9.1
CVE-2025-22927 -
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
7.8
CVE-2025-21999 - proc: fix UAF in proc_get_inode()
In the Linux kernel, the following vulnerability has been resolved: proc: fix UAF in proc_get_inode() Fix race between rmmod and /proc/XXX's inode instantiation. The bug is that pde->proc_ops don't belong to /proc, it belongs to a module, therefore dereferencing it after /proc entry has been regβ¦
6.5
CVE-2025-32053 - Libsoup: heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space()
A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read.
6.5
CVE-2025-32052 - Libsoup: heap buffer overflow in sniff_unknown()
A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read.
9.8
CVE-2025-22928 -
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php.
7.5
CVE-2024-47215 -
An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an invalid GTM SS preview header to events, causing them to be retried indefinitely. As a result, the performance of forwarding events to GTM SS overall can be affected (latency, throuβ¦
6.5
CVE-2024-47217 -
An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated endpoint. It can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.
9.8
CVE-2025-26817 -
Netwrix Password Secure 9.2.0.32454 allows OS command injection.
9.8
CVE-2025-22926 -
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
5.5
CVE-2025-22002 - netfs: Call `invalidate_cache` only if implemented
In the Linux kernel, the following vulnerability has been resolved: netfs: Call `invalidate_cache` only if implemented Many filesystems such as NFS and Ceph do not implement the `invalidate_cache` method. On those filesystems, if writing to the cache (`NETFS_WRITE_TO_CACHE`) fails for some reasoβ¦