Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 35985 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-3885 1 Samsung 2 Harman Mgu21, Harman Mgu21 Firmware 2026-06-17 N/A 6.5 MEDIUM
Harman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Harman Becker MGU21 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Bluetooth stack of the BCM89359 chipset. The issue results from the lack of proper validation of Bluetooth frames. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23942.
CVE-2025-3831 1 Checkpoint 1 Harmony Sase 2026-06-17 N/A 8.1 HIGH
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
CVE-2025-3777 1 Huggingface 1 Transformers 2026-06-17 N/A 3.5 LOW
Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection. This allows attackers to craft URLs that appear to be from YouTube but resolve to malicious domains, potentially leading to phishing attacks, malware distribution, or data exfiltration. The issue is fixed in version 4.52.1.
CVE-2025-3768 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 5.0 MEDIUM
Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.
CVE-2025-3744 1 Hashicorp 1 Nomad 2026-06-17 N/A 7.6 HIGH
Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.
CVE-2025-3739 1 Drupal 8 Google Optimize Hide Page Project 1 Drupal 8 Google Optimize Hide Page 2026-06-17 N/A 5.9 MEDIUM
Vulnerability in Drupal Drupal 8 Google Optimize Hide Page.This issue affects Drupal 8 Google Optimize Hide Page: *.*.
CVE-2025-3738 1 Google Optimize Project 1 Google Optimize 2026-06-17 N/A 5.9 MEDIUM
Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*.
CVE-2025-3737 1 Google Maps\ 1 Store Locator Project 2026-06-17 N/A 5.9 MEDIUM
Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.
CVE-2025-3736 1 Simple Gtm Project 1 Simple Gtm 2026-06-17 N/A 5.9 MEDIUM
Vulnerability in Drupal Simple GTM.This issue affects Simple GTM: *.*.
CVE-2025-3735 1 Panelizer \(obsolete\) Project 1 Panelizer \(obsolete\) 2026-06-17 N/A 5.9 MEDIUM
Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*.
CVE-2025-3698 1 Tecno 1 Carlcare 2026-06-17 N/A 7.5 HIGH
Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage risk.
CVE-2025-3675 1 Totolink 2 A3700r, A3700r Firmware 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issue is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3668 1 Totolink 2 A3700r, A3700r Firmware 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability affects the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-3667 1 Totolink 2 A3700r, A3700r Firmware 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-3666 1 Totolink 2 A3700r, A3700r Firmware 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-3663 1 Totolink 2 A3700r, A3700r Firmware 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue affects the function setWiFiEasyCfg/setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component Password Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-3599 1 Broadcom 2 Symantec Endpoint Protection, Symantec Eraser Engine 2026-06-17 N/A 6.5 MEDIUM
Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.
CVE-2025-3597 1 Firelightwp 1 Firelight Lightbox 2026-06-17 N/A 5.9 MEDIUM
The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.
CVE-2025-3587 1 Zerowdd 1 Studentmanager 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical was found in ZeroWdd/code-projects studentmanager 1.0. This vulnerability affects unknown code of the file /getTeacherList. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3471 1 Brainstormforce 1 Sureforms 2026-06-17 N/A 4.9 MEDIUM
The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action