Vulnerabilities (CVE)

Total 400148 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-54334 1 Samsung 14 Exynos 1280, Exynos 1280 Firmware, Exynos 1380 and 11 more 2026-06-17 N/A 7.5 HIGH
An issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. There is a NULL Pointer Dereference of hdev in the __npu_vertex_bootup function.
CVE-2025-54333 1 Samsung 2 Exynos 1380, Exynos 1380 Firmware 2026-06-17 N/A 5.3 MEDIUM
An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Invalid Pointer Dereference of node in the get_vs4l_profiler_node function.
CVE-2025-54332 1 Samsung 2 Exynos 1380, Exynos 1380 Firmware 2026-06-17 N/A 7.5 HIGH
An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is a NULL Pointer Dereference of profiler.node in the npu_vertex_profileoff function.
CVE-2025-54331 1 Samsung 2 Exynos 1380, Exynos 1380 Firmware 2026-06-17 N/A 5.3 MEDIUM
An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function.
CVE-2025-54330 1 Samsung 2 Exynos 1380, Exynos 1380 Firmware 2026-06-17 N/A 5.3 MEDIUM
An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Out-of-bounds Read of q->bufs[] in the __is_done_for_me function.
CVE-2025-54329 1 Samsung 36 Exynos 1280, Exynos 1280 Firmware, Exynos 1330 and 33 more 2026-06-17 N/A 7.5 HIGH
An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to send a multiple-payloads message (including an SMS message) lacks bounds checking, which can lead to a heap overflow.
CVE-2025-54327 1 Samsung 6 Exynos 1280, Exynos 1280 Firmware, Exynos 1380 and 3 more 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W1000. Improper input validation in the VTS driver leads to an arbitrary write.
CVE-2025-54326 1 Samsung 4 Exynos 1280, Exynos 1280 Firmware, Exynos 2200 and 1 more 2026-06-17 N/A 7.5 HIGH
An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardware IP address in the Camera device driver can lead to a NULL pointer dereference, resulting in a denial of service.
CVE-2025-54325 1 Samsung 22 Exynos 1080, Exynos 1080 Firmware, Exynos 1280 and 19 more 2026-06-17 N/A 5.3 MEDIUM
An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1080, 1280, 2200, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000. A race condition in the VTS driver results in an out-of-bounds read, leading to an information leak.
CVE-2025-54323 1 Samsung 24 Exynos 1080, Exynos 1080 Firmware, Exynos 1280 and 21 more 2026-06-17 N/A 7.5 HIGH
An issue was discovered in the camera in Samsung Mobile Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, and 1580. Improper debug printing leads to information leakage.
CVE-2025-54322 1 Xspeeder 1 Sxzos 2026-06-17 N/A 10.0 CRITICAL
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
CVE-2025-54321 1 Ascertia 1 Signinghub 2026-06-17 N/A 9.8 CRITICAL
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.
CVE-2025-54320 1 Ascertia 1 Signinghub 2026-06-17 N/A 4.3 MEDIUM
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.
CVE-2025-54319 2026-06-17 N/A 6.3 MEDIUM
An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized access to sensitive information via system logging information (syslog verbose logging that includes credentials).
CVE-2025-54317 2026-06-17 N/A 8.4 HIGH
An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vulnerability when creating a Layout Template, which can lead to remote code execution (RCE).
CVE-2025-54316 2026-06-17 N/A 4.9 MEDIUM
An issue was discovered in Logpoint before 7.6.0. When creating reports, attackers can create custom Jinja templates that chained built-in filter functions to generate XSS payloads. These payloads can be rendered by the Logpoint Report Template engine, making it vulnerable to cross-site scripting (XSS) attacks.
CVE-2025-54315 2026-06-17 N/A 7.1 HIGH
The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.
CVE-2025-54314 2026-06-17 N/A 2.8 LOW
Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments."
CVE-2025-54313 5 Alexghr, Homarr, Microsoft and 2 more 8 Got-fetch, Homarr, Windows and 5 more 2026-06-17 N/A 7.5 HIGH
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
CVE-2025-54310 1 Qbittorrent 1 Qbittorrent 2026-06-17 N/A 4.0 MEDIUM
qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.