4.7

CVSS3.1

CVE-2025-4955 - tarteaucitron.io < 1.9.5 - Contributor+ Stored XSS

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

πŸ“… Published: June 18, 2025, 6 a.m. πŸ”„ Last Modified: July 2, 2025, 7:25 p.m.

9.3

CVSS4.0

CVE-2025-51381 -

An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier. If this vulnerability is exploited, an attacker may bypass the authentication of the product from within the LAN to which the product is connected.

πŸ“… Published: June 18, 2025, 4:27 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-50202 - Lychee Path Traversal Vulnerability

Lychee is a free photo-management tool. In versions starting from 6.6.6 to before 6.6.10, an attacker can leak local files including environment variables, nginx logs, other user's uploaded images, and configuration secrets due to a path traversal exploit in SecurePathController.php. This issue has…

πŸ“… Published: June 18, 2025, 4:13 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-4413 - Pixabay Images <= 3.4 - Authenticated (Author+) Arbitrary File Upload

The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pixabay_upload function in all versions up to, and including, 3.4. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary f…

πŸ“… Published: June 18, 2025, 2:21 a.m. πŸ”„ Last Modified: April 21, 2026, 8:15 p.m.

4.5

CVSS3.1

CVE-2025-23252 -

The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A successful exploit of this vulnerability may lead to information disclosure.

πŸ“… Published: June 18, 2025, 12:17 a.m. πŸ”„ Last Modified: Sept. 18, 2025, 2:02 p.m.

7.0

CVSS3.1

CVE-2025-38051 - smb: client: Fix use-after-free in cifs_fill_dirent

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_fill_dirent There is a race condition in the readdir concurrency process, which may access the rsp buffer after it has been released, triggering the following KASAN warning. =============…

πŸ“… Published: June 18, 2025, midnight πŸ”„ Last Modified: Jan. 12, 2026, 1:11 p.m.

5.5

CVSS3.1

CVE-2022-50215 - scsi: sg: Allow waiting for commands to complete on removed device

In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Allow waiting for commands to complete on removed device When a SCSI device is removed while in active use, currently sg will immediately return -ENODEV on any attempt to wait for active commands that were sent before t…

πŸ“… Published: June 18, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 1:27 p.m.

5.5

CVSS3.1

CVE-2022-50127 - RDMA/rxe: Fix error unwind in rxe_create_qp()

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix error unwind in rxe_create_qp() In the function rxe_create_qp(), rxe_qp_from_init() is called to initialize qp, internally things like the spin locks are not setup until rxe_qp_init_req(). If an error occures befor…

πŸ“… Published: June 18, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 6:11 p.m.

5.5

CVSS3.1

CVE-2022-50197 - cpufreq: zynq: Fix refcount leak in zynq_get_revision

In the Linux kernel, the following vulnerability has been resolved: cpufreq: zynq: Fix refcount leak in zynq_get_revision of_find_compatible_node() returns a node pointer with refcount incremented, we should use of_node_put() on it when done. Add missing of_node_put() to avoid refcount leak.

πŸ“… Published: June 18, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 12:47 p.m.

5.5

CVSS3.1

CVE-2022-50158 - mtd: partitions: Fix refcount leak in parse_redboot_of

In the Linux kernel, the following vulnerability has been resolved: mtd: partitions: Fix refcount leak in parse_redboot_of of_get_child_by_name() returns a node pointer with refcount incremented, we should use of_node_put() on it when not need anymore. Add missing of_node_put() to avoid refcount …

πŸ“… Published: June 18, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 3:17 p.m.
Total resulsts: 348202
Page 4862 of 34,821
Β« previous page Β» next page
Filters