CVE-2025-7195 2025-11-08 19:05:06 UTC | Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd | MEDIUM 5.2 |
CVE-2025-64459 2025-11-08 12:49:45 UTC | Potential SQL injection via _connector keyword argument in QuerySet and Q objects | CRITICAL 9.1 |
CVE-2023-6710 2025-11-08 10:04:51 UTC | Mod_cluster/mod_proxy_cluster: stored cross site scripting | MEDIUM 5.4 |
CVE-2025-11967 2025-11-08 09:28:12 UTC | Mail Mint <= 1.18.10 - Authenticated (Admin+) Arbitrary File Upload | HIGH 7.2 |
CVE-2025-12399 2025-11-08 09:28:12 UTC | Alex Reservations: Smart Restaurant Booking <= 2.2.3 - Authenticated (Admin+) Arbitrary File Upload | HIGH 7.2 |
CVE-2025-11448 2025-11-08 09:28:11 UTC | Gallery Plugin for WordPress – Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+) Gallery Conversion | MEDIUM 4.3 |
CVE-2025-12837 2025-11-08 09:28:11 UTC | aThemes Addons for Elementor <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Call To Action Widget | MEDIUM 6.4 |
CVE-2025-11980 2025-11-08 09:28:10 UTC | Quick Featured Images <= 13.7.3 - Authenticated (Editor+) SQL Injection via delete_orphaned | MEDIUM 4.9 |
CVE-2025-12643 2025-11-08 09:28:10 UTC | Saphali LiqPay for donate <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | MEDIUM 6.4 |
CVE-2025-12092 2025-11-08 09:28:09 UTC | CYAN Backup <= 2.5.4 - Authenticated (Admin+) Arbitrary File Deletion | MEDIUM 6.5 |
CVE-2024-8612 2025-11-08 08:56:18 UTC | Qemu-kvm: information leak in virtio devices | LOW 3.8 |
CVE-2024-8354 2025-11-08 08:56:17 UTC | Qemu-kvm: usb: assertion failure in usb_ep_get() | MEDIUM 5.5 |
CVE-2023-5215 2025-11-08 08:55:24 UTC | Libnbd: crash or misbehaviour when nbd server returns an unexpected block size | MEDIUM 5.3 |
CVE-2025-12098 2025-11-08 08:27:42 UTC | Academy LMS Pro <= 3.3.8 - Unauthenticated Sensitive Information Exposure via 'enqueue_social_login_script' | MEDIUM 5.3 |
CVE-2025-12099 2025-11-08 08:27:41 UTC | Academy LMS – WordPress LMS Plugin for Complete eLearning Solution <= 3.3.8 - Authenticated (Administrator+) PHP Object Injection via 'import_all_courses' | HIGH 7.2 |
CVE-2024-1441 2025-11-08 08:05:37 UTC | Libvirt: off-by-one error in udevlistinterfacesbystatus() | MEDIUM 5.5 |
CVE-2023-39417 2025-11-08 08:05:26 UTC | Postgresql: extension script @substitutions@ within quoting allow sql injection | HIGH 7.5 |
CVE-2025-12621 2025-11-08 07:26:28 UTC | Flexible Refund and Return Order for WooCommerce <= 1.0.42 - Incorrect Authorization to Authenticated (Contributor+) Refund Status Update | MEDIUM 5.3 |
CVE-2025-47712 2025-11-08 07:16:29 UTC | Nbd: nbdkit: integer overflow triggers an assertion resulting in denial of service | MEDIUM 4.3 |
CVE-2025-47711 2025-11-08 07:16:25 UTC | Nbdkit: nbdkit-server: off-by-one error when processing block status may lead to a denial of service | MEDIUM 4.3 |
CVE-2024-52337 2025-11-08 07:14:23 UTC | Tuned: improper sanitization of `instance_name` parameter of the `instance_create()` method | MEDIUM 5.5 |
CVE-2024-8235 2025-11-08 07:13:57 UTC | Libvirt: crash of virtinterfaced via virconnectlistinterfaces() | MEDIUM 6.2 |
CVE-2024-7383 2025-11-08 07:13:53 UTC | Libnbd: nbd server improper certificate validation | HIGH 7.4 |
