Weekly Vulnerabilities Reports > April 14 to 20, 2025
Overview
309 new vulnerabilities reported during this period, including 33 critical vulnerabilities and 127 high severity vulnerabilities. This weekly summary report vulnerabilities in 49 products from 36 vendors including Linux, Senior Walter, Pcman, Namelessmc, and Autodesk. Vulnerabilities are notably categorized as "SQL Injection", "Injection", "NULL Pointer Dereference", "Cross-site Scripting", and "Code Injection".
- 242 reported vulnerabilities are remotely exploitables.
- 1 reported vulnerabilities have public exploit available.
- 117 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 96 reported vulnerabilities are exploitable by an anonymous user.
- Linux has the most reported vulnerabilities, with 41 reported vulnerabilities.
- Pcman has the most reported critical vulnerabilities, with 12 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
33 Critical Vulnerabilities
127 High Vulnerabilities
137 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2025-04-18 | CVE-2025-30357 | Namelessmc | Use of Incorrectly-Resolved Name or Reference vulnerability in Namelessmc Nameless NamelessMC is a free, easy to use & powerful website software for Minecraft servers. | 6.8 |
2025-04-18 | CVE-2025-32389 | Namelessmc | SQL Injection vulnerability in Namelessmc Nameless NamelessMC is a free, easy to use & powerful website software for Minecraft servers. | 6.5 |
2025-04-18 | CVE-2025-32796 | Langgenius | Incorrect Authorization vulnerability in Langgenius Dify Dify is an open-source LLM app development platform. | 6.5 |
2025-04-18 | CVE-2025-3787 | Pbootcms | Unspecified vulnerability in Pbootcms 3.2.5 A vulnerability was found in PbootCMS 3.2.5. | 6.5 |
2025-04-17 | CVE-2025-26268 | Dragonflydb | Unspecified vulnerability in Dragonflydb Dragonfly DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. | 6.5 |
2025-04-17 | CVE-2025-43014 | Jetbrains | Missing Critical Step in Authentication vulnerability in Jetbrains Toolbox In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation | 6.5 |
2025-04-17 | CVE-2025-43015 | Jetbrains | Insecure Default Initialization of Resource vulnerability in Jetbrains Rubymine In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces | 6.5 |
2025-04-17 | CVE-2025-42921 | Jetbrains | Improper Validation of Certificate with Host Mismatch vulnerability in Jetbrains Toolbox In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin | 6.5 |
2025-04-16 | CVE-2025-0101 | A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. | 6.5 | |
2025-04-15 | CVE-2025-30717 | Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). | 6.5 | |
2025-04-14 | CVE-2025-32910 | A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. | 6.5 | |
2025-04-19 | CVE-2025-3661 | The SB Chart block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. | 6.4 | |
2025-04-19 | CVE-2025-1457 | The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Wrapper Link, Countdown and Gallery widgets in all versions up to, and including, 5.10.28 due to insufficient input sanitization and output escaping. | 6.4 | |
2025-04-19 | CVE-2025-3275 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. | 6.4 | |
2025-04-18 | CVE-2025-3106 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-04-18 | CVE-2024-13650 | The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before After Image Comparison Slider' widget in all versions up to, and including, 2.4.34 due to insufficient input sanitization and output escaping. | 6.4 | |
2025-04-17 | CVE-2024-42177 | Hcltech | Inadequate Encryption Strength vulnerability in Hcltech Dryice Myxalytics 6.3 HCL MyXalytics is affected by SSL/TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. | 6.4 |
2025-04-17 | CVE-2025-3487 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘limit’ parameter in all versions up to, and including, 1.42.0 due to insufficient input sanitization and output escaping. | 6.4 | |
2025-04-17 | CVE-2025-3615 | The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. | 6.4 | |
