Vulnerabilities
201 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-41432 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2025-69822 | An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame NVD description · AI analysis pending | 7.4 | <1% | PoC |
| — | |
| CVE-2025-27128 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2025-27131 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. NVD description · AI analysis pending | 5.5 group max | <1% |
| — | ||
| CVE-2025-4415 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO allows Cross-Site Scripting (XSS).This is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO allows Cross-Site Scripting (XSS).This issue affects Piwik PRO: from 0.0.0 before 1.3.2. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2025-27132 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2025-22851 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2025-31680 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from 0.0.0 before 1.24.0. NVD description · AI analysis pending | 6.8 | <1% |
| — | ||
| CVE-2025-24309 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. NVD description · AI analysis pending | 7.8 group max | <1% |
| — |