NA - CVE-2025-21842 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: amdkfd: properly free gang_ctx_bo when failed to init user queue The destructor of a gtt bo is declared as void...
NA - CVE-2025-21843 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: avoid garbage value in panthor_ioctl_dev_query() 'priorities_info' is uninitialized, and the...
Medium - CVE-2024-13552 - The SupportCandy – Helpdesk & Customer Support...
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.0 via file upload due...
Medium - CVE-2024-13635 - The VK Blocks plugin for WordPress is...
The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. This makes it possible for...
NA - CVE-2024-13668 - The WordPress Activity O Meter WordPress plugin...
The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could...
Medium - CVE-2024-13805 - The Advanced File Manager — Ultimate WordPress...
The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,...
Medium - CVE-2024-13857 - The WPGet API – Connect to any external REST...
The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.10. This makes it possible for...
NA - CVE-2024-9458 - The Reservit Hotel WordPress plugin before 3.0...
The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks...
Medium - CVE-2024-12634 - The Related Posts, Inline Related Posts,...
The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
Medium - CVE-2025-1768 - The SEO Plugin by Squirrly SEO plugin for...
The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in all versions up to, and including, 12.4.05 due to insufficient...