Weekly Vulnerabilities Reports > April 14 to 20, 2025

Overview

309 new vulnerabilities reported during this period, including 33 critical vulnerabilities and 127 high severity vulnerabilities. This weekly summary report vulnerabilities in 49 products from 36 vendors including Linux, Senior Walter, Pcman, Namelessmc, and Autodesk. Vulnerabilities are notably categorized as "SQL Injection", "Injection", "NULL Pointer Dereference", "Cross-site Scripting", and "Code Injection".

  • 242 reported vulnerabilities are remotely exploitables.
  • 1 reported vulnerabilities have public exploit available.
  • 117 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 96 reported vulnerabilities are exploitable by an anonymous user.
  • Linux has the most reported vulnerabilities, with 41 reported vulnerabilities.
  • Pcman has the most reported critical vulnerabilities, with 12 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

33 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-04-20 CVE-2025-43955 Convertigo Injection vulnerability in Convertigo

TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.

9.8
2025-04-20 CVE-2025-3830 Kuangstudy Unrestricted Upload of File with Dangerous Type vulnerability in Kuangstudy Kuangsimplebbs 1.0

A vulnerability was found in kuangstudy KuangSimpleBBS 1.0.

9.8
2025-04-20 CVE-2025-3828 Phpgurukul Injection vulnerability in PHPgurukul MEN Salon Management System 1.0

A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical.

9.8
2025-04-20 CVE-2025-3829 Phpgurukul Injection vulnerability in PHPgurukul MEN Salon Management System 1.0

A vulnerability was found in PHPGurukul Men Salon Management System 1.0.

9.8
2025-04-20 CVE-2025-3827 Phpgurukul Injection vulnerability in PHPgurukul MEN Salon Management System 1.0

A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical.

9.8
2025-04-20 CVE-2025-43928 Infodraw Path Traversal vulnerability in Infodraw Pmrs-102 Firmware 7.1.0.0

In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field.

9.8
2025-04-19 CVE-2025-3819 Phpgurukul Injection vulnerability in PHPgurukul MEN Salon Management System 1.0

A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical.

9.8
2025-04-19 CVE-2021-4455 The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.0.4.
9.8
2025-04-19 CVE-2025-1093 The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generate_image function in all versions up to, and including, 1.3.7.
9.8
2025-04-19 CVE-2025-3278 The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.4.
9.8
2025-04-18 CVE-2025-3783 Seniorwalter Unrestricted Upload of File with Dangerous Type vulnerability in Seniorwalter Web-Based Pharmacy Product Management System 1.0

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0.

9.8
2025-04-18 CVE-2025-42599 Qualitia Stack-based Buffer Overflow vulnerability in Qualitia Active! Mail

Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability.

9.8
2025-04-17 CVE-2025-3762 Pcman Classic Buffer Overflow vulnerability in Pcman FTP Server 2.0.7

A vulnerability was found in PCMan FTP Server 2.0.7.

9.8
2025-04-16 CVE-2025-3727 Pcman Unspecified vulnerability in Pcman FTP Server 2.0.7

A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7.

9.8
2025-04-16 CVE-2025-3729 Senior Walter OS Command Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0

A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0.

9.8
2025-04-16 CVE-2025-3723 Pcman Classic Buffer Overflow vulnerability in Pcman FTP Server 2.0.7

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical.

9.8
2025-04-16 CVE-2025-3724 Pcman Classic Buffer Overflow vulnerability in Pcman FTP Server 2.0.7

A vulnerability was found in PCMan FTP Server 2.0.7.

9.8
2025-04-16 CVE-2025-3725 Pcman Unspecified vulnerability in Pcman FTP Server 2.0.7

A vulnerability was found in PCMan FTP Server 2.0.7.

9.8
2025-04-16 CVE-2025-3726 Pcman Unspecified vulnerability in Pcman FTP Server 2.0.7

A vulnerability was found in PCMan FTP Server 2.0.7.

9.8
2025-04-16 CVE-2025-27495 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
9.8
2025-04-16 CVE-2025-27539 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
9.8
2025-04-16 CVE-2025-27540 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
9.8
2025-04-16 CVE-2025-3694 Senior Walter Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0

A vulnerability classified as critical has been found in SourceCodester Web-based Pharmacy Product Management System 1.0.

9.8
2025-04-16 CVE-2025-3690 Phpgurukul SQL Injection vulnerability in PHPgurukul MEN Salon Management System 1.0

A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical.

9.8
2025-04-16 CVE-2025-3682 Pcman Unspecified vulnerability in Pcman FTP Server 2.0.7

A vulnerability was found in PCMan FTP Server 2.0.7.

9.8
2025-04-16 CVE-2025-3683 Pcman Unspecified vulnerability in Pcman FTP Server 2.0.7

A vulnerability was found in PCMan FTP Server 2.0.7.

9.8
2025-04-16 CVE-2025-3684 Xianqi SQL Injection vulnerability in Xianqi Kindergarten Management System 2.0

A vulnerability was found in Xianqi Kindergarten Management System 2.0 Bulid 20190808.

9.8
2025-04-16 CVE-2025-3679 Pcman Out-of-bounds Write vulnerability in Pcman FTP Server 2.0.7

A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7.

9.8
2025-04-16 CVE-2025-3680 Pcman Unspecified vulnerability in Pcman FTP Server 2.0.7

A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical.

9.8
2025-04-16 CVE-2025-3681 Pcman Unspecified vulnerability in Pcman FTP Server 2.0.7

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical.

9.8
2025-04-16 CVE-2025-3678 Pcman Classic Buffer Overflow vulnerability in Pcman FTP Server 2.0.7

A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7.

9.8
2025-04-16 CVE-2025-3676 Xxyopen SQL Injection vulnerability in Xxyopen Novel-Plus 3.5.0

A vulnerability classified as critical has been found in xxyopen Novel-Plus 3.5.0.

9.8
2025-04-14 CVE-2025-3589 Oretnom23 SQL Injection vulnerability in Oretnom23 Music Class Enrollment System 1.0

A vulnerability, which was classified as critical, was found in SourceCodester Music Class Enrollment System 1.0.

9.8

127 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-04-19 CVE-2025-3820 A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical.
8.8
2025-04-19 CVE-2025-3817 Oretnom23 Injection vulnerability in Oretnom23 Online Eyewear Shop 1.0

A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0.

8.8
2025-04-19 CVE-2025-3802 A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644).
8.8
2025-04-19 CVE-2025-3803 A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644).
8.8
2025-04-19 CVE-2025-3404 The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12.
8.8
2025-04-18 CVE-2025-3785 A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical.
8.8
2025-04-18 CVE-2025-3786 Tenda Classic Buffer Overflow vulnerability in Tenda Ac15 Firmware 15.03.05.19

A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical.

