5.3
CVE-2025-48769 - Apache NuttX RTOS: fs/vfs/fs_rename: use after free
Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer reallocation and write to the previously freed heap chunk, that in spโฆ
5.3
CVE-2025-48768 - Apache NuttX RTOS: fs/inode: fs_inoderemove root inode removal
Release of Invalid Pointer or Reference vulnerability was discovered inย fs/inode/fs_inoderemoveย code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer dereference (handled differently depending on the taโฆ
6.9
CVE-2025-66023 - NanoMQ has Use-After-Free of malformed bridging message
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Free (UAF) vulnerability within the MQTT bridge client component (implemented via the underlying NanoNNG library). The vulnerability is triggered when NanoMQ acts as a bridge connectโฆ
5.3
CVE-2025-15405 - PHPEMS cross-site request forgery
A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely.
5.3
CVE-2025-15404 - campcodes School File Management System save_file.php unrestricted upload
A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an unknown function of the file /save_file.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosedโฆ
6.9
CVE-2026-0544 - itsourcecode School Management System index.php sql injection
A security flaw has been discovered in itsourcecode School Management System 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and โฆ
7.8
CVE-2025-11157 - Arbitrary Code Execution in feast-dev/feast
A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`. The vulnerability arises from the use of `yaml.load(..., Loader=yaml.Loader)` tโฆ
5.3
CVE-2025-13820 - Comments โ wpDiscuz < 7.6.40 - Unauthenticated Account Takeover
The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.
5.3
CVE-2025-69413 - Gitea: Gitea: Information disclosure via differing authentication responses
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
8.1
CVE-2025-12805 - Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy
A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPolicy restricts access to the llama-stack service endpoint. As a result, a user iโฆ