7.8

CVSS3.1

CVE-2025-21693 - mm: zswap: properly synchronize freeing resources during CPU hotunplug

In the Linux kernel, the following vulnerability has been resolved: mm: zswap: properly synchronize freeing resources during CPU hotunplug In zswap_compress() and zswap_decompress(), the per-CPU acomp_ctx of the current CPU at the beginning of the operation is retrieved and used throughout. Howe…

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: May 4, 2025, 7:19 a.m.

8.3

CVSS3.1

CVE-2024-46436 -

Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 5:38 p.m.

4.8

CVSS3.1

CVE-2024-57409 -

A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 7:06 p.m.

8.2

CVSS3.1

CVE-2024-13440 - Super Store Finder <= 7.0 - Unauthenticated SQL Injection to Stored Cross-Site Scripting

The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the β€˜ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…

πŸ“… Published: Feb. 9, 2025, 4:22 a.m. πŸ”„ Last Modified: April 8, 2026, 5:23 p.m.

6.5

CVSS3.1

CVE-2024-54658 - webkitgtk: Processing web content may lead to a denial-of-service

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to a denial-of-service.

πŸ“… Published: Feb. 9, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 7:18 p.m.

5.5

CVSS3.1

CVE-2025-21684 - gpio: xilinx: Convert gpio_lock to raw spinlock

In the Linux kernel, the following vulnerability has been resolved: gpio: xilinx: Convert gpio_lock to raw spinlock irq_chip functions may be called in raw spinlock context. Therefore, we must also use a raw spinlock for our own internal locking. This fixes the following lockdep splat: [ 5.3…

πŸ“… Published: Feb. 9, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.5

CVSS3.1

CVE-2024-57949 - irqchip/gic-v3-its: Don't enable interrupts in its_irq_set_vcpu_affinity()

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Don't enable interrupts in its_irq_set_vcpu_affinity() The following call-chain leads to enabling interrupts in a nested interrupt disabled section: irq_set_vcpu_affinity() irq_get_desc_lock() raw_spin…

πŸ“… Published: Feb. 9, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:18 p.m.

4.7

CVSS3.1

CVE-2025-21685 - platform/x86: lenovo-yoga-tab2-pro-1380-fastcharger: fix serdev race

In the Linux kernel, the following vulnerability has been resolved: platform/x86: lenovo-yoga-tab2-pro-1380-fastcharger: fix serdev race The yt2_1380_fc_serdev_probe() function calls devm_serdev_device_open() before setting the client ops via serdev_device_set_client_ops(). This ordering can trig…

πŸ“… Published: Feb. 9, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

6.4

CVSS3.1

CVE-2025-0169 - DWT - Directory & Listing WordPress Theme <=3.3.4 - Authenticated (Contributor+) Stored Cross-Site …

The DWT - Directory & Listing WordPress Theme is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contribut…

πŸ“… Published: Feb. 8, 2025, 10:21 p.m. πŸ”„ Last Modified: April 21, 2026, 10:30 p.m.

9.8

CVSS3.1

CVE-2025-0316 - WP Directorybox Manager <= 2.5 - Authentication Bypass

The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_enquiry_agent_contact_form_submit_callback' function. This makes it possible for unauthenticated attackers to log in a…

πŸ“… Published: Feb. 8, 2025, 9:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6812 of 34,919
Β« previous page Β» next page
Filters