8.8
2025-04-17 CVE-2025-3764 Senior Walter Unrestricted Upload of File with Dangerous Type vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0.

8.8
2025-04-17 CVE-2025-3765 Senior Walter Unrestricted Upload of File with Dangerous Type vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0

A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0.

8.8
2025-04-17 CVE-2024-55238 Open Metadata Unspecified vulnerability in Open-Metadata Openmetadata

OpenMetadata <=1.4.1 is vulnerable to SQL Injection.

8.8
2025-04-16 CVE-2025-29905 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-30002 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-30003 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-30030 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-30031 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-30032 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-31343 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-31349 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-31350 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-31351 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-31352 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-31353 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32475 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32822 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32823 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32824 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32825 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32826 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32827 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32828 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32829 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32830 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32831 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32832 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32833 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32834 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32835 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32836 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32837 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32838 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32839 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32840 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32841 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32842 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32843 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32844 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32845 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32846 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32847 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32848 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32849 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32850 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32851 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32852 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32853 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32854 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32855 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32856 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32857 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32858 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32859 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32860 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32861 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32862 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32863 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32864 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32865 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32866 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32867 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32868 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32869 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32870 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32871 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-32872 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
8.8
2025-04-16 CVE-2025-3696 Senior Walter Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0.

8.8
2025-04-16 CVE-2025-3697 Senior Walter Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0

A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0.

8.8
2025-04-16 CVE-2025-3693 A vulnerability was found in Tenda W12 3.0.0.5.
8.8
2025-04-16 CVE-2025-3663 Totolink Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513

A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513.

8.2
2025-04-20 CVE-2025-43920 GNU OS Command Injection vulnerability in GNU Mailman

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line.

8.1
2025-04-18 CVE-2025-3520 The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 0.1.4.
8.1
2025-04-14 CVE-2025-3545 A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014.
8.0
2025-04-14 CVE-2025-3546 A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014.
8.0
2025-04-14 CVE-2025-3543 A vulnerability has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014 and classified as critical.
8.0
2025-04-14 CVE-2025-3544 A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical.
8.0
2025-04-14 CVE-2025-3542 A vulnerability, which was classified as critical, was found in H3C Magic NX15, Magic NX400 and Magic R3010 up to V100R014.
8.0
2025-04-20 CVE-2025-43929 Kovidgoyal Origin Validation Error vulnerability in Kovidgoyal Kitty

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

7.8
2025-04-18 CVE-2025-40014 Linux Improper Validation of Array Index vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: objtool, spi: amd: Fix out-of-bounds stack access in amd_set_spi_freq() If speed_hz < AMD_SPI_MIN_HZ, amd_set_spi_freq() iterates over the entire amd_spi_freq array without breaking out early, causing 'i' to go beyond the array bounds. Fix that by stopping the loop when it gets to the last entry, so the low speed_hz value gets clamped up to AMD_SPI_MIN_HZ. Fixes the following warning with an UBSAN kernel: drivers/spi/spi-amd.o: error: objtool: amd_set_spi_freq() falls through to next function amd_spi_set_opcode()

7.8
2025-04-18 CVE-2025-40114 Linux Improper Validation of Array Index vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: iio: light: Add check for array bounds in veml6075_read_int_time_ms The array contains only 5 elements, but the index calculated by veml6075_read_int_time_index can range from 0 to 7, which could lead to out-of-bounds access.

7.8
2025-04-17 CVE-2025-3763 Razormist Unspecified vulnerability in Razormist Phone Management System 1.0

A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0.

7.8
2025-04-16 CVE-2025-22067 Linux Improper Validation of Array Index vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: spi: cadence: Fix out-of-bounds array access in cdns_mrvl_xspi_setup_clock() If requested_clk > 128, cdns_mrvl_xspi_setup_clock() iterates over the entire cdns_mrvl_xspi_clk_div_list array without breaking out early, causing 'i' to go beyond the array bounds. Fix that by stopping the loop when it gets to the last entry, clamping the clock to the minimum 6.25 MHz. Fixes the following warning with an UBSAN kernel: vmlinux.o: warning: objtool: cdns_mrvl_xspi_setup_clock: unexpected end of section .text.cdns_mrvl_xspi_setup_clock

7.8
2025-04-16 CVE-2025-22068 Linux Use After Free vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ublk: make sure ubq->canceling is set when queue is frozen Now ublk driver depends on `ubq->canceling` for deciding if the request can be dispatched via uring_cmd & io_uring_cmd_complete_in_task(). Once ubq->canceling is set, the uring_cmd can be done via ublk_cancel_cmd() and io_uring_cmd_done(). So set ubq->canceling when queue is frozen, this way makes sure that the flag can be observed from ublk_queue_rq() reliably, and avoids use-after-free on uring_cmd.

7.8
2025-04-16 CVE-2025-22056 Linux Out-of-bounds Write vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix geneve_opt type confusion addition When handling multiple NFTA_TUNNEL_KEY_OPTS_GENEVE attributes, the parsing logic should place every geneve_opt structure one by one compactly.