2025-04-16 | CVE-2025-3077 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button shortcode and Custom CSS field in all versions up to, and including, 28.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-04-16 | CVE-2025-2314 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13.5 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-04-15 | CVE-2025-2083 | The Logo Carousel Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sliderId’ parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. | 6.4 | |
2025-04-15 | CVE-2025-2225 | The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rael_title_tag' parameter in all versions up to, and including, 1.6.9 due to insufficient input sanitization and output escaping. | 6.4 | |
2025-04-19 | CVE-2025-3818 | A vulnerability, which was classified as critical, was found in webpy web.py 0.70. | 6.3 | |
2025-04-19 | CVE-2025-3807 | A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. | 6.3 | |
2025-04-18 | CVE-2025-3796 | A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. | 6.3 | |
2025-04-18 | CVE-2024-45651 | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system. | 6.3 | |
2025-04-18 | CVE-2024-49808 | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions. | 6.3 | |
2025-04-16 | CVE-2025-3685 | A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. | 6.3 | |
2025-04-14 | CVE-2025-3593 | A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. | 6.3 | |
2025-04-14 | CVE-2025-3590 | A vulnerability has been found in Adianti Framework up to 8.0 and classified as critical. | 6.3 | |
2025-04-14 | CVE-2024-49825 | IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system. | 6.3 | |
2025-04-14 | CVE-2025-3569 | A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical. | 6.3 | |
2025-04-14 | CVE-2025-3558 | A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. | 6.3 | |
2025-04-14 | CVE-2025-3559 | A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. | 6.3 | |
2025-04-14 | CVE-2025-3553 | A vulnerability was found in phpshe 1.8. | 6.3 | |
2025-04-14 | CVE-2025-3547 | A vulnerability classified as critical was found in frdel Agent-Zero 0.8.1.2. | 6.3 | |
2025-04-20 | CVE-2020-36844 | Knowbe4 | Cross-site Scripting vulnerability in Knowbe4 Security Awareness Training The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS. | 6.1 |
2025-04-20 | CVE-2020-36845 | Knowbe4 | Open Redirect vulnerability in Knowbe4 Security Awareness Training The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. | 6.1 |
2025-04-20 | CVE-2025-43954 | Quasar | Cross-site Scripting vulnerability in Quasar Qmarkdown QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set. | 6.1 |
2025-04-18 | CVE-2025-3598 | The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the commission_summary parameter in all versions up to, and including, .6.3.0 due to insufficient input sanitization and output escaping. | 6.1 | |
2025-04-16 | CVE-2024-13452 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.29. | 6.1 | |
2025-04-15 | CVE-2025-30719 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). | 6.1 | |
2025-04-15 | CVE-2025-30720 | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Orders). | 6.1 | |
2025-04-16 | CVE-2025-20178 | A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system. This vulnerability is due to insufficient integrity checks within device backup files. | 6.0 | |
2025-04-16 | CVE-2024-22314 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 5.9 | |
2025-04-14 | CVE-2022-43851 | IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 5.9 | |
2025-04-15 | CVE-2025-30737 | Vulnerability in the Oracle Smart View for Office product of Oracle Hyperion (component: Core Smart View). | 5.7 | |
2025-04-18 | CVE-2025-37860 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_param() Since cited commit, ef100_probe_main() and hence also ef100_check_design_params() run before efx->net_dev is created; consequently, we cannot netif_set_tso_max_size() or _segs() at this point. Move those netif calls to ef100_probe_netdev(), and also replace netif_err within the design params code with pci_err. | 5.5 |
