6.4
CVE-2024-13650 - Piotnet Addons For Elementor <= 2.4.36 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before After Image Comparison Slider' widget in all versions up to, and including, 2.4.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticβ¦
8.1
CVE-2025-3520 - Avatar <= 0.1.4 - Authenticated (Subscriber+) Arbitrary File Deletion
The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 0.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the sβ¦
8.2
CVE-2025-0467 - GPU DDK - rgxfw_hwperf_get_packet_buffer OOB write
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
8.6
CVE-2025-25427 - XSS in TP-Link TL-WR841N v14/v14.6/v14.8 Upnp page
A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/v14.8 <= Build 241230 Rel. 50788n allows remote attackers to inject arbitrary JavaScript code via the port mapping description. This leads to an execution of the JavaScript payloaβ¦
9.8
CVE-2025-28242 -
Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.
7.5
CVE-2025-28235 -
An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.0.7x and v1.0.5x allows attackers to access Administrator credentials in plaintext.
7.8
CVE-2025-40364 - io_uring: fix io_req_prep_async with provided buffers
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if needed.
9.1
CVE-2024-29643 -
An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.
5.5
CVE-2025-38575 - ksmbd: use aead_request_free to match aead_request_alloc
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_alloc Use aead_request_free() instead of kfree() to properly free memory allocated by aead_request_alloc(). This ensures sensitive crypto data is zeroed before being freed.
9.8
CVE-2024-53591 -
An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.