Search Results (330452 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-50735 1 Nextchat 1 Nextchat 2025-11-05 7.5 High
Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-all route, allowing attackers to gain sensitive information via authenticated or anonymous WebDAV endpoints.
CVE-2025-36172 1 Ibm 1 Cloud Pak For Business Automation 2025-11-05 6.4 Medium
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2025-20727 1 Mediatek 90 Lr12a, Modem, Mt2735 and 87 more 2025-11-05 7.5 High
In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01672601; Issue ID: MSV-4623.
CVE-2025-57353 1 Nodejs 2 Messageformat, Nodejs 2025-11-05 5.3 Medium
The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the processing of message data, an attacker can manipulate the prototype chain of JavaScript objects by providing specially crafted input. This can result in the injection of arbitrary properties into the Object.prototype, potentially leading to denial of service conditions or unexpected application behavior. The vulnerability allows attackers to alter the prototype of base objects, impacting all subsequent object instances throughout the application's lifecycle.
CVE-2025-27041 1 Qualcomm 127 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 124 more 2025-11-05 5.5 Medium
Transient DOS while processing video packets received from video firmware.
CVE-2025-27045 1 Qualcomm 37 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 34 more 2025-11-05 6.1 Medium
Information disclosure while processing batch command execution in Video driver.
CVE-2025-27048 1 Qualcomm 37 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 34 more 2025-11-05 7.8 High
Memory corruption while processing camera platform driver IOCTL calls.
CVE-2025-27049 1 Qualcomm 63 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 60 more 2025-11-05 5.5 Medium
Transient DOS while processing IOCTL call for image encoding.
CVE-2025-27053 1 Qualcomm 639 215 Mobile Platform, 215 Mobile Platform Firmware, 315 5g Iot Modem and 636 more 2025-11-05 7.8 High
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-27054 1 Qualcomm 599 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 596 more 2025-11-05 7.8 High
Memory corruption while processing a malformed license file during reboot.
CVE-2025-47338 1 Qualcomm 37 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 34 more 2025-11-05 7.8 High
Memory corruption while processing escape commands from userspace.
CVE-2025-47340 1 Qualcomm 37 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 34 more 2025-11-05 7.8 High
Memory corruption while processing IOCTL call to get the mapping.
CVE-2025-47341 1 Qualcomm 63 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 60 more 2025-11-05 7.8 High
memory corruption while processing an image encoding completion event.
CVE-2025-47349 1 Qualcomm 37 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 34 more 2025-11-05 7.8 High
Memory corruption while processing an escape call.
CVE-2025-47351 1 Qualcomm 57 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 54 more 2025-11-05 7.8 High
Memory corruption while processing user buffers.
CVE-2025-47354 1 Qualcomm 77 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 74 more 2025-11-05 7.8 High
Memory corruption while allocating buffers in DSP service.
CVE-2025-47355 1 Qualcomm 55 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 52 more 2025-11-05 7.8 High
Memory corruption while invoking remote procedure IOCTL calls.
CVE-2025-45663 1 Netsurf-browser 1 Netsurf 2025-11-05 6.5 Medium
An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.
CVE-2024-51317 1 Netsurf-browser 1 Netsurf 2025-11-05 6.5 Medium
An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function
CVE-2025-29699 1 Netsurf-browser 1 Netsurf 2025-11-05 6.5 Medium
NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.