7.8
2025-04-16 CVE-2025-22020 Linux Use After Free vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove This fixes the following crash: ================================================================== BUG: KASAN: slab-use-after-free in rtsx_usb_ms_poll_card+0x159/0x200 [rtsx_usb_ms] Read of size 8 at addr ffff888136335380 by task kworker/6:0/140241 CPU: 6 UID: 0 PID: 140241 Comm: kworker/6:0 Kdump: loaded Tainted: G E 6.14.0-rc6+ #1 Tainted: [E]=UNSIGNED_MODULE Hardware name: LENOVO 30FNA1V7CW/1057, BIOS S0EKT54A 07/01/2024 Workqueue: events rtsx_usb_ms_poll_card [rtsx_usb_ms] Call Trace: <TASK> dump_stack_lvl+0x51/0x70 print_address_description.constprop.0+0x27/0x320 ? rtsx_usb_ms_poll_card+0x159/0x200 [rtsx_usb_ms] print_report+0x3e/0x70 kasan_report+0xab/0xe0 ? rtsx_usb_ms_poll_card+0x159/0x200 [rtsx_usb_ms] rtsx_usb_ms_poll_card+0x159/0x200 [rtsx_usb_ms] ? __pfx_rtsx_usb_ms_poll_card+0x10/0x10 [rtsx_usb_ms] ? __pfx___schedule+0x10/0x10 ? kick_pool+0x3b/0x270 process_one_work+0x357/0x660 worker_thread+0x390/0x4c0 ? __pfx_worker_thread+0x10/0x10 kthread+0x190/0x1d0 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x2d/0x50 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 </TASK> Allocated by task 161446: kasan_save_stack+0x20/0x40 kasan_save_track+0x10/0x30 __kasan_kmalloc+0x7b/0x90 __kmalloc_noprof+0x1a7/0x470 memstick_alloc_host+0x1f/0xe0 [memstick] rtsx_usb_ms_drv_probe+0x47/0x320 [rtsx_usb_ms] platform_probe+0x60/0xe0 call_driver_probe+0x35/0x120 really_probe+0x123/0x410 __driver_probe_device+0xc7/0x1e0 driver_probe_device+0x49/0xf0 __device_attach_driver+0xc6/0x160 bus_for_each_drv+0xe4/0x160 __device_attach+0x13a/0x2b0 bus_probe_device+0xbd/0xd0 device_add+0x4a5/0x760 platform_device_add+0x189/0x370 mfd_add_device+0x587/0x5e0 mfd_add_devices+0xb1/0x130 rtsx_usb_probe+0x28e/0x2e0 [rtsx_usb] usb_probe_interface+0x15c/0x460 call_driver_probe+0x35/0x120 really_probe+0x123/0x410 __driver_probe_device+0xc7/0x1e0 driver_probe_device+0x49/0xf0 __device_attach_driver+0xc6/0x160 bus_for_each_drv+0xe4/0x160 __device_attach+0x13a/0x2b0 rebind_marked_interfaces.isra.0+0xcc/0x110 usb_reset_device+0x352/0x410 usbdev_do_ioctl+0xe5c/0x1860 usbdev_ioctl+0xa/0x20 __x64_sys_ioctl+0xc5/0xf0 do_syscall_64+0x59/0x170 entry_SYSCALL_64_after_hwframe+0x76/0x7e Freed by task 161506: kasan_save_stack+0x20/0x40 kasan_save_track+0x10/0x30 kasan_save_free_info+0x36/0x60 __kasan_slab_free+0x34/0x50 kfree+0x1fd/0x3b0 device_release+0x56/0xf0 kobject_cleanup+0x73/0x1c0 rtsx_usb_ms_drv_remove+0x13d/0x220 [rtsx_usb_ms] platform_remove+0x2f/0x50 device_release_driver_internal+0x24b/0x2e0 bus_remove_device+0x124/0x1d0 device_del+0x239/0x530 platform_device_del.part.0+0x19/0xe0 platform_device_unregister+0x1c/0x40 mfd_remove_devices_fn+0x167/0x170 device_for_each_child_reverse+0xc9/0x130 mfd_remove_devices+0x6e/0xa0 rtsx_usb_disconnect+0x2e/0xd0 [rtsx_usb] usb_unbind_interface+0xf3/0x3f0 device_release_driver_internal+0x24b/0x2e0 proc_disconnect_claim+0x13d/0x220 usbdev_do_ioctl+0xb5e/0x1860 usbdev_ioctl+0xa/0x20 __x64_sys_ioctl+0xc5/0xf0 do_syscall_64+0x59/0x170 entry_SYSCALL_64_after_hwframe+0x76/0x7e Last potentially related work creation: kasan_save_stack+0x20/0x40 kasan_record_aux_stack+0x85/0x90 insert_work+0x29/0x100 __queue_work+0x34a/0x540 call_timer_fn+0x2a/0x160 expire_timers+0x5f/0x1f0 __run_timer_base.part.0+0x1b6/0x1e0 run_timer_softirq+0x8b/0xe0 handle_softirqs+0xf9/0x360 __irq_exit_rcu+0x114/0x130 sysvec_apic_timer_interrupt+0x72/0x90 asm_sysvec_apic_timer_interrupt+0x16/0x20 Second to last potentially related work creation: kasan_save_stack+0x20/0x40 kasan_record_aux_stack+0x85/0x90 insert_work+0x29/0x100 __queue_work+0x34a/0x540 call_timer_fn+0x2a/0x160 expire_timers+0x5f/0x1f0 __run_timer_base.part.0+0x1b6/0x1e0 run_timer_softirq+0x8b/0xe0 handle_softirqs+0xf9/0x ---truncated---

7.8
2025-04-15 CVE-2025-1273 Autodesk Out-of-bounds Write vulnerability in Autodesk Revit

A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability.

7.8
2025-04-15 CVE-2025-1274 Autodesk Out-of-bounds Write vulnerability in Autodesk Revit

A maliciously crafted RCS file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability.

7.8
2025-04-15 CVE-2025-1275 Autodesk Out-of-bounds Write vulnerability in Autodesk products

A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability.

7.8
2025-04-15 CVE-2025-1277 Autodesk Out-of-bounds Write vulnerability in Autodesk Revit

A maliciously crafted PDF file, when parsed through Autodesk applications, can force a Memory Corruption vulnerability.

7.8
2025-04-15 CVE-2025-1656 Autodesk Out-of-bounds Write vulnerability in Autodesk Revit

A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability.

7.8
2025-04-15 CVE-2025-2497 Autodesk Out-of-bounds Write vulnerability in Autodesk Revit

A maliciously crafted DWG file, when parsed through Autodesk Revit, can cause a Stack-Based Buffer Overflow vulnerability.

7.8
2025-04-15 CVE-2025-33026 Peazip Inclusion of Functionality from Untrusted Control Sphere vulnerability in Peazip 9.4.0

In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability.

7.8
2025-04-15 CVE-2025-33027 Bandisoft Inclusion of Functionality from Untrusted Control Sphere vulnerability in Bandisoft Bandizip

In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability.

7.8
2025-04-20 CVE-2025-43919 GNU Path Traversal vulnerability in GNU Mailman

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter.

7.5
2025-04-19 CVE-2025-2111 The Insert Headers And Footers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1.
7.5
2025-04-19 CVE-2025-3103 The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vulnerable to arbitrary file read due to insufficient file path validation in the 'history.php' file in all versions up to, and including, 2.4.
7.5
2025-04-19 CVE-2025-2010 The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injection via the 'jobwp_upload_resume' parameter in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
7.5
2025-04-18 CVE-2025-29784 Namelessmc Improper Validation of Specified Quantity in Input vulnerability in Namelessmc Nameless

NamelessMC is a free, easy to use & powerful website software for Minecraft servers.

7.5
2025-04-17 CVE-2024-42178 Hcltech Missing Authentication for Critical Function vulnerability in Hcltech Dryice Myxalytics 6.3

HCL MyXalytics is affected by a failure to restrict URL access vulnerability.

7.5
2025-04-17 CVE-2025-32415 Xmlsoft Out-of-bounds Read vulnerability in Xmlsoft Libxml2

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read.

7.5
2025-04-17 CVE-2025-43013 Jetbrains Cleartext Transmission of Sensitive Information vulnerability in Jetbrains Toolbox

In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible

7.5
2025-04-17 CVE-2025-25234 Omnissa Unspecified vulnerability in Omnissa Unified Access Gateway

Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.

