Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2025-01-31 CVE-2025-21671 Use After Free vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: zram: fix potential UAF of zram table If zram_meta_alloc failed early, it frees allocated zram->table without setting it NULL.
local
low complexity
linux CWE-416
7.8
2025-01-31 CVE-2025-21680 Improper Validation of Array Index vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: pktgen: Avoid out-of-bounds access in get_imix_entries Passing a sufficient amount of imix entries leads to invalid access to the pkt_dev->imix_entries array because of the incorrect boundary check. UBSAN: array-index-out-of-bounds in net/core/pktgen.c:874:24 index 20 is out of range for type 'imix_pkt [20]' CPU: 2 PID: 1210 Comm: bash Not tainted 6.10.0-rc1 #121 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) Call Trace: <TASK> dump_stack_lvl lib/dump_stack.c:117 __ubsan_handle_out_of_bounds lib/ubsan.c:429 get_imix_entries net/core/pktgen.c:874 pktgen_if_write net/core/pktgen.c:1063 pde_write fs/proc/inode.c:334 proc_reg_write fs/proc/inode.c:346 vfs_write fs/read_write.c:593 ksys_write fs/read_write.c:644 do_syscall_64 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:130 Found by Linux Verification Center (linuxtesting.org) with SVACE. [ fp: allow to fill the array completely; minor changelog cleanup ]
local
low complexity
linux CWE-129
7.8
2025-01-31 CVE-2024-13472 Code Injection vulnerability in Wcproducttable Woocommerce Product Table
The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.9.4.
network
low complexity
wcproducttable CWE-94
7.3
2025-01-31 CVE-2024-13504 The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
7.2
2025-01-31 CVE-2025-0809 The Link Fixer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via broken links in all versions up to, and including, 3.4 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
7.2
2025-01-31 CVE-2024-13767 The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ClearFiles() function in all versions up to, and including, 1.9.11.
network
low complexity
CWE-862
8.1
2025-01-30 CVE-2025-0568 Out-of-bounds Write vulnerability in Santesoft Sante Pacs Server
Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability.
network
low complexity
santesoft CWE-787
7.5
2025-01-30 CVE-2025-0569 Out-of-bounds Write vulnerability in Santesoft Sante Pacs Server
Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability.
network
low complexity
santesoft CWE-787
7.5
2025-01-30 CVE-2025-0574 Out-of-bounds Write vulnerability in Santesoft Sante Pacs Server
Sante PACS Server URL path Memory Corruption Denial-of-Service Vulnerability.
network
low complexity
santesoft CWE-787
7.5
2025-01-30 CVE-2025-0882 SQL Injection vulnerability in Fabianros Chat System 1.0
A vulnerability was found in code-projects Chat System up to 1.0.
network
low complexity
fabianros CWE-89
7.5