CVE Monitor
3.46K subscribers
33.6K links
Download Telegram
{
"Source": "CVE FEED",
"Title": "CVE-2025-11530 - code-projects Online Complaint Site state.php sql injection",
"Content": "CVE ID : CVE-2025-11530
Published : Oct. 9, 2025, 3:32 a.m. | 23 minutes ago
Description : A weakness has been identified in code-projects Online Complaint Site 1.0. Affected is an unknown function of the file /cms/admin/state.php. This manipulation of the argument state causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-6038 - Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.4.0 - authenticated (subscriber+) privilege escalation",
"Content": "CVE ID : CVE-2025-6038
Published : Oct. 9, 2025, 3:23 a.m. | 31 minutes ago
Description : The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation via password update in all versions up to, and including, 1.4.0. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary user's passwords, including those of administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47355 - Out-of-bounds Write in DSP Service",
"Content": "CVE ID : CVE-2025-47355
Published : Oct. 9, 2025, 3:18 a.m. | 36 minutes ago
Description : Memory corruption while invoking remote procedure IOCTL calls.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47354 - Use After Free in DSP Service",
"Content": "CVE ID : CVE-2025-47354
Published : Oct. 9, 2025, 3:18 a.m. | 36 minutes ago
Description : Memory corruption while allocating buffers in DSP service.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47351 - Integer Overflow or Wraparound in DSP Service",
"Content": "CVE ID : CVE-2025-47351
Published : Oct. 9, 2025, 3:18 a.m. | 36 minutes ago
Description : Memory corruption while processing user buffers.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47349 - Use of Out-of-range Pointer Offset in DSP Service",
"Content": "CVE ID : CVE-2025-47349
Published : Oct. 9, 2025, 3:18 a.m. | 36 minutes ago
Description : Memory corruption while processing an escape call.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47347 - Stack-based Buffer Overflow in Automotive Software platform based on QNX",
"Content": "CVE ID : CVE-2025-47347
Published : Oct. 9, 2025, 3:18 a.m. | 36 minutes ago
Description : Memory corruption while processing control commands in the virtual memory management interface.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47342 - Use After Free in BT Controller",
"Content": "CVE ID : CVE-2025-47342
Published : Oct. 9, 2025, 3:18 a.m. | 36 minutes ago
Description : Transient DOS may occur when multi-profile concurrency arises with QHS enabled.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47341 - Buffer Copy Without Checking Size of Input in Camera",
"Content": "CVE ID : CVE-2025-47341
Published : Oct. 9, 2025, 3:18 a.m. | 36 minutes ago
Description : memory corruption while processing an image encoding completion event.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47340 - Out-of-bounds Write in DSP Service",
"Content": "CVE ID : CVE-2025-47340
Published : Oct. 9, 2025, 3:18 a.m. | 36 minutes ago
Description : Memory corruption while processing IOCTL call to get the mapping.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47338 - Untrusted Pointer Dereference in DSP Service",
"Content": "CVE ID : CVE-2025-47338
Published : Oct. 9, 2025, 3:18 a.m. | 36 minutes ago
Description : Memory corruption while processing escape commands from userspace.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-27060 - Untrusted Pointer Dereference in TZ Firmware",
"Content": "CVE ID : CVE-2025-27060
Published : Oct. 9, 2025, 3:18 a.m. | 37 minutes ago
Description : Memory corruption while performing SCM call with malformed inputs.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-27059 - Use of Out-of-range Pointer Offset in TZ Firmware",
"Content": "CVE ID : CVE-2025-27059
Published : Oct. 9, 2025, 3:18 a.m. | 37 minutes ago
Description : Memory corruption while performing SCM call.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-27054 - Out-of-bounds Write in Display",
"Content": "CVE ID : CVE-2025-27054
Published : Oct. 9, 2025, 3:18 a.m. | 37 minutes ago
Description : Memory corruption while processing a malformed license file during reboot.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-27053 - Incorrect Calculation of Buffer Size in HLOS",
"Content": "CVE ID : CVE-2025-27053
Published : Oct. 9, 2025, 3:18 a.m. | 37 minutes ago
Description : Memory corruption during PlayReady APP usecase while processing TA commands.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-27049 - Buffer Over-read in Camera",
"Content": "CVE ID : CVE-2025-27049
Published : Oct. 9, 2025, 3:17 a.m. | 37 minutes ago
Description : Transient DOS while processing IOCTL call for image encoding.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-27048 - Untrusted Pointer Dereference in Camera",
"Content": "CVE ID : CVE-2025-27048
Published : Oct. 9, 2025, 3:17 a.m. | 37 minutes ago
Description : Memory corruption while processing camera platform driver IOCTL calls.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-27045 - Buffer Over-read in Video",
"Content": "CVE ID : CVE-2025-27045
Published : Oct. 9, 2025, 3:17 a.m. | 37 minutes ago
Description : Information disclosure while processing batch command execution in Video driver.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-27041 - Buffer Over-read in Video",
"Content": "CVE ID : CVE-2025-27041
Published : Oct. 9, 2025, 3:17 a.m. | 37 minutes ago
Description : Transient DOS while processing video packets received from video firmware.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-27040 - Improper Input Validation in TZ Firmware",
"Content": "CVE ID : CVE-2025-27040
Published : Oct. 9, 2025, 3:17 a.m. | 37 minutes ago
Description : Information disclosure may occur while processing the hypervisor log.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-7634 - WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - unauthenticated local file inclusion",
"Content": "CVE ID : CVE-2025-7634
Published : Oct. 9, 2025, 5:23 a.m. | 34 minutes ago
Description : The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the mode parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "09 Oct 2025",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