7.5
2025-04-15 CVE-2025-32021 Weblate Unspecified vulnerability in Weblate

Weblate is a web based localization tool.

7.5
2025-04-14 CVE-2025-3572 SmartRobot from INTUMIT has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to probe internal network and even access arbitrary local files on the server.
7.5
2025-04-19 CVE-2025-3800 A vulnerability has been found in WCMS 11 and classified as critical.
7.3
2025-04-19 CVE-2025-3799 A vulnerability, which was classified as critical, was found in WCMS 11.
7.3
2025-04-16 CVE-2025-3689 A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical.
7.3
2025-04-14 CVE-2025-3566 A vulnerability, which was classified as critical, has been found in veal98 ??? Echo ?????? 4.2.
7.3
2025-04-19 CVE-2025-3809 The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the auto-refresh debug log in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping.
7.2
2025-04-17 CVE-2025-2947 IBM i 7.6  contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.
7.2
2025-04-17 CVE-2025-3294 The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1.
7.2
2025-04-14 CVE-2025-3563 Wuzhicms Injection vulnerability in Wuzhicms 4.1.0

A vulnerability was found in WuzhiCMS 4.1.

7.2
2025-04-18 CVE-2025-30158 Namelessmc Resource Exhaustion vulnerability in Namelessmc Nameless

NamelessMC is a free, easy to use & powerful website software for Minecraft servers.

7.1
2025-04-18 CVE-2025-31118 Namelessmc Resource Exhaustion vulnerability in Namelessmc Nameless

NamelessMC is a free, easy to use & powerful website software for Minecraft servers.

7.1
2025-04-18 CVE-2025-37785 Linux Out-of-bounds Read vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounting a corrupted filesystem with directory which contains '.' dir entry with rec_len == block size results in out-of-bounds read (later on, when the corrupted directory is removed). ext4_empty_dir() assumes every ext4 directory contains at least '.' and '..' as directory entries in the first data block.

7.1
2025-04-18 CVE-2025-39735 Linux Out-of-bounds Read vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds read in ea_get() During the "size_check" label in ea_get(), the code checks if the extended attribute list (xattr) size matches ea_size.

7.1
2025-04-18 CVE-2025-39778 Linux Out-of-bounds Read vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: objtool, nvmet: Fix out-of-bounds stack access in nvmet_ctrl_state_show() The csts_state_names[] array only has six sparse entries, but the iteration code in nvmet_ctrl_state_show() iterates seven, resulting in a potential out-of-bounds stack read.

7.1
2025-04-16 CVE-2025-22038 Linux Out-of-bounds Read vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate zero num_subauth before sub_auth is accessed Access psid->sub_auth[psid->num_subauth - 1] without checking if num_subauth is non-zero leads to an out-of-bounds read. This patch adds a validation step to ensure num_subauth != 0 before sub_auth is accessed.

7.1
2025-04-16 CVE-2025-22036 Linux Use After Free vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: exfat: fix random stack corruption after get_block When get_block is called with a buffer_head allocated on the stack, such as do_mpage_readpage, stack corruption due to buffer_head UAF may occur in the following race condition situation. <CPU 0> <CPU 1> mpage_read_folio <<bh on stack>> do_mpage_readpage exfat_get_block bh_read __bh_read get_bh(bh) submit_bh wait_on_buffer ... end_buffer_read_sync __end_buffer_read_notouch unlock_buffer <<keep going>> ... ... ... ... <<bh is not valid out of mpage_read_folio>> . . another_function <<variable A on stack>> put_bh(bh) atomic_dec(bh->b_count) * stack corruption here * This patch returns -EAGAIN if a folio does not have buffers when bh_read needs to be called.

7.0

137 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-04-18 CVE-2025-30357 Namelessmc Use of Incorrectly-Resolved Name or Reference vulnerability in Namelessmc Nameless

NamelessMC is a free, easy to use & powerful website software for Minecraft servers.

6.8
2025-04-18 CVE-2025-32389 Namelessmc SQL Injection vulnerability in Namelessmc Nameless

NamelessMC is a free, easy to use & powerful website software for Minecraft servers.

6.5
2025-04-18 CVE-2025-32796 Langgenius Incorrect Authorization vulnerability in Langgenius Dify

Dify is an open-source LLM app development platform.

6.5
2025-04-18 CVE-2025-3787 Pbootcms Unspecified vulnerability in Pbootcms 3.2.5

A vulnerability was found in PbootCMS 3.2.5.

6.5
2025-04-17 CVE-2025-26268 Dragonflydb Unspecified vulnerability in Dragonflydb Dragonfly

DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command.

6.5
2025-04-17 CVE-2025-43014 Jetbrains Missing Critical Step in Authentication vulnerability in Jetbrains Toolbox

In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation

6.5
2025-04-17 CVE-2025-43015 Jetbrains Insecure Default Initialization of Resource vulnerability in Jetbrains Rubymine

In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces

6.5
2025-04-17 CVE-2025-42921 Jetbrains Improper Validation of Certificate with Host Mismatch vulnerability in Jetbrains Toolbox

In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin

6.5
2025-04-16 CVE-2025-0101 A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit.
6.5
2025-04-15 CVE-2025-30717 Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts).
6.5
2025-04-14 CVE-2025-32910 A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference.
6.5
2025-04-19 CVE-2025-3661 The SB Chart block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping.
6.4
2025-04-19 CVE-2025-1457 The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Wrapper Link, Countdown and Gallery widgets in all versions up to, and including, 5.10.28 due to insufficient input sanitization and output escaping.
6.4
2025-04-19 CVE-2025-3275 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping.
6.4
2025-04-18 CVE-2025-3106 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-04-18 CVE-2024-13650 The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before After Image Comparison Slider' widget in all versions up to, and including, 2.4.34 due to insufficient input sanitization and output escaping.
6.4
2025-04-17 CVE-2024-42177 Hcltech Inadequate Encryption Strength vulnerability in Hcltech Dryice Myxalytics 6.3

HCL MyXalytics is affected by SSL/TLS Protocol affected with BREACH & LUCKY13 vulnerabilities.