2025-04-18 | CVE-2025-37893 | Linux | Off-by-one Error vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix off-by-one error in build_prologue() Vincent reported that running BPF progs with tailcalls on LoongArch causes kernel hard lockup. | 5.5 |
2025-04-18 | CVE-2025-37925 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type Syzbot has reported the following BUG: kernel BUG at fs/inode.c:668! Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 3 UID: 0 PID: 139 Comm: jfsCommit Not tainted 6.12.0-rc4-syzkaller-00085-g4e46774408d9 #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-3.fc41 04/01/2014 RIP: 0010:clear_inode+0x168/0x190 Code: 4c 89 f7 e8 ba fe e5 ff e9 61 ff ff ff 44 89 f1 80 e1 07 80 c1 03 38 c1 7c c1 4c 89 f7 e8 90 ff e5 ff eb b7 0b e8 01 5d 7f ff 90 0f 0b e8 f9 5c 7f ff 90 0f 0b e8 f1 5c 7f RSP: 0018:ffffc900027dfae8 EFLAGS: 00010093 RAX: ffffffff82157a87 RBX: 0000000000000001 RCX: ffff888104d4b980 RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000000 RBP: ffffc900027dfc90 R08: ffffffff82157977 R09: fffff520004fbf38 R10: dffffc0000000000 R11: fffff520004fbf38 R12: dffffc0000000000 R13: ffff88811315bc00 R14: ffff88811315bda8 R15: ffff88811315bb80 FS: 0000000000000000(0000) GS:ffff888135f00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005565222e0578 CR3: 0000000026ef0000 CR4: 00000000000006f0 Call Trace: <TASK> ? __die_body+0x5f/0xb0 ? die+0x9e/0xc0 ? do_trap+0x15a/0x3a0 ? clear_inode+0x168/0x190 ? do_error_trap+0x1dc/0x2c0 ? clear_inode+0x168/0x190 ? __pfx_do_error_trap+0x10/0x10 ? report_bug+0x3cd/0x500 ? handle_invalid_op+0x34/0x40 ? clear_inode+0x168/0x190 ? exc_invalid_op+0x38/0x50 ? asm_exc_invalid_op+0x1a/0x20 ? clear_inode+0x57/0x190 ? clear_inode+0x167/0x190 ? clear_inode+0x168/0x190 ? clear_inode+0x167/0x190 jfs_evict_inode+0xb5/0x440 ? __pfx_jfs_evict_inode+0x10/0x10 evict+0x4ea/0x9b0 ? __pfx_evict+0x10/0x10 ? iput+0x713/0xa50 txUpdateMap+0x931/0xb10 ? __pfx_txUpdateMap+0x10/0x10 jfs_lazycommit+0x49a/0xb80 ? _raw_spin_unlock_irqrestore+0x8f/0x140 ? lockdep_hardirqs_on+0x99/0x150 ? __pfx_jfs_lazycommit+0x10/0x10 ? __pfx_default_wake_function+0x10/0x10 ? __kthread_parkme+0x169/0x1d0 ? __pfx_jfs_lazycommit+0x10/0x10 kthread+0x2f2/0x390 ? __pfx_jfs_lazycommit+0x10/0x10 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x4d/0x80 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 </TASK> This happens when 'clear_inode()' makes an attempt to finalize an underlying JFS inode of unknown type. | 5.5 |
2025-04-18 | CVE-2025-38049 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: x86/resctrl: Fix allocation of cleanest CLOSID on platforms with no monitors Commit 6eac36bb9eb0 ("x86/resctrl: Allocate the cleanest CLOSID by searching closid_num_dirty_rmid") added logic that causes resctrl to search for the CLOSID with the fewest dirty cache lines when creating a new control group, if requested by the arch code. This depends on the values read from the llc_occupancy counters. | 5.5 |
2025-04-18 | CVE-2025-38152 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdown There is case as below could trigger kernel dump: Use U-Boot to start remote processor(rproc) with resource table published to a fixed address by rproc. | 5.5 |
2025-04-18 | CVE-2025-39728 | Linux | Improper Validation of Array Index vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init() With UBSAN_ARRAY_BOUNDS=y, I'm hitting the below panic due to dereferencing `ctx->clk_data.hws` before setting `ctx->clk_data.num = nr_clks`. | 5.5 |
2025-04-18 | CVE-2025-39755 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix cb7210 pcmcia Oops The pcmcia_driver struct was still only using the old .name initialization in the drv field. | 5.5 |
