Search

Search Results (327108 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-21681 1 Internationalcolorconsortium 1 Iccdev 2026-01-08 7.1 High
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Undefined Behavior runtime error. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.
CVE-2025-47334 1 Qualcomm 1 Snapdragon 2026-01-08 6.7 Medium
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
CVE-2025-47343 1 Qualcomm 1 Snapdragon 2026-01-08 7.8 High
Memory corruption while processing a video session to set video parameters.
CVE-2025-47344 1 Qualcomm 1 Snapdragon 2026-01-08 6.7 Medium
Memory corruption while handling sensor utility operations.
CVE-2025-47356 1 Qualcomm 1 Snapdragon 2026-01-08 7.8 High
Memory Corruption when multiple threads concurrently access and modify shared resources.
CVE-2025-47369 1 Qualcomm 1 Snapdragon 2026-01-08 5.5 Medium
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
CVE-2025-47380 1 Qualcomm 1 Snapdragon 2026-01-08 7.8 High
Memory corruption while preprocessing IOCTLs in sensors.
CVE-2025-47393 1 Qualcomm 1 Snapdragon 2026-01-08 7.8 High
Memory corruption when accessing resources in kernel driver.
CVE-2025-47395 1 Qualcomm 1 Snapdragon 2026-01-08 6.5 Medium
Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.
CVE-2025-14891 2 Ivole, Wordpress 2 Customer Reviews For Woocommerce, Wordpress 2026-01-08 6.4 Medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayName' parameter in all versions up to, and including, 5.93.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with customer-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. While it is possible to invoke the AJAX action without authentication, the attacker would need to know a valid form ID, which requires them to place an order. This vulnerability can be exploited by unauthenticated attackers if guest checkout is enabled. However, the form ID still needs to be obtained through placing an order.
CVE-2025-31964 1 Hcltech 1 Bigfix Insights For Vulnerability Remediation 2026-01-08 2.2 Low
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
CVE-2025-13722 1 Wordpress 1 Wordpress 2026-01-08 5.3 Medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary forms via the publicly exposed AI builder.
CVE-2025-13801 1 Wordpress 1 Wordpress 2026-01-08 7.5 High
The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.8.8 via the file parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
CVE-2025-13847 1 Wordpress 1 Wordpress 2026-01-08 6.4 Medium
The PhotoFade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'time' parameter in all versions up to, and including, 0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2025-47388 1 Qualcomm 1 Snapdragon 2026-01-08 7.8 High
Memory corruption while passing pages to DSP with an unaligned starting address.
CVE-2025-14631 1 Tp-link 1 Archer Be400 2026-01-08 N/A
A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows  an adjacent attacker to cause a denial-of-service (DoS) by triggering a device reboot. This issue affects Archer BE400: xi 1.1.0 Build 20250710 rel.14914.
CVE-2025-47330 1 Qualcomm 1 Snapdragon 2026-01-08 5.5 Medium
Transient DOS while parsing video packets received from the video firmware.
CVE-2025-47332 1 Qualcomm 1 Snapdragon 2026-01-08 6.7 Medium
Memory corruption while processing a config call from userspace.
CVE-2025-47333 1 Qualcomm 1 Snapdragon 2026-01-08 6.6 Medium
Memory corruption while handling buffer mapping operations in the cryptographic driver.
CVE-2025-13848 2 Sergiotoca, Wordpress 2 Stm Gallery, Wordpress 2026-01-08 6.4 Medium
The STM Gallery 1.9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'composicion' parameter in all versions up to, and including, 0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.