CVE-2024-6505 2025-11-08 07:13:51 UTC | Qemu-kvm: virtio-net: queue index out-of-bounds access in software rss | MEDIUM 6.8 |
CVE-2024-4418 2025-11-08 07:13:49 UTC | Libvirt: stack use-after-free in virnetclientioeventloop() | MEDIUM 6.2 |
CVE-2024-4693 2025-11-08 07:13:46 UTC | Qemu-kvm: virtio-pci: improper release of configure vector leads to guest triggerable crash | MEDIUM 5.5 |
CVE-2024-10306 2025-11-08 07:11:48 UTC | Mod_proxy_cluster: mod_proxy_cluster unauthorized mcmp requests | MEDIUM 5.4 |
CVE-2024-2182 2025-11-08 07:11:46 UTC | Ovn: insufficient validation of bfd packets may lead to denial of service | MEDIUM 6.5 |
CVE-2023-42755 2025-11-08 07:10:59 UTC | Kernel: rsvp: out-of-bounds read in rsvp_classify() | MEDIUM 6.5 |
CVE-2023-39192 2025-11-08 07:10:42 UTC | Kernel: netfilter: xtables out-of-bounds read in u32_match_it() | MEDIUM 6.7 |
CVE-2023-6841 2025-11-08 07:10:39 UTC | Keycloak: amount of attributes per object is not limited and it may lead to dos | HIGH 7.5 |
CVE-2023-6683 2025-11-08 07:10:34 UTC | Qemu: vnc: null pointer dereference in qemu_clipboard_request() | MEDIUM 6.5 |
CVE-2023-6610 2025-11-08 07:10:28 UTC | Kernel: oob access in smb2_dump_detail | HIGH 7.1 |
CVE-2023-6606 2025-11-08 07:10:24 UTC | Kernel: out-of-bounds read vulnerability in smbcalcsize | HIGH 7.1 |
CVE-2023-6240 2025-11-08 07:10:22 UTC | Kernel: marvin vulnerability side-channel leakage in the rsa decryption operation | MEDIUM 6.5 |
CVE-2023-5090 2025-11-08 07:10:11 UTC | Kernel: kvm: svm: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs | MEDIUM 6.0 |
CVE-2024-3567 2025-11-08 06:49:51 UTC | Qemu-kvm: net: assertion failure in update_sctp_checksum() | MEDIUM 5.5 |
CVE-2024-2496 2025-11-08 06:49:39 UTC | Libvirt: null pointer dereference in udevconnectlistallinterfaces() | MEDIUM 5.0 |
CVE-2024-2494 2025-11-08 06:49:31 UTC | Libvirt: negative g_new0 length can lead to unbounded memory allocation | MEDIUM 6.2 |
CVE-2025-12498 2025-11-08 06:39:56 UTC | EventPrime – Events Calendar, Bookings and Tickets <= 4.2.0.0 - Missing Authorization to Authenticated (Subscriber+) Booking Note Creation | MEDIUM 4.3 |
CVE-2023-3750 2025-11-08 06:30:27 UTC | Libvirt: improper locking in virstoragepoolobjlistsearch may lead to denial of service | MEDIUM 6.5 |
CVE-2023-3255 2025-11-08 06:30:20 UTC | Qemu: vnc: infinite loop in inflate_buffer() leads to denial of service | MEDIUM 6.5 |
CVE-2025-9334 2025-11-08 05:52:43 UTC | Better Find and Replace <= 1.7.7 - Authenticated (Subscriber+) Limited Code Injection | HIGH 8.8 |
CVE-2025-10230 2025-11-08 04:55:22 UTC | Samba: command injection in wins server hook script | CRITICAL 10.0 |
CVE-2025-36186 2025-11-08 04:55:21 UTC | IBM Db2 privilege escalation | HIGH 7.4 |
CVE-2025-9458 2025-11-08 04:55:21 UTC | PRT File Parsing Memory Corruption Vulnerability | HIGH 7.8 |
CVE-2025-12790 2025-11-08 04:55:20 UTC | Rubygem-mqtt: rubygem-mqtt hostname validation | HIGH 7.4 |
CVE-2025-10885 2025-11-08 04:55:19 UTC | Privilege Escalation Vulnerability | HIGH 7.8 |
CVE-2025-11458 2025-11-08 04:55:18 UTC | Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | HIGH 8.1 |
