03-04-2025, 05:00 PM
CVE-2025-27521
CVE-2025-27221
CVE-2025-27220
CVE-2025-26849
CVE-2025-24309
CVE-2025-24301
CVE-2025-23420
CVE-2025-23418
CVE-2025-23414
CVE-2025-23409
CVE-2025-23240
CVE-2025-23234
CVE-2025-22897
CVE-2025-22847
CVE-2025-22841
CVE-2025-22837
CVE-2025-22835
CVE-2025-22443
CVE-2025-21098
CVE-2025-21097
Vulnerability of improper access permission in the process management module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Maximum CVSS Score : 6.8
Exploit Availability: Not available
CVE-2025-27221
In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.
Maximum CVSS Score : 3.2
Exploit Availability: Not available
CVE-2025-27220
In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
Maximum CVSS Score : 4.0
Exploit Availability: Not available
CVE-2025-26849
There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions.
Maximum CVSS Score : 4.3
Exploit Availability: Not available
CVE-2025-24309
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
Maximum CVSS Score : 3.8
Exploit Availability: Not available
CVE-2025-24301
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.
Maximum CVSS Score : 3.8
Exploit Availability: Not available
CVE-2025-23420
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
Maximum CVSS Score : 3.8
Exploit Availability: Not available
CVE-2025-23418
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.
Maximum CVSS Score : 3.3
Exploit Availability: Not available
CVE-2025-23414
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.
Maximum CVSS Score : 3.8
Exploit Availability: Not available
CVE-2025-23409
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.
Maximum CVSS Score : 3.8
Exploit Availability: Not available
CVE-2025-23240
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
Maximum CVSS Score : 3.8
Exploit Availability: Not available
CVE-2025-23234
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.
Maximum CVSS Score : 3.3
Exploit Availability: Not available
CVE-2025-22897
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.
Maximum CVSS Score : 3.3
Exploit Availability: Not available
CVE-2025-22847
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.
Maximum CVSS Score : 3.3
Exploit Availability: Not available
CVE-2025-22841
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.
Maximum CVSS Score : 3.3
Exploit Availability: Not available
CVE-2025-22837
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.
Maximum CVSS Score : 3.3
Exploit Availability: Not available
CVE-2025-22835
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
Maximum CVSS Score : 3.8
Exploit Availability: Not available
CVE-2025-22443
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.
Maximum CVSS Score : 3.3
Exploit Availability: Not available
CVE-2025-21098
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check.
Maximum CVSS Score : 5.5
Exploit Availability: Not available
CVE-2025-21097
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.
Maximum CVSS Score : 3.3
Exploit Availability: Not available