6.4
2025-04-17 CVE-2025-3487 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘limit’ parameter in all versions up to, and including, 1.42.0 due to insufficient input sanitization and output escaping.
6.4
2025-04-17 CVE-2025-3615 The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping.
6.4
2025-04-16 CVE-2025-3077 The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button shortcode and Custom CSS field in all versions up to, and including, 28.0.3 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-04-16 CVE-2025-2314 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13.5 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-04-15 CVE-2025-2083 The Logo Carousel Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sliderId’ parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping.
6.4
2025-04-15 CVE-2025-2225 The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rael_title_tag' parameter in all versions up to, and including, 1.6.9 due to insufficient input sanitization and output escaping.
6.4
2025-04-19 CVE-2025-3818 A vulnerability, which was classified as critical, was found in webpy web.py 0.70.
6.3
2025-04-19 CVE-2025-3807 A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0.
6.3
2025-04-18 CVE-2025-3796 A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0.
6.3
2025-04-18 CVE-2024-45651 IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.
6.3
2025-04-18 CVE-2024-49808 IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.
6.3
2025-04-16 CVE-2025-3685 A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0.
6.3
2025-04-14 CVE-2025-3593 A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0.
6.3
2025-04-14 CVE-2025-3590 A vulnerability has been found in Adianti Framework up to 8.0 and classified as critical.
6.3
2025-04-14 CVE-2024-49825 IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
6.3
2025-04-14 CVE-2025-3569 A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical.
6.3
2025-04-14 CVE-2025-3558 A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0.
6.3
2025-04-14 CVE-2025-3559 A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical.
6.3
2025-04-14 CVE-2025-3553 A vulnerability was found in phpshe 1.8.
6.3
2025-04-14 CVE-2025-3547 A vulnerability classified as critical was found in frdel Agent-Zero 0.8.1.2.
6.3
2025-04-20 CVE-2020-36844 Knowbe4 Cross-site Scripting vulnerability in Knowbe4 Security Awareness Training

The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS.

6.1
2025-04-20 CVE-2020-36845 Knowbe4 Open Redirect vulnerability in Knowbe4 Security Awareness Training

The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting.

6.1
2025-04-20 CVE-2025-43954 Quasar Cross-site Scripting vulnerability in Quasar Qmarkdown

QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.

6.1
2025-04-18 CVE-2025-3598 The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the commission_summary parameter in all versions up to, and including, .6.3.0 due to insufficient input sanitization and output escaping.
6.1
2025-04-16 CVE-2024-13452 The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.29.
6.1
2025-04-15 CVE-2025-30719 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
6.1
2025-04-15 CVE-2025-30720 Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Orders).
6.1
2025-04-16 CVE-2025-20178 A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system. This vulnerability is due to insufficient integrity checks within device backup files.
6.0
2025-04-16 CVE-2024-22314 IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
5.9
2025-04-14 CVE-2022-43851 IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
5.9
2025-04-15 CVE-2025-30737 Vulnerability in the Oracle Smart View for Office product of Oracle Hyperion (component: Core Smart View).
5.7
2025-04-18 CVE-2025-37860 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_param() Since cited commit, ef100_probe_main() and hence also ef100_check_design_params() run before efx->net_dev is created; consequently, we cannot netif_set_tso_max_size() or _segs() at this point. Move those netif calls to ef100_probe_netdev(), and also replace netif_err within the design params code with pci_err.

5.5
2025-04-18 CVE-2025-37893 Linux Off-by-one Error vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix off-by-one error in build_prologue() Vincent reported that running BPF progs with tailcalls on LoongArch causes kernel hard lockup.

5.5
2025-04-18 CVE-2025-37925 Linux Unspecified vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type Syzbot has reported the following BUG: kernel BUG at fs/inode.c:668! Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 3 UID: 0 PID: 139 Comm: jfsCommit Not tainted 6.12.0-rc4-syzkaller-00085-g4e46774408d9 #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-3.fc41 04/01/2014 RIP: 0010:clear_inode+0x168/0x190 Code: 4c 89 f7 e8 ba fe e5 ff e9 61 ff ff ff 44 89 f1 80 e1 07 80 c1 03 38 c1 7c c1 4c 89 f7 e8 90 ff e5 ff eb b7 0b e8 01 5d 7f ff 90 0f 0b e8 f9 5c 7f ff 90 0f 0b e8 f1 5c 7f RSP: 0018:ffffc900027dfae8 EFLAGS: 00010093 RAX: ffffffff82157a87 RBX: 0000000000000001 RCX: ffff888104d4b980 RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000000 RBP: ffffc900027dfc90 R08: ffffffff82157977 R09: fffff520004fbf38 R10: dffffc0000000000 R11: fffff520004fbf38 R12: dffffc0000000000 R13: ffff88811315bc00 R14: ffff88811315bda8 R15: ffff88811315bb80 FS: 0000000000000000(0000) GS:ffff888135f00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005565222e0578 CR3: 0000000026ef0000 CR4: 00000000000006f0 Call Trace: <TASK> ? __die_body+0x5f/0xb0 ? die+0x9e/0xc0 ? do_trap+0x15a/0x3a0 ? clear_inode+0x168/0x190 ? do_error_trap+0x1dc/0x2c0 ? clear_inode+0x168/0x190 ? __pfx_do_error_trap+0x10/0x10 ? report_bug+0x3cd/0x500 ? handle_invalid_op+0x34/0x40 ? clear_inode+0x168/0x190 ? exc_invalid_op+0x38/0x50 ? asm_exc_invalid_op+0x1a/0x20 ? clear_inode+0x57/0x190 ? clear_inode+0x167/0x190 ? clear_inode+0x168/0x190 ? clear_inode+0x167/0x190 jfs_evict_inode+0xb5/0x440 ? __pfx_jfs_evict_inode+0x10/0x10 evict+0x4ea/0x9b0 ? __pfx_evict+0x10/0x10 ? iput+0x713/0xa50 txUpdateMap+0x931/0xb10 ? __pfx_txUpdateMap+0x10/0x10 jfs_lazycommit+0x49a/0xb80 ? _raw_spin_unlock_irqrestore+0x8f/0x140 ? lockdep_hardirqs_on+0x99/0x150 ? __pfx_jfs_lazycommit+0x10/0x10 ? __pfx_default_wake_function+0x10/0x10 ? __kthread_parkme+0x169/0x1d0 ? __pfx_jfs_lazycommit+0x10/0x10 kthread+0x2f2/0x390 ? __pfx_jfs_lazycommit+0x10/0x10 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x4d/0x80 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 </TASK> This happens when 'clear_inode()' makes an attempt to finalize an underlying JFS inode of unknown type.

5.5
2025-04-18 CVE-2025-38049 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: x86/resctrl: Fix allocation of cleanest CLOSID on platforms with no monitors Commit 6eac36bb9eb0 ("x86/resctrl: Allocate the cleanest CLOSID by searching closid_num_dirty_rmid") added logic that causes resctrl to search for the CLOSID with the fewest dirty cache lines when creating a new control group, if requested by the arch code. This depends on the values read from the llc_occupancy counters.

5.5
2025-04-18 CVE-2025-38152 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdown There is case as below could trigger kernel dump: Use U-Boot to start remote processor(rproc) with resource table published to a fixed address by rproc.

