NA - CVE-2025-21866 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: powerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_ALLOC Erhard reported the following KASAN hit...
NA - CVE-2025-2239 - Generation of Error Message Containing...
Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation FireWall: from...
NA - CVE-2024-13870 - An improper access control vulnerability exists...
An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an...
NA - CVE-2024-13871 - A command injection vulnerability exists in the...
A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated,...
NA - CVE-2024-13872 - Bitdefender Box, versions 1.3.11.490 through...
Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices....
Medium - CVE-2025-1527 - The ShopLentor – WooCommerce Builder for...
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to a Stored DOM-Based Cross-Site Scripting...
NA - CVE-2024-10838 - An integer underflow during deserialization may...
An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address...