

Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.

May 6, 2025
CVE-2025-21469
7.8 HIGH

Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.

May 6, 2025
CVE-2025-21468
7.8 HIGH

Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at …

May 6, 2025
CVE-2025-21467
7.8 HIGH

Memory corruption while reading the FW response from the shared queue.

May 6, 2025
CVE-2025-21462
7.8 HIGH

Memory corruption while processing an IOCTL request, when buffer significantly exceeds the command argument limit.

May 6, 2025
CVE-2025-21460
7.8 HIGH

Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed continuously.

May 6, 2025
CVE-2025-21459
7.5 HIGH

Transient DOS while parsing per STA profile in ML IE.

May 6, 2025
CVE-2025-21453
7.8 HIGH

Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.

May 6, 2025
CVE-2024-49847
7.5 HIGH

Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.

May 6, 2025
CVE-2024-49846
8.2 HIGH

Memory corruption while decoding of OTA messages from T3448 IE.

May 6, 2025
CVE-2024-49845
7.8 HIGH

Memory corruption during the FRS UDS generation process.

May 6, 2025
CVE-2024-49844
7.8 HIGH

Memory corruption while triggering commands in the PlayReady Trusted application.

May 6, 2025
CVE-2024-49842
7.8 HIGH

Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.

May 6, 2025
CVE-2024-49841
7.8 HIGH

Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.

May 6, 2025
CVE-2024-49835
7.8 HIGH

Memory corruption while reading secure file.

May 6, 2025
CVE-2024-49830
6.6 MEDIUM

Memory corruption while processing an IOCTL call to set mixer controls.

May 6, 2025
CVE-2024-49829
6.7 MEDIUM

Memory corruption can occur during context user dumps due to inadequate checks on buffer length.

May 6, 2025
CVE-2024-45583
6.6 MEDIUM

Memory corruption while handling multiple IOCTL calls from userspace to operate DMA operations.

May 6, 2025
CVE-2024-45581
6.6 MEDIUM

Memory corruption while sound model registration for voice activation with audio kernel driver.

May 6, 2025
CVE-2024-45579
7.8 HIGH

Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement …

May 6, 2025
CVE-2024-45578
7.8 HIGH

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

May 6, 2025
CVE-2024-45577
7.8 HIGH

Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.

May 6, 2025
CVE-2024-45576
7.8 HIGH

Memory corruption while prociesing command buffer buffer in OPE module.

May 6, 2025
CVE-2024-45575
7.8 HIGH

Memory corruption Camera kernel when large number of devices are attached through userspace.

May 6, 2025
CVE-2024-45574
7.8 HIGH

Memory corruption during array access in Camera kernel due to invalid index from invalid command data.

May 6, 2025
CVE-2024-45570
6.6 MEDIUM

Memory corruption may occur during IO configuration processing when the IO port count is invalid.

May 6, 2025
CVE-2024-45568
6.7 MEDIUM

Memory corruption due to improper bounds check while command handling in camera-kernel driver.

May 6, 2025
CVE-2024-45567
7.8 HIGH

Memory corruption while encoding JPEG format.

May 6, 2025
CVE-2024-45566
7.8 HIGH

Memory corruption during concurrent buffer access due to modification of the reference count.

May 6, 2025
CVE-2024-45565
7.8 HIGH

Memory corruption when blob structure is modified by user-space after kernel verification.

May 6, 2025
CVE-2024-45564
7.8 HIGH

Memory corruption during concurrent access to server info object due to incorrect reference count update.

May 6, 2025
CVE-2024-45563
6.6 MEDIUM

Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session.

May 6, 2025
CVE-2024-45562
6.6 MEDIUM

Memory corruption during concurrent access to server info object due to unprotected critical field.

May 6, 2025
CVE-2024-45554
7.8 HIGH

Memory corruption during concurrent SSR execution due to race condition on the global maps list.

May 6, 2025
CVE-2025-4340
6.3 MEDIUM

A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of the file /htdocs/soap.cgi. …

May 6, 2025
CVE-2025-4333
6.3 MEDIUM

A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critical. This affects the function uploadFile of the …

May 6, 2025
CVE-2025-4332
7.3 HIGH

A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the …

May 6, 2025
CVE-2025-4331
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Online Student Clearance System 1.0. This vulnerability affects unknown code of the file /Admin/login.php. The manipulation …

May 6, 2025
CVE-2025-46593
5.1 MEDIUM

Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.

May 6, 2025
CVE-2025-46592
4.4 MEDIUM

Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availability.

May 6, 2025
CVE-2025-46591
6.2 MEDIUM

Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 6, 2025
CVE-2025-46590
6.3 MEDIUM

Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypass authentication and enable access to some network search …

May 6, 2025
CVE-2025-46589
4.4 MEDIUM

Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

May 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.