Latest CVE Feed
- 
                                
                                
0.0
NACVE-2025-39958
In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Make attach succeed when the device was surprise removed When a PCI device is removed with surprise hotplug, there may still be attempts to attach the device to the default ... Read more
Affected Products : linux_kernel- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
0.0
NACVE-2025-39955
In the Linux kernel, the following vulnerability has been resolved: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). syzbot reported the splat below where a socket had tcp_sk(sk)->fastopen_rsk in the TCP_ESTABLISHED state. [0] syzbot reused the... Read more
Affected Products : linux_kernel- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11522
The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user validation in the search_and_go_elated_check_facebook_u... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
8.8
HIGHCVE-2025-6038
The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation via password update in all versions up to, and including, 1.4.0. This is due to the plugin not properly validat... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
7.8
HIGHCVE-2025-47355
Memory corruption while invoking remote procedure IOCTL calls.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-27049
Transient DOS while processing IOCTL call for image encoding.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
8.8
HIGHCVE-2025-11535
MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.... Read more
Affected Products :- Published: Oct. 08, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-27041
Transient DOS while processing video packets received from video firmware.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
5.4
MEDIUMCVE-2025-11166
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 9.0.46. This is due to the plugin exposing state-changing REST actions through an AJAX bridge without pr... Read more
Affected Products : wp_go_maps- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Cross-Site Request Forgery
 
 - 
                                
                                
7.2
HIGHCVE-2025-10496
The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uuid parameter in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthe... Read more
Affected Products : cookie_notice_\&_consent- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
9.8
CRITICALCVE-2025-10586
The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis... Read more
Affected Products : community_events- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
7.8
HIGHCVE-2025-47341
memory corruption while processing an image encoding completion event.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.5
HIGHCVE-2025-10862
The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.1.3. This is due to insufficient escaping on the 'id' parame... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
7.8
HIGH- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
9.8
CRITICALCVE-2025-7526
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versions up to, and inc... Read more
Affected Products : wp_travel_engine- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Path Traversal
 
 - 
                                
                                
7.8
HIGHCVE-2025-27048
Memory corruption while processing camera platform driver IOCTL calls.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.8
HIGHCVE-2025-47340
Memory corruption while processing IOCTL call to get the mapping.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.8
HIGHCVE-2025-27053
Memory corruption during PlayReady APP usecase while processing TA commands.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2025-39963
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix incorrect io_kiocb reference in io_link_skb In io_link_skb function, there is a bug where prev_notif is incorrectly assigned using 'nd' instead of 'prev_nd'. This causes t... Read more
Affected Products : linux_kernel- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2025-39962
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix untrusted unsigned subtract Fix the following Smatch static checker warning: net/rxrpc/rxgk_app.c:65 rxgk_yfs_decode_ticket() warn: untrusted unsigned subtract. 'ticke... Read more
Affected Products : linux_kernel- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Memory Corruption