CVE Monitor
CVE-2025-47388
HIGH
06 Jan 2026
Memory corruption while passing pages to DSP with an unaligned starting address.
CVE-2025-47380
HIGH
06 Jan 2026
Memory corruption while preprocessing IOCTLs in sensors.
CVE-2025-47369
MEDIUM
06 Jan 2026
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
CVE-2025-47356
HIGH
06 Jan 2026
Memory Corruption when multiple threads concurrently access and modify shared resources.
CVE-2025-47348
HIGH
06 Jan 2026
Memory corruption while processing identity credential operations in the trusted application.
CVE-2025-47346
HIGH
06 Jan 2026
Memory corruption while processing a secure logging command in the trusted application.
CVE-2025-47345
HIGH
06 Jan 2026
Cryptographic issue may occur while encrypting license data.
CVE-2025-47344
MEDIUM
06 Jan 2026
Memory corruption while handling sensor utility operations.
CVE-2025-47343
HIGH
06 Jan 2026
Memory corruption while processing a video session to set video parameters.
CVE-2025-47339
HIGH
06 Jan 2026
Memory corruption while deinitializing a HDCP session.
CVE-2025-47337
MEDIUM
06 Jan 2026
Memory corruption while accessing a synchronization object during concurrent operations.
CVE-2025-47336
MEDIUM
06 Jan 2026
Memory corruption while performing sensor register read operations.
CVE-2025-47335
MEDIUM
06 Jan 2026
Memory corruption while parsing clock configuration data for a specific hardware type.
CVE-2025-47334
MEDIUM
06 Jan 2026
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
CVE-2025-47333
MEDIUM
06 Jan 2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
CVE-2025-47332
MEDIUM
06 Jan 2026
Memory corruption while processing a config call from userspace.
CVE-2025-47331
MEDIUM
06 Jan 2026
Information disclosure while processing a firmware event.
CVE-2025-47330
MEDIUM
06 Jan 2026
Transient DOS while parsing video packets received from the video firmware.
CVE-2026-0642
MEDIUM
06 Jan 2026
A vulnerability was detected in projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /app/complaint.php. The manipulation of the argument Name results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
CVE-2025-11235
LOW
06 Jan 2026
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.
CVE-2025-15472
HIGH
06 Jan 2026
A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of the component httpd . This manipulation of the argument DeviceURL causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-14625
MEDIUM
06 Jan 2026
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell modules), Altera Quartus Prime Lite on Windows (Nios II Command Shell modules) allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 19.1 through 24.1; Quartus Prime Lite: from 19.1 through 24.1.
CVE-2025-14614
MEDIUM
06 Jan 2026
Insecure Temporary File vulnerability in Altera Quartus Prime Standard  Installer (SFX) on Windows, Altera Quartus Prime Lite  Installer (SFX) on Windows allows Explore for Predictable Temporary File Names.This issue affects Quartus Prime Standard: from 23.1 through 24.1; Quartus Prime Lite: from 23.1 through 24.1.
CVE-2025-15471
CRITICAL
06 Jan 2026
A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-14599
MEDIUM
06 Jan 2026
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Prime Lite  Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 23.1 through 24.1; Quartus Prime Lite: from 23.1 through 24.1.