5.5
2025-04-18 CVE-2025-39728 Linux Improper Validation of Array Index vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init() With UBSAN_ARRAY_BOUNDS=y, I'm hitting the below panic due to dereferencing `ctx->clk_data.hws` before setting `ctx->clk_data.num = nr_clks`.

5.5
2025-04-18 CVE-2025-39755 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix cb7210 pcmcia Oops The pcmcia_driver struct was still only using the old .name initialization in the drv field.

5.5
2025-04-17 CVE-2020-36789 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but not always, the case), the 'WARN_ON(in_irq)' in net/core/skbuff.c#skb_release_head_state() might be triggered, under network congestion circumstances, together with the potential risk of a NULL pointer dereference. The root cause of this issue is the call to kfree_skb() instead of dev_kfree_skb_irq() in net/core/dev.c#enqueue_to_backlog(). This patch prevents the skb to be freed within the call to netif_rx() by incrementing its reference count with skb_get().

5.5
2025-04-16 CVE-2025-22065 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: idpf: fix adapter NULL pointer dereference on reboot With SRIOV enabled, idpf ends up calling into idpf_remove() twice. First via idpf_shutdown() and then again when idpf_remove() calls into sriov_disable(), because the VF devices use the idpf driver, hence the same remove routine.

5.5
2025-04-16 CVE-2025-22066 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ASoC: imx-card: Add NULL check in imx_card_probe() devm_kasprintf() returns NULL when memory allocation fails.

5.5
2025-04-16 CVE-2025-22070 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: fs/9p: fix NULL pointer dereference on mkdir When a 9p tree was mounted with option 'posixacl', parent directory had a default ACL set for its subdirectories, e.g.: setfacl -m default:group:simpsons:rwx parentdir then creating a subdirectory crashed 9p client, as v9fs_fid_add() call in function v9fs_vfs_mkdir_dotl() sets the passed 'fid' pointer to NULL (since dafbe689736) even though the subsequent v9fs_set_create_acl() call expects a valid non-NULL 'fid' pointer: [ 37.273191] BUG: kernel NULL pointer dereference, address: 0000000000000000 ... [ 37.322338] Call Trace: [ 37.323043] <TASK> [ 37.323621] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434) [ 37.324448] ? page_fault_oops (arch/x86/mm/fault.c:714) [ 37.325532] ? search_module_extables (kernel/module/main.c:3733) [ 37.326742] ? p9_client_walk (net/9p/client.c:1165) 9pnet [ 37.328006] ? search_bpf_extables (kernel/bpf/core.c:804) [ 37.329142] ? exc_page_fault (./arch/x86/include/asm/paravirt.h:686 arch/x86/mm/fault.c:1488 arch/x86/mm/fault.c:1538) [ 37.330196] ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:574) [ 37.331330] ? p9_client_walk (net/9p/client.c:1165) 9pnet [ 37.332562] ? v9fs_fid_xattr_get (fs/9p/xattr.c:30) 9p [ 37.333824] v9fs_fid_xattr_set (fs/9p/fid.h:23 fs/9p/xattr.c:121) 9p [ 37.335077] v9fs_set_acl (fs/9p/acl.c:276) 9p [ 37.336112] v9fs_set_create_acl (fs/9p/acl.c:307) 9p [ 37.337326] v9fs_vfs_mkdir_dotl (fs/9p/vfs_inode_dotl.c:411) 9p [ 37.338590] vfs_mkdir (fs/namei.c:4313) [ 37.339535] do_mkdirat (fs/namei.c:4336) [ 37.340465] __x64_sys_mkdir (fs/namei.c:4354) [ 37.341455] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) [ 37.342447] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) Fix this by simply swapping the sequence of these two calls in v9fs_vfs_mkdir_dotl(), i.e.

5.5
2025-04-16 CVE-2025-22080 Linux Integer Overflow or Wraparound vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Prevent integer overflow in hdr_first_de() The "de_off" and "used" variables come from the disk so they both need to check.

5.5
2025-04-16 CVE-2025-22081 Linux Integer Overflow or Wraparound vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix a couple integer overflows on 32bit systems On 32bit systems the "off + sizeof(struct NTFS_DE)" addition can have an integer wrapping issue.

5.5
2025-04-16 CVE-2025-23134 Linux Improper Locking vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Don't take register_mutex with copy_from/to_user() The infamous mmap_lock taken in copy_from/to_user() can be often problematic when it's called inside another mutex, as they might lead to deadlocks. In the case of ALSA timer code, the bad pattern is with guard(mutex)(&register_mutex) that covers copy_from/to_user() -- which was mistakenly introduced at converting to guard(), and it had been carefully worked around in the past. This patch fixes those pieces simply by moving copy_from/to_user() out of the register mutex lock again.

5.5
2025-04-16 CVE-2025-23136 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: Add NULL check for adev Not all devices have an ACPI companion fwnode, so adev might be NULL. This is similar to the commit cd2fd6eab480 ("platform/x86: int3472: Check for adev == NULL"). Add a check for adev not being set and return -ENODEV in that case to avoid a possible NULL pointer deref in int3402_thermal_probe(). Note, under the same directory, int3400_thermal_probe() has such a check. [ rjw: Subject edit, added Fixes: ]

5.5
2025-04-16 CVE-2025-23137 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update Check if policy is NULL before dereferencing it in amd_pstate_update.

5.5
2025-04-16 CVE-2024-58097 Linux Infinite Loop vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix RCU stall while reaping monitor destination ring While processing the monitor destination ring, MSDUs are reaped from the link descriptor based on the corresponding buf_id. However, sometimes the driver cannot obtain a valid buffer corresponding to the buf_id received from the hardware.

5.5
2025-04-16 CVE-2025-22024 Linux Use After Free vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix management of listener transports Currently, when no active threads are running, a root user using nfsdctl command can try to remove a particular listener from the list of previously added ones, then start the server by increasing the number of threads, it leads to the following problem: [ 158.835354] refcount_t: addition on 0; use-after-free. [ 158.835603] WARNING: CPU: 2 PID: 9145 at lib/refcount.c:25 refcount_warn_saturate+0x160/0x1a0 [ 158.836017] Modules linked in: rpcrdma rdma_cm iw_cm ib_cm ib_core nfsd auth_rpcgss nfs_acl lockd grace overlay isofs uinput snd_seq_dummy snd_hrtimer nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables qrtr sunrpc vfat fat uvcvideo videobuf2_vmalloc videobuf2_memops uvc videobuf2_v4l2 videodev videobuf2_common snd_hda_codec_generic mc e1000e snd_hda_intel snd_intel_dspcfg snd_hda_codec snd_hda_core snd_hwdep snd_seq snd_seq_device snd_pcm snd_timer snd soundcore sg loop dm_multipath dm_mod nfnetlink vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vmw_vmci vsock xfs libcrc32c crct10dif_ce ghash_ce vmwgfx sha2_ce sha256_arm64 sr_mod sha1_ce cdrom nvme drm_client_lib drm_ttm_helper ttm nvme_core drm_kms_helper nvme_auth drm fuse [ 158.840093] CPU: 2 UID: 0 PID: 9145 Comm: nfsd Kdump: loaded Tainted: G B W 6.13.0-rc6+ #7 [ 158.840624] Tainted: [B]=BAD_PAGE, [W]=WARN [ 158.840802] Hardware name: VMware, Inc.

