5.5
CVE-2025-22014 - soc: qcom: pdr: Fix the potential deadlock
In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pdr: Fix the potential deadlock When some client process A call pdr_add_lookup() to add the look up for the service and does schedule locator work, later a process B got a new server packet indicating locator is up andβ¦
5.5
CVE-2025-22012 - Revert "arm64: dts: qcom: sdm845: Affirm IDR0.CCTW on apps_smmu"
In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: dts: qcom: sdm845: Affirm IDR0.CCTW on apps_smmu" There are reports that the pagetable walker cache coherency is not a given across the spectrum of SDM845/850 devices, leading to lock-ups and resets. It works fine β¦
8.6
CVE-2025-32406 -
An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse the XML response.
6.4
CVE-2025-32413 -
Vulnerability-Lookup before 2.7.1 allows stored XSS via a user bio in website/web/views/user.py.
5.1
CVE-2025-3389 - hailey888 oa_system Backend InformManageController.java testMess cross site scripting
A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue affects the function testMess of the file cn/gson/oasys/controller/inform/InformManageController.java of the component Backend. The manipulation of the argument menu leads to croβ¦
5.3
CVE-2025-3388 - hailey888 oa_system Frontend LoginsController.java loginCheck cross site scripting
A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the component Frontend. The manipulation of the argument Username leads to cross site sβ¦
5.1
CVE-2025-3387 - renrenio renren-security JSON cross site scripting
A vulnerability classified as problematic has been found in renrenio renren-security up to 5.4.0. This affects an unknown part of the component JSON Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public β¦
4.8
CVE-2025-3386 - LinZhaoguan pb-cms Friendship Link admin#links cross site scripting
A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin#links of the component Friendship Link Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The expβ¦
8.6
CVE-2025-0942 - Jalios JPlatform 10 SP6 < 10.0.6 Record Chooser SQL Injection
The DB chooser functionality inΒ Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for unauthenticated users to trigger SQL Injection. This issue affects JPlatform before 10.0.6 and a PatchPlugin release 10.0.6 was issued 2023-02-06.
4.8
CVE-2025-3385 - LinZhaoguan pb-cms Classification Management Page cross site scripting
A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Classification Management Page. The manipulation of the argument Classification name leads to cross site scripting. The attack can beβ¦