6.2
CVE-2025-21433 - NULL Pointer Dereference in SPS-HLOS
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
7.8
CVE-2025-21432 - Double Free in SPS-HLOS
Memory corruption while retrieving the CBOR data from TA.
8.2
CVE-2025-21427 - Buffer Over-read in Data HLOS - LNX
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
6.6
CVE-2025-21426 - Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Camera_Linux
Memory corruption while processing camera TPG write request.
7.1
CVE-2025-21422 - Cryptographic Issues in Automotive
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
5.3
CVE-2024-53009 - Improper Validation of Array Index in Automotive Autonomy
Memory corruption while operating the mailbox in Automotive.
6.9
CVE-2025-7178 - code-projects Food Distributor Site login.php sql injection
A vulnerability classified as critical has been found in code-projects Food Distributor Site 1.0. This affects an unknown part of the file /admin/login.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosβ¦
5.1
CVE-2025-7177 - PHPGurukul Car Washing Management System editcar-washpoint.php sql injection
A vulnerability was found in PHPGurukul Car Washing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/editcar-washpoint.php. The manipulation of the argument wpid leads to sql injection. The attack may be launched remotely.β¦
5.6
CVE-2024-36350 - kernel: information leak via transient execution vulnerability in some AMD processors
A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.
5.1
CVE-2025-40721 - Reflected Cross-site Scripting (XSS) vulnerability in Quiter Gateway
Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL trhough the id_factura parameter in /<Client>FacturaE/listado_facturas_fichaβ¦