Medium - CVE-2025-25209 - The AuthPolicy metadata on Red Hat Connectivity...
The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead of copying it to the...
NA - CVE-2025-3581 - The Newsletter WordPress plugin before 8.8.5...
The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow high...
NA - CVE-2025-3582 - The Newsletter WordPress plugin before 8.85...
The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
Medium - CVE-2025-47711 - There's a flaw in the nbdkit server when...
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin...
Medium - CVE-2025-47712 - A flaw exists in the nbdkit "blocksize" filter...
A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a...
NA - CVE-2025-4652 - The Broadstreet WordPress plugin before 1.51.8...
The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...
High - CVE-2025-5863 - A vulnerability was found in Tenda AC5...
A vulnerability was found in Tenda AC5 15.03.06.47. It has been classified as critical. Affected is the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the...
Low - CVE-2025-5864 - A vulnerability was found in Tenda TDSEE App up...
A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/ConfirmSmsCode of the...
High - CVE-2025-5865 - A vulnerability was found in RT-Thread 5.1.0....
A vulnerability was found in RT-Thread 5.1.0. It has been rated as critical. Affected by this issue is the function sys_select of the file rt-thread/components/lwp/lwp_syscall.c of the component...
High - CVE-2025-5866 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in RT-Thread 5.1.0. This affects the function sys_sigprocmask of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the...