2025-04-17 | CVE-2020-36789 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but not always, the case), the 'WARN_ON(in_irq)' in net/core/skbuff.c#skb_release_head_state() might be triggered, under network congestion circumstances, together with the potential risk of a NULL pointer dereference. The root cause of this issue is the call to kfree_skb() instead of dev_kfree_skb_irq() in net/core/dev.c#enqueue_to_backlog(). This patch prevents the skb to be freed within the call to netif_rx() by incrementing its reference count with skb_get(). | 5.5 |
2025-04-16 | CVE-2025-22065 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: idpf: fix adapter NULL pointer dereference on reboot With SRIOV enabled, idpf ends up calling into idpf_remove() twice. First via idpf_shutdown() and then again when idpf_remove() calls into sriov_disable(), because the VF devices use the idpf driver, hence the same remove routine. | 5.5 |
2025-04-16 | CVE-2025-22066 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: ASoC: imx-card: Add NULL check in imx_card_probe() devm_kasprintf() returns NULL when memory allocation fails. | 5.5 |
2025-04-16 | CVE-2025-22070 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: fs/9p: fix NULL pointer dereference on mkdir When a 9p tree was mounted with option 'posixacl', parent directory had a default ACL set for its subdirectories, e.g.: setfacl -m default:group:simpsons:rwx parentdir then creating a subdirectory crashed 9p client, as v9fs_fid_add() call in function v9fs_vfs_mkdir_dotl() sets the passed 'fid' pointer to NULL (since dafbe689736) even though the subsequent v9fs_set_create_acl() call expects a valid non-NULL 'fid' pointer: [ 37.273191] BUG: kernel NULL pointer dereference, address: 0000000000000000 ... [ 37.322338] Call Trace: [ 37.323043] <TASK> [ 37.323621] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434) [ 37.324448] ? page_fault_oops (arch/x86/mm/fault.c:714) [ 37.325532] ? search_module_extables (kernel/module/main.c:3733) [ 37.326742] ? p9_client_walk (net/9p/client.c:1165) 9pnet [ 37.328006] ? search_bpf_extables (kernel/bpf/core.c:804) [ 37.329142] ? exc_page_fault (./arch/x86/include/asm/paravirt.h:686 arch/x86/mm/fault.c:1488 arch/x86/mm/fault.c:1538) [ 37.330196] ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:574) [ 37.331330] ? p9_client_walk (net/9p/client.c:1165) 9pnet [ 37.332562] ? v9fs_fid_xattr_get (fs/9p/xattr.c:30) 9p [ 37.333824] v9fs_fid_xattr_set (fs/9p/fid.h:23 fs/9p/xattr.c:121) 9p [ 37.335077] v9fs_set_acl (fs/9p/acl.c:276) 9p [ 37.336112] v9fs_set_create_acl (fs/9p/acl.c:307) 9p [ 37.337326] v9fs_vfs_mkdir_dotl (fs/9p/vfs_inode_dotl.c:411) 9p [ 37.338590] vfs_mkdir (fs/namei.c:4313) [ 37.339535] do_mkdirat (fs/namei.c:4336) [ 37.340465] __x64_sys_mkdir (fs/namei.c:4354) [ 37.341455] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) [ 37.342447] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) Fix this by simply swapping the sequence of these two calls in v9fs_vfs_mkdir_dotl(), i.e. | 5.5 |
2025-04-16 | CVE-2025-22080 | Linux | Integer Overflow or Wraparound vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Prevent integer overflow in hdr_first_de() The "de_off" and "used" variables come from the disk so they both need to check. | 5.5 |
2025-04-16 | CVE-2025-22081 | Linux | Integer Overflow or Wraparound vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix a couple integer overflows on 32bit systems On 32bit systems the "off + sizeof(struct NTFS_DE)" addition can have an integer wrapping issue. | 5.5 |
2025-04-16 | CVE-2025-23134 | Linux | Improper Locking vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Don't take register_mutex with copy_from/to_user() The infamous mmap_lock taken in copy_from/to_user() can be often problematic when it's called inside another mutex, as they might lead to deadlocks. In the case of ALSA timer code, the bad pattern is with guard(mutex)(®ister_mutex) that covers copy_from/to_user() -- which was mistakenly introduced at converting to guard(), and it had been carefully worked around in the past. This patch fixes those pieces simply by moving copy_from/to_user() out of the register mutex lock again. | 5.5 |
