5.1

CVSS4.0

CVE-2025-40640 - Multiple vulnerabilities in Energy CRM by Status Tracker

Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request to “/crm/create_invoice_submit.php”, using the “customerName_0” parameter. This vulnerability could allow a …

📅 Published: Oct. 10, 2025, 8:19 a.m. 🔄 Last Modified: Oct. 10, 2025, 1:58 p.m.

7.1

CVSS3.1

CVE-2025-21050 -

Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.

📅 Published: Oct. 10, 2025, 6:41 a.m. 🔄 Last Modified: Oct. 10, 2025, 6:41 a.m.

4

CVSS3.1

CVE-2025-21070 -

Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.

📅 Published: Oct. 10, 2025, 6:33 a.m. 🔄 Last Modified: Oct. 10, 2025, 6:33 a.m.

4

CVSS3.1

CVE-2025-21069 -

Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

📅 Published: Oct. 10, 2025, 6:33 a.m. 🔄 Last Modified: Oct. 10, 2025, 6:33 a.m.

4

CVSS3.1

CVE-2025-21068 -

Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

📅 Published: Oct. 10, 2025, 6:33 a.m. 🔄 Last Modified: Oct. 10, 2025, 6:33 a.m.

4

CVSS3.1

CVE-2025-21067 -

Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

📅 Published: Oct. 10, 2025, 6:33 a.m. 🔄 Last Modified: Oct. 10, 2025, 6:33 a.m.

4

CVSS3.1

CVE-2025-21066 -

Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

📅 Published: Oct. 10, 2025, 6:33 a.m. 🔄 Last Modified: Oct. 10, 2025, 6:33 a.m.

6.6

CVSS3.1

CVE-2025-21065 -

Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands on their own devices.

📅 Published: Oct. 10, 2025, 6:33 a.m. 🔄 Last Modified: Oct. 10, 2025, 6:33 a.m.

8.8

CVSS3.1

CVE-2025-21064 -

Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

📅 Published: Oct. 10, 2025, 6:33 a.m. 🔄 Last Modified: Oct. 10, 2025, 6:33 a.m.

4.6

CVSS3.1

CVE-2025-21063 -

Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording files on the lock screen.

📅 Published: Oct. 10, 2025, 6:33 a.m. 🔄 Last Modified: Oct. 10, 2025, 6:33 a.m.
Total resulsts: 313728
Page 15 of 31,373
« previous page » next page
Filters