5.5
2025-04-16 CVE-2025-22031 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: PCI/bwctrl: Fix NULL pointer dereference on bus number exhaustion When BIOS neglects to assign bus numbers to PCI bridges, the kernel attempts to correct that during PCI device enumeration.

5.5
2025-04-16 CVE-2025-22032 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix kernel panic due to null pointer dereference Address a kernel panic caused by a null pointer dereference in the `mt792x_rx_get_wcid` function.

5.5
2025-04-16 CVE-2025-22033 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: arm64: Don't call NULL in do_compat_alignment_fixup() do_alignment_t32_to_handler() only fixes up alignment faults for specific instructions; it returns NULL otherwise (e.g.

5.5
2025-04-16 CVE-2025-22037 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request.

5.5
2025-04-16 CVE-2025-22051 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix Oops after disconnect in agilent usb If the agilent usb dongle is disconnected subsequent calls to the driver cause a NULL dereference Oops as the bus_interface is set to NULL on disconnect. This problem was introduced by setting usb_dev from the bus_interface for dev_xxx messages. Previously bus_interface was checked for NULL only in the functions directly calling usb_fill_bulk_urb or usb_control_msg. Check for valid bus_interface on all interface entry points and return -ENODEV if it is NULL.

5.5
2025-04-16 CVE-2025-22052 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix Oops after disconnect in ni_usb If the usb dongle is disconnected subsequent calls to the driver cause a NULL dereference Oops as the bus_interface is set to NULL on disconnect. This problem was introduced by setting usb_dev from the bus_interface for dev_xxx messages. Previously bus_interface was checked for NULL only in the the functions directly calling usb_fill_bulk_urb or usb_control_msg. Check for valid bus_interface on all interface entry points and return -ENODEV if it is NULL.

5.5
2025-04-16 CVE-2025-22054 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: arcnet: Add NULL check in com20020pci_probe() devm_kasprintf() returns NULL when memory allocation fails.

5.5
2025-04-16 CVE-2025-22059 Linux Integer Overflow or Wraparound vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: udp: Fix multiple wraparounds of sk->sk_rmem_alloc. __udp_enqueue_schedule_skb() has the following condition: if (atomic_read(&sk->sk_rmem_alloc) > sk->sk_rcvbuf) goto drop; sk->sk_rcvbuf is initialised by net.core.rmem_default and later can be configured by SO_RCVBUF, which is limited by net.core.rmem_max, or SO_RCVBUFFORCE. If we set INT_MAX to sk->sk_rcvbuf, the condition is always false as sk->sk_rmem_alloc is also signed int. Then, the size of the incoming skb is added to sk->sk_rmem_alloc unconditionally. This results in integer overflow (possibly multiple times) on sk->sk_rmem_alloc and allows a single socket to have skb up to net.core.udp_mem[1]. For example, if we set a large value to udp_mem[1] and INT_MAX to sk->sk_rcvbuf and flood packets to the socket, we can see multiple overflows: # cat /proc/net/sockstat | grep UDP: UDP: inuse 3 mem 7956736 <-- (7956736 << 12) bytes > INT_MAX * 15 ^- PAGE_SHIFT # ss -uam State Recv-Q ... UNCONN -1757018048 ...

5.5
2025-04-16 CVE-2025-22062 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: sctp: add mutual exclusion in proc_sctp_do_udp_port() We must serialize calls to sctp_udp_sock_stop() and sctp_udp_sock_start() or risk a crash as syzbot reported: Oops: general protection fault, probably for non-canonical address 0xdffffc000000000d: 0000 [#1] SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000068-0x000000000000006f] CPU: 1 UID: 0 PID: 6551 Comm: syz.1.44 Not tainted 6.14.0-syzkaller-g7f2ff7b62617 #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 RIP: 0010:kernel_sock_shutdown+0x47/0x70 net/socket.c:3653 Call Trace: <TASK> udp_tunnel_sock_release+0x68/0x80 net/ipv4/udp_tunnel_core.c:181 sctp_udp_sock_stop+0x71/0x160 net/sctp/protocol.c:930 proc_sctp_do_udp_port+0x264/0x450 net/sctp/sysctl.c:553 proc_sys_call_handler+0x3d0/0x5b0 fs/proc/proc_sysctl.c:601 iter_file_splice_write+0x91c/0x1150 fs/splice.c:738 do_splice_from fs/splice.c:935 [inline] direct_splice_actor+0x18f/0x6c0 fs/splice.c:1158 splice_direct_to_actor+0x342/0xa30 fs/splice.c:1102 do_splice_direct_actor fs/splice.c:1201 [inline] do_splice_direct+0x174/0x240 fs/splice.c:1227 do_sendfile+0xafd/0xe50 fs/read_write.c:1368 __do_sys_sendfile64 fs/read_write.c:1429 [inline] __se_sys_sendfile64 fs/read_write.c:1415 [inline] __x64_sys_sendfile64+0x1d8/0x220 fs/read_write.c:1415 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]

5.5
2025-04-16 CVE-2025-22063 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets When calling netlbl_conn_setattr(), addr->sa_family is used to determine the function behavior.

5.5
2025-04-16 CVE-2025-22018 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: atm: Fix NULL pointer dereference When MPOA_cache_impos_rcvd() receives the msg, it can trigger Null Pointer Dereference Vulnerability if both entry and holding_time are NULL.

5.5
2025-04-20 CVE-2025-3822 Senior Walter Code Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0.

5.4
2025-04-20 CVE-2025-3821 Senior Walter Code Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0.

5.4
2025-04-18 CVE-2025-2950 IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i.
5.4
2025-04-18 CVE-2025-3788 Jsite Cross-site Scripting vulnerability in Jsite 1.0

A vulnerability was found in baseweb JSite 1.0.

5.4
2025-04-18 CVE-2025-3056 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping.
5.4
2025-04-16 CVE-2025-3692 Oretnom23 Code Injection vulnerability in Oretnom23 Online Eyewear Shop 1.0

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0.

5.4
2025-04-15 CVE-2025-30718 Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload).
5.4
2025-04-15 CVE-2025-30723 Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services).
5.4
2025-04-14 CVE-2022-43847 IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.
5.4
2025-04-14 CVE-2022-43850 IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting.
5.4
2025-04-20 CVE-2025-43921 GNU Incorrect Authorization vulnerability in GNU Mailman

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint.