2025-04-16 | CVE-2025-23136 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: Add NULL check for adev Not all devices have an ACPI companion fwnode, so adev might be NULL. This is similar to the commit cd2fd6eab480 ("platform/x86: int3472: Check for adev == NULL"). Add a check for adev not being set and return -ENODEV in that case to avoid a possible NULL pointer deref in int3402_thermal_probe(). Note, under the same directory, int3400_thermal_probe() has such a check. [ rjw: Subject edit, added Fixes: ] | 5.5 |
2025-04-16 | CVE-2025-23137 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update Check if policy is NULL before dereferencing it in amd_pstate_update. | 5.5 |
2025-04-16 | CVE-2024-58097 | Linux | Infinite Loop vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix RCU stall while reaping monitor destination ring While processing the monitor destination ring, MSDUs are reaped from the link descriptor based on the corresponding buf_id. However, sometimes the driver cannot obtain a valid buffer corresponding to the buf_id received from the hardware. | 5.5 |
2025-04-16 | CVE-2025-22024 | Linux | Use After Free vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: fix management of listener transports Currently, when no active threads are running, a root user using nfsdctl command can try to remove a particular listener from the list of previously added ones, then start the server by increasing the number of threads, it leads to the following problem: [ 158.835354] refcount_t: addition on 0; use-after-free. [ 158.835603] WARNING: CPU: 2 PID: 9145 at lib/refcount.c:25 refcount_warn_saturate+0x160/0x1a0 [ 158.836017] Modules linked in: rpcrdma rdma_cm iw_cm ib_cm ib_core nfsd auth_rpcgss nfs_acl lockd grace overlay isofs uinput snd_seq_dummy snd_hrtimer nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables qrtr sunrpc vfat fat uvcvideo videobuf2_vmalloc videobuf2_memops uvc videobuf2_v4l2 videodev videobuf2_common snd_hda_codec_generic mc e1000e snd_hda_intel snd_intel_dspcfg snd_hda_codec snd_hda_core snd_hwdep snd_seq snd_seq_device snd_pcm snd_timer snd soundcore sg loop dm_multipath dm_mod nfnetlink vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vmw_vmci vsock xfs libcrc32c crct10dif_ce ghash_ce vmwgfx sha2_ce sha256_arm64 sr_mod sha1_ce cdrom nvme drm_client_lib drm_ttm_helper ttm nvme_core drm_kms_helper nvme_auth drm fuse [ 158.840093] CPU: 2 UID: 0 PID: 9145 Comm: nfsd Kdump: loaded Tainted: G B W 6.13.0-rc6+ #7 [ 158.840624] Tainted: [B]=BAD_PAGE, [W]=WARN [ 158.840802] Hardware name: VMware, Inc. | 5.5 |
2025-04-16 | CVE-2025-22031 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: PCI/bwctrl: Fix NULL pointer dereference on bus number exhaustion When BIOS neglects to assign bus numbers to PCI bridges, the kernel attempts to correct that during PCI device enumeration. | 5.5 |
2025-04-16 | CVE-2025-22032 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix kernel panic due to null pointer dereference Address a kernel panic caused by a null pointer dereference in the `mt792x_rx_get_wcid` function. | 5.5 |
2025-04-16 | CVE-2025-22033 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: arm64: Don't call NULL in do_compat_alignment_fixup() do_alignment_t32_to_handler() only fixes up alignment faults for specific instructions; it returns NULL otherwise (e.g. | 5.5 |
2025-04-16 | CVE-2025-22037 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request. | 5.5 |
2025-04-16 | CVE-2025-22051 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix Oops after disconnect in agilent usb If the agilent usb dongle is disconnected subsequent calls to the driver cause a NULL dereference Oops as the bus_interface is set to NULL on disconnect. This problem was introduced by setting usb_dev from the bus_interface for dev_xxx messages. Previously bus_interface was checked for NULL only in the functions directly calling usb_fill_bulk_urb or usb_control_msg. Check for valid bus_interface on all interface entry points and return -ENODEV if it is NULL. | 5.5 |
