6
CVE-2025-7954 - Race Condition in Shopware Voucher Submission
A race condition vulnerability has been identified in Shopware's voucher system of ShopwareΒ v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
6.4
CVE-2025-7727 - Gutenverse <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text anβ¦
The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun Fact blocks in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentiβ¦
5.9
CVE-2025-7376 - Information Tampering Vulnerability in multiple processes of GENESIS64, MC Works64, and GENESIS
Windows Shortcut Following (.LNK) vulnerability in multiple processes of Mitsubishi Electric Iconics Digital Solutions GENESIS64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS version 11.00, Mitsubishi Electric GENESIS64 all versions, Mitsubishi Electric MC Works64 all versionsβ¦
3.3
CVE-2025-21024 -
Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access sensitive information.
3.3
CVE-2025-21023 -
Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information.
3.3
CVE-2025-21022 -
Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.
5.7
CVE-2025-21021 -
Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
5.7
CVE-2025-21020 -
Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
5.5
CVE-2025-21019 -
Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.
4.4
CVE-2025-21018 -
Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory.