Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 35983 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-58312 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.1 MEDIUM
Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-58309 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.8 MEDIUM
Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
CVE-2025-58305 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.2 MEDIUM
Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-58304 1 Huawei 1 Harmonyos 2026-06-17 N/A 4.9 MEDIUM
Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-58302 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 8.4 HIGH
Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-58294 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.2 MEDIUM
Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-58292 1 Huawei 1 Harmonyos 2026-06-17 N/A 3.3 LOW
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
CVE-2025-58291 1 Huawei 1 Harmonyos 2026-06-17 N/A 3.3 LOW
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
CVE-2025-58290 1 Huawei 1 Harmonyos 2026-06-17 N/A 3.3 LOW
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
CVE-2025-58288 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.5 MEDIUM
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
CVE-2025-58286 1 Huawei 1 Harmonyos 2026-06-17 N/A 3.3 LOW
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
CVE-2025-58285 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.3 MEDIUM
Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-58284 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.9 MEDIUM
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-58283 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.5 MEDIUM
Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-58282 1 Huawei 1 Harmonyos 2026-06-17 N/A 2.8 LOW
Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-58279 1 Huawei 1 Harmonyos 2026-06-17 N/A 4.4 MEDIUM
Permission control vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-58276 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 6.8 MEDIUM
Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-58053 1 Galette 1 Galette 2026-06-17 N/A 9.8 CRITICAL
Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a self forged POST request, one can gain higher privileges. Version 1.2.0 fixes the issue.
CVE-2025-57808 1 Esphome 1 Esphome Firmware 2026-06-17 N/A 8.1 HIGH
ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.
CVE-2025-57784 1 Hiawatha-webserver 1 Hiawatha 2026-06-17 N/A 3.3 LOW
Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.