Latest CVE Feed
- 
                                
                                
8.8
HIGHCVE-2025-10240
A vulnerability exists in the Progress Flowmon web application prior to version 12.5.5, whereby a user who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated session.... Read more
Affected Products : flowmon- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Cross-Site Request Forgery
 
 - 
                                
                                
7.5
HIGHCVE-2025-10862
The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.1.3. This is due to insufficient escaping on the 'id' parame... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
0.0
NACVE-2025-39957
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: increase scan_ies_len for S1G Currently the S1G capability element is not taken into account for the scan_ies_len, which leads to a buffer length validation failure in i... Read more
Affected Products : linux_kernel- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 
 - 
                                
                                
0.0
NACVE-2025-39959
In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp: Fix incorrect retrival of acp_chip_info Use dev_get_drvdata(dev->parent) instead of dev_get_platdata(dev) to correctly obtain acp_chip_info members in the acp I2S driver... Read more
Affected Products : linux_kernel- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2025-39960
In the Linux kernel, the following vulnerability has been resolved: gpiolib: acpi: initialize acpi_gpio_info struct Since commit 7c010d463372 ("gpiolib: acpi: Make sure we fill struct acpi_gpio_info"), uninitialized acpi_gpio_info struct are passed to _... Read more
Affected Products : linux_kernel- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 
 - 
                                
                                
0.0
NACVE-2025-39963
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix incorrect io_kiocb reference in io_link_skb In io_link_skb function, there is a bug where prev_notif is incorrectly assigned using 'nd' instead of 'prev_nd'. This causes t... Read more
Affected Products : linux_kernel- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.2
HIGHCVE-2025-10496
The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uuid parameter in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthe... Read more
Affected Products : cookie_notice_\&_consent- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
5.1
MEDIUMCVE-2025-62228
Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, we recommend users update Flink CDC... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
0.0
NACVE-2025-39954
In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: mp: Fix dual-divider clock rate readback When dual-divider clock support was introduced, the P divider offset was left out of the .recalc_rate readback function. This cau... Read more
Affected Products : linux_kernel- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
7.8
HIGHCVE-2025-47338
Memory corruption while processing escape commands from userspace.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.8
HIGHCVE-2025-47341
memory corruption while processing an image encoding completion event.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.2
HIGHCVE-2025-10239
In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privileges and access to the management interface to execute additional unintended commands within scripts intended for troubleshooting purposes... Read more
Affected Products : flowmon- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
8.8
HIGHCVE-2025-11535
MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.... Read more
Affected Products :- Published: Oct. 08, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
9.9
CRITICALCVE-2025-11539
Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath parameter that allowed an attacker to save a shared object ... Read more
Affected Products : grafana-image-renderer- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Path Traversal
 
 - 
                                
                                
0.0
NACVE-2025-39956
In the Linux kernel, the following vulnerability has been resolved: igc: don't fail igc_probe() on LED setup error When igc_led_setup() fails, igc_probe() fails and triggers kernel panic in free_netdev() since unregister_netdev() is not called. [1] This... Read more
Affected Products : linux_kernel- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-27045
Information disclosure while processing batch command execution in Video driver.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
10.0
CRITICALCVE-2025-36636
In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.... Read more
Affected Products : security_center- Published: Oct. 08, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
7.2
HIGHCVE-2025-11470
A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0. The impacted element is an unknown function of the file /manage_website.php. The manipulation of the argument website_image/back_login_image leads to... Read more
Affected Products : hotel_and_lodge_management_system- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11471
A vulnerability was detected in SourceCodester Hotel and Lodge Management System 1.0. This affects an unknown function of the file /edit_customer.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. T... Read more
Affected Products : hotel_and_lodge_management_system- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11472
A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. This impacts an unknown function of the file /edit_room.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The expl... Read more
Affected Products : hotel_and_lodge_management_system- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Injection