4.4

CVSS3.1

CVE-2025-20942 -

Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID.

πŸ“… Published: April 8, 2025, 4:39 a.m. πŸ”„ Last Modified: Feb. 5, 2026, 3:42 p.m.

6.2

CVSS3.1

CVE-2025-20941 -

Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.

πŸ“… Published: April 8, 2025, 4:39 a.m. πŸ”„ Last Modified: Feb. 5, 2026, 3:47 p.m.

4

CVSS3.1

CVE-2025-20940 -

Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 allows local attackers to access provider in SDMHS.

πŸ“… Published: April 8, 2025, 4:39 a.m. πŸ”„ Last Modified: April 8, 2025, 6:23 p.m.

5.5

CVSS3.1

CVE-2025-20938 -

Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts.

πŸ“… Published: April 8, 2025, 4:39 a.m. πŸ”„ Last Modified: Feb. 5, 2026, 2:02 p.m.

8.8

CVSS3.1

CVE-2025-20936 -

Improper access control in HDCP trustlet prior to SMR Apr-2025 Release 1 allows local attackers with shell privilege to escalate their privileges to root.

πŸ“… Published: April 8, 2025, 4:39 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

5.5

CVSS3.1

CVE-2025-20935 -

Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access files with system privilege. User interaction is required for triggering this vulnerability.

πŸ“… Published: April 8, 2025, 4:39 a.m. πŸ”„ Last Modified: April 8, 2025, 6:13 p.m.

5.5

CVSS3.1

CVE-2025-20934 -

Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.

πŸ“… Published: April 8, 2025, 4:39 a.m. πŸ”„ Last Modified: April 30, 2025, 7:04 p.m.

5.3

CVSS4.0

CVE-2025-3409 - Nothings stb stb_include_string stack-based overflow

A vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_include_string. The manipulation of the argument path_to_includes leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This product does not use versio…

πŸ“… Published: April 8, 2025, 4:31 a.m. πŸ”„ Last Modified: Oct. 16, 2025, 3:08 p.m.

9.1

CVSS3.1

CVE-2025-2004 - Simple WP Events <= 1.8.17 - Unauthenticated Arbitrary File Deletion

The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpe_delete_file AJAX action in all versions up to, and including, 1.8.17. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, …

πŸ“… Published: April 8, 2025, 4:21 a.m. πŸ”„ Last Modified: April 8, 2026, 7:23 p.m.

5.3

CVSS3.1

CVE-2024-13820 - Melhor Envio <= 2.15.11 - Unauthenticated Sensitive Information Exposure via Hardcoded Hash

The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.15.11 via the 'run' function, which uses a hardcoded hash. This makes it possible for unauthenticated attackers to extract sensitive data including environment information, …

πŸ“… Published: April 8, 2025, 4:21 a.m. πŸ”„ Last Modified: April 8, 2026, 7:20 p.m.
Total resulsts: 344064
Page 5465 of 34,407
Β« previous page Β» next page
Filters