Latest CVE Feed
-
7.6
HIGHCVE-2025-47290
containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could arbitrarily modify the host file system. The o... Read more
Affected Products : containerd- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Race Condition
-
6.1
MEDIUMCVE-2024-12561
The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.4.9. This is due to insufficient validation on the redirect url supplied via the 'afflink' parameter. This ... Read more
Affected Products :- Published: May. 21, 2025
- Modified: May. 21, 2025
- Vuln Type: Misconfiguration
-
0.0
NACVE-2025-37946
In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has child VFs With commit bcb5d6c76903 ("s390/pci: introduce lock to synchronize state of zpci_dev's") the code to ignore... Read more
Affected Products : linux_kernel- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-37978
In the Linux kernel, the following vulnerability has been resolved: block: integrity: Do not call set_page_dirty_lock() Placing multiple protection information buffers inside the same page can lead to oopses because set_page_dirty_lock() can't be called... Read more
Affected Products : linux_kernel- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Misconfiguration
-
5.7
MEDIUMCVE-2024-52013
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at wiz_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a c... Read more
Affected Products : r7000p_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2024-52014
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at genie_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a... Read more
Affected Products : r7000p_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2024-52015
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at bsw_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a c... Read more
Affected Products : r7000p_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2024-52016
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component wlg_adv.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allo... Read more
Affected Products : r7000p_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
8.0
HIGHCVE-2024-52022
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulnerability allows attackers to execute... Read more
Affected Products : r7000p_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2024-51011
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
7.5
HIGHCVE-2025-2240
A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial o... Read more
Affected Products :- Published: Mar. 12, 2025
- Modified: May. 21, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2022-3197
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
4.8
MEDIUMCVE-2022-3135
The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : seo_smart_links- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
7.5
HIGHCVE-2022-3119
The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them t... Read more
Affected Products : oauth_client_single_sign_on- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
7.8
HIGH- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
7.2
HIGHCVE-2022-2903
The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present ... Read more
Affected Products : ninja_forms- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2022-2861
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2022-2860
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafted HTML page.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-2859
Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-2858
Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025