CVE-2025-11756 2025-11-08 04:55:18 UTC | Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | HIGH 8.8 |
CVE-2025-11205 2025-11-08 04:55:17 UTC | Heap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | HIGH 8.8 |
CVE-2025-11206 2025-11-08 04:55:16 UTC | Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | HIGH 7.1 |
CVE-2025-11460 2025-11-08 04:55:15 UTC | Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High) | |
CVE-2025-12036 2025-11-08 04:55:14 UTC | Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | HIGH 8.8 |
CVE-2025-24252 2025-11-08 04:55:13 UTC | A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt process memory. | HIGH 8.8 |
CVE-2024-11614 2025-11-08 04:04:42 UTC | Dpdk: denial of service from malicious guest on hypervisors using dpdk vhost library | HIGH 7.4 |
CVE-2024-4467 2025-11-08 04:04:41 UTC | Qemu-kvm: 'qemu-img info' leads to host file read/write | HIGH 7.8 |
CVE-2025-12125 2025-11-08 03:27:51 UTC | HTML Forms <= 1.5.5 - Authenticated (Admin+) Stored Cross-Site Scripting | MEDIUM 4.4 |
CVE-2025-12000 2025-11-08 03:27:50 UTC | WPFunnels <= 3.6.2 - Authenticated (Administrator+) Arbitrary File Deletion via Path Traversal | MEDIUM 6.5 |
CVE-2025-12112 2025-11-08 03:27:50 UTC | Insert Headers and Footers Code – HT Script <= 1.1.6 - Authenticated (Author+) Stored Cross-Site Scripting | MEDIUM 6.4 |
CVE-2025-11748 2025-11-08 03:27:49 UTC | Groups <= 6.7.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Group Join | MEDIUM 4.3 |
CVE-2025-12161 2025-11-08 03:27:49 UTC | Smart Auto Upload Images <= 1.2.0 - Authenticated (Contributor+) Arbitrary File Upload | HIGH 8.8 |
CVE-2025-12193 2025-11-08 03:27:49 UTC | Mang Board WP <= 2.3.1 - Reflected Cross-Site Scripting | MEDIUM 6.1 |
CVE-2025-11972 2025-11-08 03:27:48 UTC | Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.40.0 - Authenticated (Editor+) SQL Injection | MEDIUM 4.9 |
CVE-2025-7663 2025-11-08 03:27:48 UTC | Ovatheme Events Manager <= 1.8.6 - Missing Authorization | MEDIUM 6.5 |
CVE-2025-12042 2025-11-08 03:27:47 UTC | Course Booking System <= 6.1.5 - Missing Authorization to Unauthenticated Booking Data Export | MEDIUM 5.3 |
CVE-2025-12353 2025-11-08 03:27:47 UTC | WPFunnels <= 3.6.2 - Unauthorized User Registration | MEDIUM 5.3 |
CVE-2025-12064 2025-11-08 03:27:46 UTC | WP2Social Auto Publish <= 2.4.7 - Reflected Cross-Site Scripting via PostMessage | MEDIUM 6.1 |
CVE-2025-12177 2025-11-08 03:27:46 UTC | Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key | MEDIUM 5.3 |
CVE-2025-12167 2025-11-08 03:27:45 UTC | Contact Form 7 AWeber Extension <= 0.1.42 - Missing Authorization to Authenticated (Subscriber+) Log Reset | MEDIUM 4.3 |
CVE-2024-52336 2025-11-08 03:14:13 UTC | Tuned: `script_pre` and `script_post` options allow to pass arbitrary scripts executed by root | HIGH 7.8 |
CVE-2023-5157 2025-11-08 03:13:37 UTC | Mariadb: node crashes with transport endpoint is not connected mysqld got signal 6 | HIGH 7.5 |
CVE-2023-4004 2025-11-08 03:13:35 UTC | Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove() | HIGH 7.8 |
CVE-2024-3049 2025-11-08 03:10:49 UTC | Booth: specially crafted hash can lead to invalid hmac being accepted by booth server | MEDIUM 5.9 |
