Total
398785 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-47419 | 2026-06-17 | N/A | N/A | ||
| Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |||||
| CVE-2025-47418 | 2026-06-17 | N/A | N/A | ||
| Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. There is no visible indication when the system is recording and recording can be enabled remotely via a network API. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |||||
| CVE-2025-47417 | 2026-06-17 | N/A | N/A | ||
| Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. When Enable Debug Images in Crestron Automate VX is active, snapshots of the captured video or portions thereof are stored locally on the system, and there is no visible indication that this is being done. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |||||
| CVE-2025-47416 | 2026-06-17 | N/A | N/A | ||
| A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to unauthorized execution of an attacker-defined file that gets prioritized by the ConsoleFindCommandMatchList. A third-party researcher discovered that the ConsoleFindCommandMatchList enumerates the /dev/shm/symproc/c directory in alphabetical order to identify console commands. Permission levels are inferred from the integer values present in each command's file name. Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061 Fixed Firmware: no fixed released (product is discontinued and end of life) For x70 The Affected Firmware:- 3.000.0110.001 and versions below The Fixed Firmware:- 3.001.0031.001 | |||||
| CVE-2025-47415 | 2026-06-17 | N/A | N/A | ||
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001. Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061 - (no fix released, product discontinued) For x70 The Affected Firmware:- 3.000.0110.001 and versions below The Fixed Firmware:- 3.001.0031.001 | |||||
| CVE-2025-47411 | 1 Apache | 1 Streampipes | 2026-06-17 | N/A | 8.1 HIGH |
| A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator. This vulnerability allows an attacker to gain administrative control over the application by manipulating JWT tokens, which can lead to data tampering, unauthorized access and other security issues. This issue affects Apache StreamPipes: through 0.97.0. Users are recommended to upgrade to version 0.98.0, which fixes the issue. | |||||
| CVE-2025-47410 | 1 Apache | 1 Geode | 2026-06-17 | N/A | 8.8 HIGH |
| Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on behalf of the authenticated user. This issue affects Apache Geode: versions 1.10 through 1.15.1 Users are recommended to upgrade to version 1.15.2, which fixes the issue. | |||||
| CVE-2025-47408 | 1 Qualcomm | 40 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6900 and 37 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption when another driver calls an IOCTL with invalid input/output buffer. | |||||
| CVE-2025-47407 | 1 Qualcomm | 200 Cq7790, Cq7790 Firmware, Cq8725s and 197 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level. | |||||
| CVE-2025-47406 | 1 Qualcomm | 62 Cologne, Cologne Firmware, Fastconnect 6700 and 59 more | 2026-06-17 | N/A | 6.1 MEDIUM |
| Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. | |||||
| CVE-2025-47405 | 1 Qualcomm | 32 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 29 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption when processing camera sensor input/output control codes with invalid output buffers. | |||||
| CVE-2025-47404 | 1 Qualcomm | 376 215 Mobile, 215 Mobile Firmware, 5g Fixed Wireless Access and 373 more | 2026-06-17 | N/A | 6.5 MEDIUM |
| Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | |||||
| CVE-2025-47403 | 1 Qualcomm | 514 Ar8035, Ar8035 Firmware, Cologne and 511 more | 2026-06-17 | N/A | 6.5 MEDIUM |
| Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | |||||
| CVE-2025-47402 | 1 Qualcomm | 188 Ar8035, Ar8035 Firmware, Cologne and 185 more | 2026-06-17 | N/A | 6.5 MEDIUM |
| Transient DOS when processing a received frame with an excessively large authentication information element. | |||||
| CVE-2025-47401 | 1 Qualcomm | 490 Ar8035, Ar8035 Firmware, Cologne and 487 more | 2026-06-17 | N/A | 6.5 MEDIUM |
| Transient DOS when processing target power rate tables during channel configuration. | |||||
| CVE-2025-47400 | 1 Qualcomm | 22 Pandeiro, Pandeiro Firmware, Snapdragon 8 Elite Gen 5 and 19 more | 2026-06-17 | N/A | 7.1 HIGH |
| Cryptographic issue while copying data to a destination buffer without validating its size. | |||||
| CVE-2025-47399 | 1 Qualcomm | 28 Cologne, Cologne Firmware, Fastconnect 7800 and 25 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters. | |||||
| CVE-2025-47398 | 1 Qualcomm | 306 Ar8031, Ar8031 Firmware, Csra6620 and 303 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers. | |||||
| CVE-2025-47397 | 1 Qualcomm | 294 Ar8031, Ar8031 Firmware, Csra6620 and 291 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. | |||||
| CVE-2025-47396 | 1 Qualcomm | 90 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 87 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption occurs when a secure application is launched on a device with insufficient memory. | |||||
