A vulnerability was found in Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0. It has been classified as problematic. Impacted is the function alloc_ordered_workqueue of the component iwlwifi. The manipulation leads to unchecked return value.
This vulnerability is listed as CVE-2025-38602. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0. Affected by this issue is the function ath11k_hal_dump_srng_stats. The manipulation results in denial of service.
This vulnerability is known as CVE-2025-38601. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability classified as problematic was found in Linux Kernel up to 6.16.0. Affected by this vulnerability is the function mt7925_mcu_hw_scan of the component wifi. The manipulation of the argument ssids[] results in off-by-one.
This vulnerability was named CVE-2025-38600. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in Linux Kernel up to 6.15.9/6.16.0. Affected is the function mt7996_tx of the component wifi. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-38599. The attack can only be initiated within the local network. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability labeled as critical has been found in Apple macOS up to 14.8.2/15.7.2. Affected is an unknown function of the component App. Executing manipulation can lead to integer overflow.
This vulnerability is handled as CVE-2025-46285. It is possible to launch the attack on the local host. There is not any exploit available.
The affected component should be upgraded.
A vulnerability was found in Amazon AWS Harmonix up to 0.4.1 and classified as critical. The impacted element is an unknown function. Executing manipulation can lead to incorrect privilege assignment.
This vulnerability appears as CVE-2025-14503. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability classified as problematic was found in Apple macOS up to 15.7.2. Impacted is an unknown function of the component App. Such manipulation leads to Local Privilege Escalation.
This vulnerability is listed as CVE-2025-43320. The attack must be carried out locally. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in Auto Featured Image Plugin up to 4.2.1 on WordPress. Impacted is the function bulk_action_generate_handler of the component Thumbnail Handler. This manipulation causes missing authorization.
This vulnerability is tracked as CVE-2025-13794. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.0.2. The affected element is the function rds_tcp_reset_callbacks. This manipulation causes denial of service.
This vulnerability is registered as CVE-2022-50676. The attack requires access to the local network. No exploit is available.
You should upgrade the affected component.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.0.2. Affected is the function for_each_available_child_of_node. Performing manipulation results in improper update of reference count.
This vulnerability is known as CVE-2022-50641. Access to the local network is required for this attack. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability was found in LINE Client up to 14.19 on Android and classified as critical. This vulnerability affects unknown code of the component Notifications Handler. The manipulation results in clickjacking.
This vulnerability was named CVE-2025-14020. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability was found in vion707 DMadmin up to 3403cafdb42537a648c30bf8cbc8148ec60437d1 and classified as problematic. This impacts the function Add of the file Admin/Controller/AddonsController.class.php of the component Backend. Executing manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2025-14722. The attack can be executed remotely. Additionally, an exploit exists.
This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in FNT Command 13.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component C Base Module. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2024-44598. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability identified as critical has been detected in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the component Backend App Configuration Module. The manipulation of the argument CT_App_Paytype leads to code injection.
This vulnerability is referenced as CVE-2025-14729. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability labeled as critical has been found in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms/libs/Ct_Config.php of the component Backend System Configuration Module. The manipulation of the argument Cj_Add/Cj_Edit results in code injection.
This vulnerability is identified as CVE-2025-14730. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability marked as critical has been reported in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component Frontend/Template Management Module. This manipulation causes improper neutralization of special elements used in a template engine.
This vulnerability is tracked as CVE-2025-14731. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability categorized as critical has been discovered in FreshRSS up to 1.27.0. This issue affects some unknown processing. The manipulation of the argument Language results in improper input validation.
This vulnerability is reported as CVE-2025-58173. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in Apache Airflow up to 3.1.3. It has been classified as problematic. Impacted is an unknown function of the component Template Handler. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2025-66388. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability was found in LearnPress Plugin up to 4.3.1 on WordPress. It has been classified as problematic. The impacted element is the function get_profile_social. Performing manipulation results in cross site scripting.
This vulnerability was named CVE-2025-14387. The attack may be initiated remotely. There is no available exploit.