2025-04-16 | CVE-2025-22052 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix Oops after disconnect in ni_usb If the usb dongle is disconnected subsequent calls to the driver cause a NULL dereference Oops as the bus_interface is set to NULL on disconnect. This problem was introduced by setting usb_dev from the bus_interface for dev_xxx messages. Previously bus_interface was checked for NULL only in the the functions directly calling usb_fill_bulk_urb or usb_control_msg. Check for valid bus_interface on all interface entry points and return -ENODEV if it is NULL. | 5.5 |
2025-04-16 | CVE-2025-22054 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: arcnet: Add NULL check in com20020pci_probe() devm_kasprintf() returns NULL when memory allocation fails. | 5.5 |
2025-04-16 | CVE-2025-22059 | Linux | Integer Overflow or Wraparound vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: udp: Fix multiple wraparounds of sk->sk_rmem_alloc. __udp_enqueue_schedule_skb() has the following condition: if (atomic_read(&sk->sk_rmem_alloc) > sk->sk_rcvbuf) goto drop; sk->sk_rcvbuf is initialised by net.core.rmem_default and later can be configured by SO_RCVBUF, which is limited by net.core.rmem_max, or SO_RCVBUFFORCE. If we set INT_MAX to sk->sk_rcvbuf, the condition is always false as sk->sk_rmem_alloc is also signed int. Then, the size of the incoming skb is added to sk->sk_rmem_alloc unconditionally. This results in integer overflow (possibly multiple times) on sk->sk_rmem_alloc and allows a single socket to have skb up to net.core.udp_mem[1]. For example, if we set a large value to udp_mem[1] and INT_MAX to sk->sk_rcvbuf and flood packets to the socket, we can see multiple overflows: # cat /proc/net/sockstat | grep UDP: UDP: inuse 3 mem 7956736 <-- (7956736 << 12) bytes > INT_MAX * 15 ^- PAGE_SHIFT # ss -uam State Recv-Q ... UNCONN -1757018048 ... | 5.5 |
2025-04-16 | CVE-2025-22062 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: sctp: add mutual exclusion in proc_sctp_do_udp_port() We must serialize calls to sctp_udp_sock_stop() and sctp_udp_sock_start() or risk a crash as syzbot reported: Oops: general protection fault, probably for non-canonical address 0xdffffc000000000d: 0000 [#1] SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000068-0x000000000000006f] CPU: 1 UID: 0 PID: 6551 Comm: syz.1.44 Not tainted 6.14.0-syzkaller-g7f2ff7b62617 #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 RIP: 0010:kernel_sock_shutdown+0x47/0x70 net/socket.c:3653 Call Trace: <TASK> udp_tunnel_sock_release+0x68/0x80 net/ipv4/udp_tunnel_core.c:181 sctp_udp_sock_stop+0x71/0x160 net/sctp/protocol.c:930 proc_sctp_do_udp_port+0x264/0x450 net/sctp/sysctl.c:553 proc_sys_call_handler+0x3d0/0x5b0 fs/proc/proc_sysctl.c:601 iter_file_splice_write+0x91c/0x1150 fs/splice.c:738 do_splice_from fs/splice.c:935 [inline] direct_splice_actor+0x18f/0x6c0 fs/splice.c:1158 splice_direct_to_actor+0x342/0xa30 fs/splice.c:1102 do_splice_direct_actor fs/splice.c:1201 [inline] do_splice_direct+0x174/0x240 fs/splice.c:1227 do_sendfile+0xafd/0xe50 fs/read_write.c:1368 __do_sys_sendfile64 fs/read_write.c:1429 [inline] __se_sys_sendfile64 fs/read_write.c:1415 [inline] __x64_sys_sendfile64+0x1d8/0x220 fs/read_write.c:1415 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] | 5.5 |
2025-04-16 | CVE-2025-22063 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets When calling netlbl_conn_setattr(), addr->sa_family is used to determine the function behavior. | 5.5 |
2025-04-16 | CVE-2025-22018 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: atm: Fix NULL pointer dereference When MPOA_cache_impos_rcvd() receives the msg, it can trigger Null Pointer Dereference Vulnerability if both entry and holding_time are NULL. | 5.5 |
2025-04-20 | CVE-2025-3822 | Senior Walter | Code Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0 A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. | 5.4 |
