Total
5482 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-66319 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 3.3 LOW |
|
Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.
|
|||||
| CVE-2026-28541 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 4.0 MEDIUM |
|
Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-24924 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 6.1 MEDIUM |
|
Vulnerability of improper permission control in the print module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2026-24923 | 1 Huawei | 1 Harmonyos | 2026-02-10 | N/A | 6.3 MEDIUM |
|
Permission control vulnerability in the HDC module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2026-24920 | 1 Huawei | 2 Emui, Harmonyos | 2026-02-09 | N/A | 6.2 MEDIUM |
|
Permission control vulnerability in the AMS module.
Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-24931 | 1 Huawei | 1 Harmonyos | 2026-02-09 | N/A | 5.9 MEDIUM |
|
Vulnerability of improper criterion security check in the card module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2025-68967 | 1 Huawei | 1 Harmonyos | 2026-01-15 | N/A | 5.7 MEDIUM |
|
Vulnerability of improper permission control in the print module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2013-1801 | 1 Jnunemaker | 1 Httparty | 2026-01-07 | 7.5 HIGH | N/A |
|
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156.
|
|||||
| CVE-2025-66325 | 1 Huawei | 2 Emui, Harmonyos | 2025-12-09 | N/A | 6.2 MEDIUM |
|
Permission control vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2025-66329 | 1 Huawei | 2 Emui, Harmonyos | 2025-12-09 | N/A | 4.0 MEDIUM |
|
Permission control vulnerability in the window management module. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2025-58302 | 1 Huawei | 2 Emui, Harmonyos | 2025-12-02 | N/A | 8.4 HIGH |
|
Permission control vulnerability in the Settings module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2025-64315 | 1 Huawei | 1 Harmonyos | 2025-12-02 | N/A | 4.4 MEDIUM |
|
Configuration defect vulnerability in the file management module.
Impact: Successful exploitation of this vulnerability may affect app data confidentiality and integrity.
|
|||||
| CVE-2025-58315 | 1 Huawei | 1 Harmonyos | 2025-12-02 | N/A | 5.5 MEDIUM |
|
Permission control vulnerability in the Wi-Fi module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2025-58312 | 1 Huawei | 1 Harmonyos | 2025-12-02 | N/A | 5.1 MEDIUM |
|
Permission control vulnerability in the App Lock module.
Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2025-58309 | 1 Huawei | 1 Harmonyos | 2025-12-02 | N/A | 6.8 MEDIUM |
|
Permission control vulnerability in the startup recovery module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
|
|||||
| CVE-2025-58294 | 1 Huawei | 1 Harmonyos | 2025-12-02 | N/A | 6.2 MEDIUM |
|
Permission control vulnerability in the print module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2015-0816 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-11-25 | 5.0 MEDIUM | N/A |
|
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.
|
|||||
| CVE-2013-5598 | 1 Mozilla | 1 Firefox | 2025-11-25 | 8.3 HIGH | N/A |
|
PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.
|
|||||
| CVE-2015-0801 | 1 Mozilla | 3 Firefox, Firefox Esr, Thunderbird | 2025-11-25 | 7.5 HIGH | N/A |
|
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.
|
|||||
| CVE-2014-5415 | 1 Beckhoff | 2 Embedded Pc Images, Twincat | 2025-11-05 | 9.4 HIGH | 9.1 CRITICAL |
|
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain access via the (1) Windows CE Remote Configuration Tool, (2) CE Remote Display service, or (3) TELNET service.
|
|||||
| CVE-2014-5412 | 2 Aveva, Schneider-electric | 2 Clearscada, Scada Expert Clearscada | 2025-11-04 | 6.4 MEDIUM | N/A |
|
Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access to the guest account.
|
|||||
| CVE-2015-1318 | 1 Apport Project | 1 Apport | 2025-11-03 | 7.2 HIGH | N/A |
|
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).
|
|||||
| CVE-2014-2349 | 1 Emerson | 1 Deltav | 2025-10-31 | 6.2 MEDIUM | N/A |
|
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.
|
|||||
| CVE-2013-0422 | 3 Canonical, Opensuse, Oracle | 4 Ubuntu Linux, Opensuse, Jdk and 1 more | 2025-10-22 | 10.0 HIGH | 9.8 CRITICAL |
|
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inabilit ...
Show More |
|||||
| CVE-2016-3643 | 1 Solarwinds | 1 Virtualization Manager | 2025-10-22 | 7.2 HIGH | 7.8 HIGH |
|
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."
|
|||||
| CVE-2015-1769 | 1 Microsoft | 9 Windows 10, Windows 7, Windows 8 and 6 more | 2025-10-22 | 7.2 HIGH | 6.6 MEDIUM |
|
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Mount Manager Elevation of Privilege Vulnerability."
|
|||||
| CVE-2025-54654 | 1 Huawei | 1 Harmonyos | 2025-10-16 | N/A | 6.2 MEDIUM |
|
Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service confidentiality
|
|||||
| CVE-2025-58282 | 1 Huawei | 1 Harmonyos | 2025-10-16 | N/A | 2.8 LOW |
|
Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2025-58283 | 1 Huawei | 1 Harmonyos | 2025-10-16 | N/A | 5.5 MEDIUM |
|
Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2025-58284 | 1 Huawei | 1 Harmonyos | 2025-10-16 | N/A | 5.9 MEDIUM |
|
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2025-58285 | 1 Huawei | 1 Harmonyos | 2025-10-16 | N/A | 5.3 MEDIUM |
|
Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2025-58293 | 1 Huawei | 1 Harmonyos | 2025-10-16 | N/A | 5.5 MEDIUM |
|
Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2014-2375 | 1 Ecava | 1 Integraxor | 2025-10-13 | 8.3 HIGH | N/A |
|
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive information or cause a denial of service (disk consumption), via the CSV export feature.
|
|||||
| CVE-2014-2347 | 1 Amtelco | 1 Misecuremessages | 2025-10-02 | 7.0 HIGH | N/A |
|
Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.
|
|||||
| CVE-2025-5321 | 1 Aimstack | 1 Aim | 2025-09-19 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of the component run_view Object Handler. The manipulation of the argument Abfrage leads to erweiterte Rechte. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2024-54103 | 1 Huawei | 1 Harmonyos | 2025-09-18 | N/A | 6.1 MEDIUM |
|
Vulnerability of improper access control in the album module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2025-58276 | 1 Huawei | 2 Emui, Harmonyos | 2025-09-11 | N/A | 6.8 MEDIUM |
|
Permission verification vulnerability in the home screen module
Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2009-3369 | 1 Backuppc | 1 Backuppc | 2025-09-08 | 8.5 HIGH | N/A |
|
CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.
|
|||||
| CVE-2015-3164 | 2 Opensuse, X.org | 3 Opensuse, X Server, Xorg-server | 2025-08-29 | 3.6 LOW | N/A |
|
The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.
|
|||||
| CVE-2013-4504 | 2 Drupal, Monster Menus Project | 2 Drupal, Monster Menus | 2025-08-27 | 2.6 LOW | N/A |
|
The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.
|
|||||