Vulnerabilities (CVE)

Total 398785 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-47419 2026-06-17 N/A N/A
Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
CVE-2025-47418 2026-06-17 N/A N/A
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. There is no visible indication when the system is recording and recording can be enabled remotely via a network API. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
CVE-2025-47417 2026-06-17 N/A N/A
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. When Enable Debug Images in Crestron Automate VX is active, snapshots of the captured video or portions thereof are stored locally on the system, and there is no visible indication that this is being done. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
CVE-2025-47416 2026-06-17 N/A N/A
A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to unauthorized execution of an attacker-defined file that gets prioritized by the ConsoleFindCommandMatchList. A third-party researcher discovered that the ConsoleFindCommandMatchList enumerates the /dev/shm/symproc/c directory in alphabetical order to identify console commands. Permission levels are inferred from the integer values present in each command's file name.  Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061  Fixed Firmware: no fixed released (product is discontinued and end of life)   For x70   The Affected Firmware:- 3.000.0110.001  and versions below The Fixed Firmware:- 3.001.0031.001
CVE-2025-47415 2026-06-17 N/A N/A
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001. Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061 - (no fix released, product discontinued)   For x70   The Affected Firmware:- 3.000.0110.001  and versions below The Fixed Firmware:- 3.001.0031.001
CVE-2025-47411 1 Apache 1 Streampipes 2026-06-17 N/A 8.1 HIGH
A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator.  This vulnerability allows an attacker to gain administrative control over the application by manipulating JWT tokens, which can lead to data tampering, unauthorized access and other security issues. This issue affects Apache StreamPipes: through 0.97.0. Users are recommended to upgrade to version 0.98.0, which fixes the issue.
CVE-2025-47410 1 Apache 1 Geode 2026-06-17 N/A 8.8 HIGH
Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on behalf of the authenticated user. This issue affects Apache Geode: versions 1.10 through 1.15.1 Users are recommended to upgrade to version 1.15.2, which fixes the issue.
CVE-2025-47408 1 Qualcomm 40 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6900 and 37 more 2026-06-17 N/A 7.8 HIGH
Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
CVE-2025-47407 1 Qualcomm 200 Cq7790, Cq7790 Firmware, Cq8725s and 197 more 2026-06-17 N/A 7.8 HIGH
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
CVE-2025-47406 1 Qualcomm 62 Cologne, Cologne Firmware, Fastconnect 6700 and 59 more 2026-06-17 N/A 6.1 MEDIUM
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
CVE-2025-47405 1 Qualcomm 32 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 29 more 2026-06-17 N/A 7.8 HIGH
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
CVE-2025-47404 1 Qualcomm 376 215 Mobile, 215 Mobile Firmware, 5g Fixed Wireless Access and 373 more 2026-06-17 N/A 6.5 MEDIUM
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
CVE-2025-47403 1 Qualcomm 514 Ar8035, Ar8035 Firmware, Cologne and 511 more 2026-06-17 N/A 6.5 MEDIUM
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
CVE-2025-47402 1 Qualcomm 188 Ar8035, Ar8035 Firmware, Cologne and 185 more 2026-06-17 N/A 6.5 MEDIUM
Transient DOS when processing a received frame with an excessively large authentication information element.
CVE-2025-47401 1 Qualcomm 490 Ar8035, Ar8035 Firmware, Cologne and 487 more 2026-06-17 N/A 6.5 MEDIUM
Transient DOS when processing target power rate tables during channel configuration.
CVE-2025-47400 1 Qualcomm 22 Pandeiro, Pandeiro Firmware, Snapdragon 8 Elite Gen 5 and 19 more 2026-06-17 N/A 7.1 HIGH
Cryptographic issue while copying data to a destination buffer without validating its size.
CVE-2025-47399 1 Qualcomm 28 Cologne, Cologne Firmware, Fastconnect 7800 and 25 more 2026-06-17 N/A 7.8 HIGH
Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters.
CVE-2025-47398 1 Qualcomm 306 Ar8031, Ar8031 Firmware, Csra6620 and 303 more 2026-06-17 N/A 7.8 HIGH
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.
CVE-2025-47397 1 Qualcomm 294 Ar8031, Ar8031 Firmware, Csra6620 and 291 more 2026-06-17 N/A 7.8 HIGH
Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.
CVE-2025-47396 1 Qualcomm 90 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 87 more 2026-06-17 N/A 7.8 HIGH
Memory corruption occurs when a secure application is launched on a device with insufficient memory.