NA - CVE-2025-21838 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: flush gadget workqueue after device removal device_del() can lead to new work being scheduled in...
NA - CVE-2025-21839 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop Move the conditional loading of hardware DR6 with the...
NA - CVE-2025-21840 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: thermal/netlink: Prevent userspace segmentation fault by adjusting UAPI header The intel-lpmd tool [1], which uses the...
NA - CVE-2025-21841 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Fix cpufreq_policy ref counting amd_pstate_update_limits() takes a cpufreq_policy reference but...
NA - CVE-2025-21842 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: amdkfd: properly free gang_ctx_bo when failed to init user queue The destructor of a gtt bo is declared as void...
NA - CVE-2025-21843 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: avoid garbage value in panthor_ioctl_dev_query() 'priorities_info' is uninitialized, and the...
Medium - CVE-2024-13552 - The SupportCandy – Helpdesk & Customer Support...
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.0 via file upload due...
Medium - CVE-2024-13635 - The VK Blocks plugin for WordPress is...
The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. This makes it possible for...
NA - CVE-2024-13668 - The WordPress Activity O Meter WordPress plugin...
The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could...
Medium - CVE-2024-13805 - The Advanced File Manager — Ultimate WordPress...
The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,...