2025-04-20 | CVE-2025-3821 | Senior Walter | Code Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0 A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. | 5.4 |
2025-04-18 | CVE-2025-2950 | IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. | 5.4 | |
2025-04-18 | CVE-2025-3788 | Jsite | Cross-site Scripting vulnerability in Jsite 1.0 A vulnerability was found in baseweb JSite 1.0. | 5.4 |
2025-04-18 | CVE-2025-3056 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. | 5.4 | |
2025-04-16 | CVE-2025-3692 | Oretnom23 | Code Injection vulnerability in Oretnom23 Online Eyewear Shop 1.0 A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. | 5.4 |
2025-04-15 | CVE-2025-30718 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). | 5.4 | |
2025-04-15 | CVE-2025-30723 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). | 5.4 | |
2025-04-14 | CVE-2022-43847 | IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. | 5.4 | |
2025-04-14 | CVE-2022-43850 | IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. | 5.4 | |
2025-04-20 | CVE-2025-43921 | GNU | Incorrect Authorization vulnerability in GNU Mailman GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. | 5.3 |
2025-04-19 | CVE-2025-3804 | A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. | 5.3 | |
2025-04-19 | CVE-2025-3805 | A vulnerability classified as critical was found in sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc540ec. | 5.3 | |
2025-04-18 | CVE-2025-31120 | Namelessmc | Reliance on Cookies without Validation and Integrity Checking vulnerability in Namelessmc Nameless NamelessMC is a free, easy to use & powerful website software for Minecraft servers. | 5.3 |
2025-04-18 | CVE-2025-3791 | A vulnerability classified as critical was found in symisc UnQLite up to 957c377cb691a4f617db9aba5cc46d90425071e2. | 5.3 | |
2025-04-18 | CVE-2025-3790 | A vulnerability classified as critical has been found in baseweb JSite 1.0. | 5.3 | |
2025-04-17 | CVE-2025-3453 | The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.7 via the 'password_protected_cookie' function. | 5.3 | |
2025-04-17 | CVE-2025-3479 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the 'handle_stripe_single' function due to insufficient validation on a user controlled key. | 5.3 | |
2025-04-16 | CVE-2025-3728 | A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0. | 5.3 | |
2025-04-16 | CVE-2025-20150 | A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of LDAP authentication requests. | 5.3 | |
2025-04-16 | CVE-2025-3691 | Mirweiye | Unspecified vulnerability in Mirweiye Seven Bears Library CMS A vulnerability was found in mirweiye Seven Bears Library CMS 2023. | 5.3 |
2025-04-16 | CVE-2025-3104 | The WP STAGING Pro WordPress Backup Plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 6.1.2 due to missing capability checks on the getOutdatedPluginsRequest() function. | 5.3 | |
2025-04-16 | CVE-2025-3677 | A vulnerability classified as critical was found in lm-sys fastchat up to 0.2.36. | 5.3 | |
2025-04-16 | CVE-2025-3675 | Totolink | Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513 A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. | 5.3 |
2025-04-16 | CVE-2025-3247 | The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due to insufficient validation on a user controlled key. | 5.3 | |
2025-04-16 | CVE-2025-3667 | Totolink | Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513 A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. | 5.3 |
2025-04-16 | CVE-2025-3668 | Totolink | Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513 A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. | 5.3 |
2025-04-16 | CVE-2025-3666 | Totolink | Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513 A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. | 5.3 |
2025-04-14 | CVE-2022-43852 | IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system. | 5.3 | |
