4.3
CVE-2025-8595 - Zakra <= 4.1.5 - Missing Authorization to Subscriber+ Demo Import
The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, toβ¦
8
CVE-2025-54634 -
Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Successful exploitation of this vulnerability may affect availability.
6.7
CVE-2025-54633 -
Out-of-bounds read vulnerability in the register configuration of the DMA module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
6.8
CVE-2025-54632 -
Vulnerability of insufficient data length verification in the HVB module. Impact: Successful exploitation of this vulnerability may affect service integrity.
6.7
CVE-2025-54631 -
Vulnerability of insufficient data length verification in the partition module. Impact: Successful exploitation of this vulnerability may affect availability.
6.8
CVE-2025-54630 -
:Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulnerability may affect availability.
6.7
CVE-2025-54629 -
Race condition issue occurring in the physical page import process of the memory management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
5.3
CVE-2025-54628 -
Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
8.8
CVE-2025-54627 -
Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
6.7
CVE-2025-54625 -
Race condition vulnerability in the kernel file system module. Impact: Successful exploitation of this vulnerability may affect availability.