5.3
CVE-2025-60729 -
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function
7.6
CVE-2025-60735 -
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
9.8
CVE-2025-60803 -
Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the component /api/aaa;/../register.
7.5
CVE-2025-60572 -
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvNetwork.
7.5
CVE-2025-60562 -
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formWlSiteSurvey.
5.5
CVE-2025-40023 - drm/xe/vf: Don't expose sysfs attributes not applicable for VFs
In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Don't expose sysfs attributes not applicable for VFs VFs can't read BMG_PCIE_CAP(0x138340) register nor access PCODE (already guarded by the info.skip_pcode flag) so we shouldn't expose attributes that require any of tβ¦
7.0
CVE-2025-40018 - ipvs: Defer ip_vs_ftp unregister during netns cleanup
In the Linux kernel, the following vulnerability has been resolved: ipvs: Defer ip_vs_ftp unregister during netns cleanup On the netns cleanup path, __ip_vs_ftp_exit() may unregister ip_vs_ftp before connections with valid cp->app pointers are flushed, leading to a use-after-free. Fix this by inβ¦
7.5
CVE-2025-60559 -
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetDomainFilter.
6.4
CVE-2025-7730 - Bold Page Builder <= 5.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via `percentaβ¦
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βpercentageβ parameter in all versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level aβ¦
6.3
CVE-2025-60023 - AutomationDirect Productivity Suite Relative Path Traversal
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary directories on the target machine.