2025-04-14 | CVE-2025-3588 | A vulnerability, which was classified as problematic, has been found in joelittlejohn jsonschema2pojo 1.2.2. | 5.3 | |
2025-04-14 | CVE-2025-32909 | A flaw was found in libsoup. | 5.3 | |
2025-04-14 | CVE-2025-3548 | A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp up to 5.4.3. | 5.3 | |
2025-04-14 | CVE-2025-3549 | A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. | 5.3 | |
2025-04-17 | CVE-2025-3295 | The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. | 4.9 | |
2025-04-15 | CVE-2025-3470 | The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s parameter in all versions up to, and including, 2.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 4.9 | |
2025-04-19 | CVE-2025-3816 | A vulnerability classified as critical was found in westboy CicadasCMS 2.0. | 4.7 | |
2025-04-19 | CVE-2025-3798 | A vulnerability, which was classified as critical, has been found in WCMS 11. | 4.7 | |
2025-04-19 | CVE-2025-3797 | A vulnerability classified as critical was found in SeaCMS up to 13.3. | 4.7 | |
2025-04-18 | CVE-2025-3792 | A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. | 4.7 | |
2025-04-16 | CVE-2025-22027 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: media: streamzap: fix race between device disconnection and urb callback Syzkaller has reported a general protection fault at function ir_raw_event_store_with_filter(). | 4.7 |
2025-04-14 | CVE-2025-3565 | A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. | 4.7 | |
2025-04-18 | CVE-2025-2613 | The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom logo and background URLs in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. | 4.4 | |
2025-04-19 | CVE-2025-3808 | A vulnerability has been found in zhenfeng13 My-BBS 1.0 and classified as problematic. | 4.3 | |
2025-04-19 | CVE-2025-3284 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.3. | 4.3 | |
2025-04-16 | CVE-2025-32783 | Xwiki | Unspecified vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 4.3 |
2025-04-16 | CVE-2025-3686 | A vulnerability classified as problematic was found in misstt123 oasys 1.0. | 4.3 | |
2025-04-16 | CVE-2025-3687 | A vulnerability, which was classified as problematic, has been found in misstt123 oasys 1.0. | 4.3 | |
2025-04-15 | CVE-2025-3612 | A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. | 4.3 | |
2025-04-14 | CVE-2025-3567 | A vulnerability, which was classified as problematic, was found in veal98 ??? Echo ?????? 4.2. | 4.3 | |
2025-04-14 | CVE-2025-3564 | A vulnerability classified as problematic has been found in huanfenz/code-projects StudentManager up to 1.0. | 4.3 | |
2025-04-14 | CVE-2025-3562 | A vulnerability was found in Yonyou YonBIP MA2.7. | 4.3 | |
2025-04-14 | CVE-2025-3561 | A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0. | 4.3 | |
2025-04-14 | CVE-2025-3557 | A vulnerability, which was classified as problematic, has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. | 4.3 | |
2025-04-14 | CVE-2025-3554 | A vulnerability was found in phpshe 1.8. | 4.3 | |
2025-04-14 | CVE-2025-3550 | A vulnerability has been found in wowjoy ?????????????? Internet Doctor Workstation System 1.0 and classified as problematic. | 4.3 | |
2025-04-20 | CVE-2025-3826 | Senior Walter | Code Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0 A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0. | 4.1 |
2025-04-20 | CVE-2025-3825 | Senior Walter | Code Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0 A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. | 4.1 |
2025-04-20 | CVE-2025-3823 | Senior Walter | Code Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0 A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. | 4.1 |
2025-04-20 | CVE-2025-3824 | Senior Walter | Code Injection vulnerability in Senior-Walter Web-Based Pharmacy Product Management System 1.0 A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. | 4.1 |
2025-04-15 | CVE-2025-30721 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). | 4.0 |