Total
400148 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-54334 | 1 Samsung | 14 Exynos 1280, Exynos 1280 Firmware, Exynos 1380 and 11 more | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. There is a NULL Pointer Dereference of hdev in the __npu_vertex_bootup function. | |||||
| CVE-2025-54333 | 1 Samsung | 2 Exynos 1380, Exynos 1380 Firmware | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Invalid Pointer Dereference of node in the get_vs4l_profiler_node function. | |||||
| CVE-2025-54332 | 1 Samsung | 2 Exynos 1380, Exynos 1380 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is a NULL Pointer Dereference of profiler.node in the npu_vertex_profileoff function. | |||||
| CVE-2025-54331 | 1 Samsung | 2 Exynos 1380, Exynos 1380 Firmware | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function. | |||||
| CVE-2025-54330 | 1 Samsung | 2 Exynos 1380, Exynos 1380 Firmware | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Out-of-bounds Read of q->bufs[] in the __is_done_for_me function. | |||||
| CVE-2025-54329 | 1 Samsung | 36 Exynos 1280, Exynos 1280 Firmware, Exynos 1330 and 33 more | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to send a multiple-payloads message (including an SMS message) lacks bounds checking, which can lead to a heap overflow. | |||||
| CVE-2025-54327 | 1 Samsung | 6 Exynos 1280, Exynos 1280 Firmware, Exynos 1380 and 3 more | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W1000. Improper input validation in the VTS driver leads to an arbitrary write. | |||||
| CVE-2025-54326 | 1 Samsung | 4 Exynos 1280, Exynos 1280 Firmware, Exynos 2200 and 1 more | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardware IP address in the Camera device driver can lead to a NULL pointer dereference, resulting in a denial of service. | |||||
| CVE-2025-54325 | 1 Samsung | 22 Exynos 1080, Exynos 1080 Firmware, Exynos 1280 and 19 more | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1080, 1280, 2200, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000. A race condition in the VTS driver results in an out-of-bounds read, leading to an information leak. | |||||
| CVE-2025-54323 | 1 Samsung | 24 Exynos 1080, Exynos 1080 Firmware, Exynos 1280 and 21 more | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in the camera in Samsung Mobile Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, and 1580. Improper debug printing leads to information leakage. | |||||
| CVE-2025-54322 | 1 Xspeeder | 1 Sxzos | 2026-06-17 | N/A | 10.0 CRITICAL |
| Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used. | |||||
| CVE-2025-54321 | 1 Ascertia | 1 Signinghub | 2026-06-17 | N/A | 9.8 CRITICAL |
| In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests. | |||||
| CVE-2025-54320 | 1 Ascertia | 1 Signinghub | 2026-06-17 | N/A | 4.3 MEDIUM |
| In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests. | |||||
| CVE-2025-54319 | 2026-06-17 | N/A | 6.3 MEDIUM | ||
| An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized access to sensitive information via system logging information (syslog verbose logging that includes credentials). | |||||
| CVE-2025-54317 | 2026-06-17 | N/A | 8.4 HIGH | ||
| An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vulnerability when creating a Layout Template, which can lead to remote code execution (RCE). | |||||
| CVE-2025-54316 | 2026-06-17 | N/A | 4.9 MEDIUM | ||
| An issue was discovered in Logpoint before 7.6.0. When creating reports, attackers can create custom Jinja templates that chained built-in filter functions to generate XSS payloads. These payloads can be rendered by the Logpoint Report Template engine, making it vulnerable to cross-site scripting (XSS) attacks. | |||||
| CVE-2025-54315 | 2026-06-17 | N/A | 7.1 HIGH | ||
| The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness. | |||||
| CVE-2025-54314 | 2026-06-17 | N/A | 2.8 LOW | ||
| Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments." | |||||
| CVE-2025-54313 | 5 Alexghr, Homarr, Microsoft and 2 more | 8 Got-fetch, Homarr, Windows and 5 more | 2026-06-17 | N/A | 7.5 HIGH |
| eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows. | |||||
| CVE-2025-54310 | 1 Qbittorrent | 1 Qbittorrent | 2026-06-17 | N/A | 4.0 MEDIUM |
| qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp. | |||||