5.3
2025-04-19 CVE-2025-3804 A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1.
5.3
2025-04-19 CVE-2025-3805 A vulnerability classified as critical was found in sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc540ec.
5.3
2025-04-18 CVE-2025-31120 Namelessmc Reliance on Cookies without Validation and Integrity Checking vulnerability in Namelessmc Nameless

NamelessMC is a free, easy to use & powerful website software for Minecraft servers.

5.3
2025-04-18 CVE-2025-3791 A vulnerability classified as critical was found in symisc UnQLite up to 957c377cb691a4f617db9aba5cc46d90425071e2.
5.3
2025-04-18 CVE-2025-3790 A vulnerability classified as critical has been found in baseweb JSite 1.0.
5.3
2025-04-17 CVE-2025-3453 The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.7 via the 'password_protected_cookie' function.
5.3
2025-04-17 CVE-2025-3479 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the 'handle_stripe_single' function due to insufficient validation on a user controlled key.
5.3
2025-04-16 CVE-2025-3728 A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0.
5.3
2025-04-16 CVE-2025-20150 A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of LDAP authentication requests.
5.3
2025-04-16 CVE-2025-3691 Mirweiye Unspecified vulnerability in Mirweiye Seven Bears Library CMS

A vulnerability was found in mirweiye Seven Bears Library CMS 2023.

5.3
2025-04-16 CVE-2025-3104 The WP STAGING Pro WordPress Backup Plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 6.1.2 due to missing capability checks on the getOutdatedPluginsRequest() function.
5.3
2025-04-16 CVE-2025-3677 A vulnerability classified as critical was found in lm-sys fastchat up to 0.2.36.
5.3
2025-04-16 CVE-2025-3675 Totolink Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513.

5.3
2025-04-16 CVE-2025-3247 The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due to insufficient validation on a user controlled key.
5.3
2025-04-16 CVE-2025-3667 Totolink Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513.

5.3
2025-04-16 CVE-2025-3668 Totolink Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513.

5.3
2025-04-16 CVE-2025-3666 Totolink Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical.

5.3
2025-04-14 CVE-2022-43852 IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system.
5.3
2025-04-14 CVE-2025-3588 A vulnerability, which was classified as problematic, has been found in joelittlejohn jsonschema2pojo 1.2.2.
5.3
2025-04-14 CVE-2025-32909 A flaw was found in libsoup.
5.3
2025-04-14 CVE-2025-3548 A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp up to 5.4.3.
5.3
2025-04-14 CVE-2025-3549 A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3.
5.3
2025-04-17 CVE-2025-3295 The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1.
4.9
2025-04-15 CVE-2025-3470 The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s parameter in all versions up to, and including, 2.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
4.9
2025-04-19 CVE-2025-3816 A vulnerability classified as critical was found in westboy CicadasCMS 2.0.
4.7
2025-04-19 CVE-2025-3798 A vulnerability, which was classified as critical, has been found in WCMS 11.
4.7
2025-04-19 CVE-2025-3797 A vulnerability classified as critical was found in SeaCMS up to 13.3.
4.7
2025-04-18 CVE-2025-3792 A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3.
4.7
2025-04-16 CVE-2025-22027 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: media: streamzap: fix race between device disconnection and urb callback Syzkaller has reported a general protection fault at function ir_raw_event_store_with_filter().

4.7
2025-04-14 CVE-2025-3565 A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0.
4.7
2025-04-18 CVE-2025-2613 The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom logo and background URLs in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping.
4.4
2025-04-19 CVE-2025-3808 A vulnerability has been found in zhenfeng13 My-BBS 1.0 and classified as problematic.
4.3
2025-04-19 CVE-2025-3284 The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.3.
4.3
2025-04-16 CVE-2025-32783 Xwiki Unspecified vulnerability in Xwiki

XWiki Platform is a generic wiki platform.

4.3
2025-04-16 CVE-2025-3686 A vulnerability classified as problematic was found in misstt123 oasys 1.0.
4.3
2025-04-16 CVE-2025-3687 A vulnerability, which was classified as problematic, has been found in misstt123 oasys 1.0.
4.3
2025-04-15 CVE-2025-3612 A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7.
4.3
2025-04-14 CVE-2025-3567 A vulnerability, which was classified as problematic, was found in veal98 ??? Echo ?????? 4.2.
4.3
2025-04-14 CVE-2025-3564 A vulnerability classified as problematic has been found in huanfenz/code-projects StudentManager up to 1.0.
4.3
2025-04-14 CVE-2025-3562 A vulnerability was found in Yonyou YonBIP MA2.7.
4.3
2025-04-14 CVE-2025-3561 A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0.
4.3
2025-04-14 CVE-2025-3557 A vulnerability, which was classified as problematic, has been found in ScriptAndTools eCommerce-website-in-PHP 3.0.
4.3
2025-04-14 CVE-2025-3554 A vulnerability was found in phpshe 1.8.
4.3
2025-04-14 CVE-2025-3550 A vulnerability has been found in wowjoy ?????????????? Internet Doctor Workstation System 1.0 and classified as problematic.
4.3
2025-04-20 CVE-2025-3826 Senior Walter Code Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0

A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0.

4.1
2025-04-20 CVE-2025-3825 Senior Walter Code Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0

A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0.

4.1
2025-04-20 CVE-2025-3823 Senior Walter Code Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0

A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System 1.0.

4.1
2025-04-20 CVE-2025-3824 Senior Walter Code Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0

A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0.

4.1
2025-04-15 CVE-2025-30721 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF).
4.0

12 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-04-17 CVE-2025-29931 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2).
3.7
2025-04-18 CVE-2025-3789 A vulnerability was found in baseweb JSite 1.0.
3.5
2025-04-15 CVE-2025-3613 A vulnerability has been found in Demtec Graphytics 5.0.7 and classified as problematic.
3.5
2025-04-14 CVE-2025-3591 A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic.
3.5
2025-04-14 CVE-2025-3592 A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0.
3.5
2025-04-14 CVE-2025-3570 A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0.
3.5
2025-04-14 CVE-2025-3568 A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic.
3.5
2025-04-14 CVE-2025-3560 A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0 and classified as problematic.
3.5
2025-04-14 CVE-2023-27272 IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.
3.1
2025-04-15 CVE-2024-45712 SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability.
2.6
2025-04-19 CVE-2025-3806 A vulnerability, which was classified as problematic, has been found in dazhouda lecms up to 3.0.3.
2.4
2025-04-16 CVE-2025-3688 A vulnerability, which was classified as problematic, was found in mirweiye Seven Bears Library CMS 2023.
2.4