Common Vulnerabilities and Exposures (CVE)

CVE-2025-48567

Mar 6, 2026 03:13:46 UTC

In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional executi...

CVE-2025-48544

Mar 6, 2026 03:13:01 UTC

In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...

CVE-2025-32313

Mar 6, 2026 03:12:26 UTC

In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...

CVE-2024-43766

Mar 6, 2026 03:11:34 UTC

In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User ...

CVE-2024-31328

Mar 6, 2026 03:04:51 UTC

In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from the background on the paired companion phone due to a logic error in the code. This could lead to local escalation of pr...

CVE-2025-48636

Mar 6, 2026 03:04:33 UTC

In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User ...

CVE-2026-3616

Mar 6, 2026 01:32:08 UTC

A vulnerability was detected in DefaultFuction Jeson Customer Relationship Management System 1.0.0. Impacted is an unknown function of the file /modules/customers/edit.php. Performing a manipulation of the argument ID results in sql injecti...

CVE-2026-3613

Mar 6, 2026 01:02:07 UTC

A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to stack-based buffer overflow. It is possible t...

CVE-2026-3612

Mar 6, 2026 00:32:10 UTC

A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/adm.cgi of the component OTA Online Upgrade. This manipulation of the argument firmware_url causes command injection. It...

CVE-2026-3610

Mar 6, 2026 00:32:08 UTC

A vulnerability was found in HSC Cybersecurity Mailinspector up to 5.3.2-3. Affected by this issue is some unknown functionality of the file /mailinspector/mliUserValidation.php of the component URL Handler. The manipulation of the argument...

CVE-2025-30415

Mar 5, 2026 23:56:15 UTC

Denial of service due to improper handling of malformed input. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40077, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build ...

CVE-2026-28723

Mar 5, 2026 23:55:37 UTC

Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

CVE-2026-28722

Mar 5, 2026 23:55:18 UTC

Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

CVE-2026-28721

Mar 5, 2026 23:55:01 UTC

Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

CVE-2026-28720

Mar 5, 2026 23:54:43 UTC

Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.