Search

Search Results (326467 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-14631 2026-01-07 N/A
A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows  an adjacent attacker to cause a denial-of-service (DoS) by triggering a device reboot. This issue affects Archer BE400: xi 1.1.0 Build 20250710 rel.14914.
CVE-2026-0649 2026-01-07 4.7 Medium
A security vulnerability has been detected in invoiceninja up to 5.12.38. The affected element is the function copy of the file /app/Jobs/Util/Import.php of the component Migration Import. The manipulation of the argument company_logo leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-14020 2026-01-07 5 Medium
A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unknown function of the file lib/input.js of the component Formatter Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is said to be difficult. Upgrading to version 3.5.6 will fix this issue. This patch is called 04f9feb24bfca23567706392f9ad2c53bbe4134e. You should upgrade the affected component. A successful exploitation can "only occur if the parent NodeJS application has the same security issue".
CVE-2026-0628 2026-01-06 N/A
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)
CVE-2026-0643 2026-01-06 7.3 High
A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used.
CVE-2025-47396 2026-01-06 7.8 High
Memory corruption occurs when a secure application is launched on a device with insufficient memory.
CVE-2025-47395 2026-01-06 6.5 Medium
Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.
CVE-2025-47394 2026-01-06 7.8 High
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
CVE-2025-47393 2026-01-06 7.8 High
Memory corruption when accessing resources in kernel driver.
CVE-2025-47388 2026-01-06 7.8 High
Memory corruption while passing pages to DSP with an unaligned starting address.
CVE-2025-47380 2026-01-06 7.8 High
Memory corruption while preprocessing IOCTLs in sensors.
CVE-2025-47369 2026-01-06 5.5 Medium
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
CVE-2025-47356 2026-01-06 7.8 High
Memory Corruption when multiple threads concurrently access and modify shared resources.
CVE-2025-47348 2026-01-06 7.8 High
Memory corruption while processing identity credential operations in the trusted application.
CVE-2025-47346 2026-01-06 7.8 High
Memory corruption while processing a secure logging command in the trusted application.
CVE-2025-47345 2026-01-06 8.4 High
Cryptographic issue may occur while encrypting license data.
CVE-2025-47344 2026-01-06 6.7 Medium
Memory corruption while handling sensor utility operations.
CVE-2025-47343 2026-01-06 7.8 High
Memory corruption while processing a video session to set video parameters.
CVE-2025-47339 2026-01-06 7.8 High
Memory corruption while deinitializing a HDCP session.
CVE-2025-47337 2026-01-06 6.7 Medium
Memory corruption while accessing a synchronization object during concurrent operations.