7.8
CVE-2025-27048 - Untrusted Pointer Dereference in Camera
Memory corruption while processing camera platform driver IOCTL calls.
6.1
CVE-2025-27045 - Buffer Over-read in Video
Information disclosure while processing batch command execution in Video driver.
5.5
CVE-2025-27041 - Buffer Over-read in Video
Transient DOS while processing video packets received from video firmware.
6.5
CVE-2025-27040 - Improper Input Validation in TZ Firmware
Information disclosure may occur while processing the hypervisor log.
6.6
CVE-2025-27039 - Detection of Error Condition Without Action in Computer Vision
Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request.
6.9
CVE-2025-11529 - ChurchCRM API Endpoint AuthMiddleware.php AuthMiddleware missing authentication
A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/AuthMiddleware.php of the component API Endpoint. The manipulation results in missing authentication. The attack can be executed remotely. The exploit haβ¦
8.7
CVE-2025-11528 - Tenda AC7 saveAutoQos stack-based overflow
A vulnerability was identified in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/saveAutoQos. The manipulation of the argument enable leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
8.7
CVE-2025-11527 - Tenda AC7 fast_setting_pppoe_set stack-based overflow
A vulnerability was determined in Tenda AC7 15.03.06.44. The impacted element is an unknown function of the file /goform/fast_setting_pppoe_set. Executing a manipulation of the argument Password can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publiβ¦
8.7
CVE-2025-11526 - Tenda AC7 WifiMacFilterSet stack-based overflow
A vulnerability was found in Tenda AC7 15.03.06.44. The affected element is an unknown function of the file /goform/WifiMacFilterSet. Performing a manipulation of the argument wifi_chkHz results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made public aβ¦
7.2
CVE-2025-10496 - Cookie Notice & Consent <= 1.6.5 - Unauthenticated Stored Cross-Site Scripting
The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uuid parameter in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sβ¦