CVE-2025-12583 2025-11-08 02:28:04 UTC | Simple Downloads List <= 1.4.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting | MEDIUM 6.4 |
CVE-2025-11452 2025-11-08 02:28:02 UTC | Asgaros Forum <= 3.1.0 - Unauthenticated SQL Injection | HIGH 7.5 |
CVE-2025-64496 2025-11-08 01:29:03 UTC | Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events | HIGH 7.3 |
CVE-2025-64495 2025-11-08 01:25:49 UTC | Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE | HIGH 8.7 |
CVE-2025-64494 2025-11-08 01:19:01 UTC | Soft Serve does not sanitize ANSI escape sequences in user input | MEDIUM 4.6 |
CVE-2025-64493 2025-11-08 01:16:23 UTC | SuiteCRM is Vulnerable to Authenticated Blind SQL Injection via GraphQL | MEDIUM 6.5 |
CVE-2025-64492 2025-11-08 01:07:23 UTC | SuiteCRM is Vulnerable to Authenticated Time Based Blind SQL Injection | HIGH 8.8 |
CVE-2025-64491 2025-11-08 00:45:08 UTC | SuiteCRM is vulnerable to unauthenticated reflected XSS through its Login page | MEDIUM 6.1 |
CVE-2025-64490 2025-11-08 00:22:38 UTC | SuiteCRM's Inconsistent RBAC Enforcement Enables Access Control Bypass | HIGH 8.3 |
CVE-2025-64489 2025-11-08 00:15:45 UTC | SuiteCRM: Privilege Escalation via Improper Session Invalidation and Inactive User Bypass | HIGH 8.3 |
CVE-2025-12735 2025-11-08 00:11:55 UTC | CVE-2025-12735 | CRITICAL 9.8 |
CVE-2025-64488 2025-11-07 23:59:46 UTC | SuiteCRM: Authenticated SQL Injection Possible in Reschedule Call Module | HIGH 8.6 |
CVE-2025-64486 2025-11-07 23:25:56 UTC | calibre is vulnerable to arbitrary code execution when opening FB2 files | CRITICAL 9.3 |
CVE-2025-12909 2025-11-07 23:23:39 UTC | Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cross-origin data via Devtools. (Chromium security severity: Low) | |
CVE-2025-12910 2025-11-07 23:23:39 UTC | Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain potentially sensitive information via debug logs. (Chromium security severity: Low) | |
CVE-2025-12911 2025-11-07 23:23:39 UTC | Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |
CVE-2025-12907 2025-11-07 23:23:38 UTC | Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code via user action in Devtools. (Chromium security severity: Low) | |
CVE-2025-12908 2025-11-07 23:23:38 UTC | Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low) | |
CVE-2025-12905 2025-11-07 23:23:37 UTC | Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low) | |
CVE-2025-12906 2025-11-07 23:23:37 UTC | Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |
CVE-2025-64485 2025-11-07 23:21:07 UTC | CVAT: Mounted share file overwrite via crafted request | MEDIUM 5.3 |
CVE-2025-64433 2025-11-07 23:07:31 UTC | KubeVirt Arbitrary Container File Read | MEDIUM 6.5 |
CVE-2025-64437 2025-11-07 23:04:11 UTC | KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes | MEDIUM 5.0 |
CVE-2025-64436 2025-11-07 22:59:47 UTC | KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes | MEDIUM 6.9 |
CVE-2025-64435 2025-11-07 22:57:03 UTC | KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation | MEDIUM 5.3 |
CVE-2025-64434 2025-11-07 22:54:05 UTC | KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing | MEDIUM 4.7 |