5.5

CVSS3.1

CVE-2024-57949 - irqchip/gic-v3-its: Don't enable interrupts in its_irq_set_vcpu_affinity()

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Don't enable interrupts in its_irq_set_vcpu_affinity() The following call-chain leads to enabling interrupts in a nested interrupt disabled section: irq_set_vcpu_affinity() irq_get_desc_lock() raw_spinโ€ฆ

๐Ÿ“… Published: Feb. 9, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 9:18 p.m.

4.7

CVSS3.1

CVE-2025-21685 - platform/x86: lenovo-yoga-tab2-pro-1380-fastcharger: fix serdev race

In the Linux kernel, the following vulnerability has been resolved: platform/x86: lenovo-yoga-tab2-pro-1380-fastcharger: fix serdev race The yt2_1380_fc_serdev_probe() function calls devm_serdev_device_open() before setting the client ops via serdev_device_set_client_ops(). This ordering can trigโ€ฆ

๐Ÿ“… Published: Feb. 9, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

6.4

CVSS3.1

CVE-2025-0169 - DWT - Directory & Listing WordPress Theme <=3.3.4 - Authenticated (Contributor+) Stored Cross-Site โ€ฆ

The DWT - Directory & Listing WordPress Theme is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributโ€ฆ

๐Ÿ“… Published: Feb. 8, 2025, 10:21 p.m. ๐Ÿ”„ Last Modified: April 21, 2026, 10:30 p.m.

9.8

CVSS3.1

CVE-2025-0316 - WP Directorybox Manager <= 2.5 - Authentication Bypass

The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_enquiry_agent_contact_form_submit_callback' function. This makes it possible for unauthenticated attackers to log in aโ€ฆ

๐Ÿ“… Published: Feb. 8, 2025, 9:20 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-54176 - IBM UrbanCode Deploy missing authentication

IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14 and 7.3 through 7.3.2 could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorizaโ€ฆ

๐Ÿ“… Published: Feb. 8, 2025, 4:15 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 12:33 p.m.

6.9

CVSS4.0

CVE-2025-1117 - CoinRemitter sql injection

A vulnerability, which was classified as critical, was found in CoinRemitter 0.0.1/0.0.2 on OpenCart. This affects an unknown part. The manipulation of the argument coin leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be uโ€ฆ

๐Ÿ“… Published: Feb. 8, 2025, 12:31 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-13850 - Simple add pages or posts <= 2.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Simple add pages or posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbiโ€ฆ

๐Ÿ“… Published: Feb. 8, 2025, 12:21 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:57 p.m.

6.9

CVSS4.0

CVE-2025-1116 - Dreamvention Live AJAX Search Free live_search.searchresults search sql injection

A vulnerability, which was classified as critical, has been found in Dreamvention Live AJAX Search Free up to 1.0.6 on OpenCart. Affected by this issue is the function searchresults/search of the file /?route=extension/live_search/module/live_search.searchresults. The manipulation of the argument kโ€ฆ

๐Ÿ“… Published: Feb. 8, 2025, noon ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-1115 - RT-Thread lwp_syscall.c sys_timer_settime information disclosure

A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this vulnerability is the function sys_device_close/sys_device_control/sys_device_find/sys_device_init/sys_device_open/sys_device_read/sys_device_register/sys_device_write/sys_event_delete/sys_event_recv/sys_eโ€ฆ

๐Ÿ“… Published: Feb. 8, 2025, 10 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 7:53 p.m.

7.8

CVSS3.1

CVE-2025-25187 - Cross-site Scripting in Goto Anything allows arbitrary code execution in Joplin

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by adding note titles to the document using React's `dangerouslySetInnerHTML`, without first escaping HTML entities. Joplin lacks a Contenโ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 10:38 p.m. ๐Ÿ”„ Last Modified: April 11, 2025, 6:56 p.m.
Total resulsts: 348556
Page 6750 of 34,856
ยซ previous page ยป next page
Filters