CVE Notify
19.6K subscribers
4 photos
340K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2025-47337
Memory corruption while accessing a synchronization object during concurrent operations.

πŸŽ–@cveNotify
🚨 CVE-2025-47343
Memory corruption while processing a video session to set video parameters.

πŸŽ–@cveNotify
🚨 CVE-2025-47344
Memory corruption while handling sensor utility operations.

πŸŽ–@cveNotify
🚨 CVE-2025-47345
Cryptographic issue may occur while encrypting license data.

πŸŽ–@cveNotify
🚨 CVE-2025-47346
Memory corruption while processing a secure logging command in the trusted application.

πŸŽ–@cveNotify
🚨 CVE-2025-47356
Memory Corruption when multiple threads concurrently access and modify shared resources.

πŸŽ–@cveNotify
🚨 CVE-2025-47369
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.

πŸŽ–@cveNotify
🚨 CVE-2025-47380
Memory corruption while preprocessing IOCTLs in sensors.

πŸŽ–@cveNotify
🚨 CVE-2025-47388
Memory corruption while passing pages to DSP with an unaligned starting address.

πŸŽ–@cveNotify
🚨 CVE-2025-47393
Memory corruption when accessing resources in kernel driver.

πŸŽ–@cveNotify
🚨 CVE-2025-47394
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.

πŸŽ–@cveNotify
🚨 CVE-2025-47395
Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.

πŸŽ–@cveNotify
🚨 CVE-2025-47396
Memory corruption occurs when a secure application is launched on a device with insufficient memory.

πŸŽ–@cveNotify
🚨 CVE-2025-68637
The Uniffle HTTP client is configured to trust all SSL certificates and

disables hostname verification by default. This insecure configuration
exposes all REST API communication between the Uniffle CLI/client and the
Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks.


This issue affects all versions from before 0.10.0.

Users are recommended to upgrade to version 0.10.0, which fixes the issue.

πŸŽ–@cveNotify
🚨 CVE-2025-69080
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JanStudio Gecko gecko allows PHP Local File Inclusion.This issue affects Gecko: from n/a through <= 1.9.8.

πŸŽ–@cveNotify
🚨 CVE-2025-69081
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hope charity-is-hope allows PHP Local File Inclusion.This issue affects Hope: from n/a through <= 3.0.0.

πŸŽ–@cveNotify
🚨 CVE-2025-69082
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo allows Reflected XSS.This issue affects Arlo: from n/a through <= 6.0.3.

πŸŽ–@cveNotify
🚨 CVE-2025-69333
Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.8.1.1.

πŸŽ–@cveNotify
🚨 CVE-2025-69344
Missing Authorization vulnerability in themehunk Oneline Lite oneline-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Oneline Lite: from n/a through <= 6.6.

πŸŽ–@cveNotify
🚨 CVE-2025-9611
Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victim’s web browser and send unauthorized requests to a locally running MCP server, resulting in unintended invocation of MCP tool endpoints.

πŸŽ–@cveNotify
🚨 CVE-2025-32303
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0.

πŸŽ–@cveNotify