π¨ CVE-2025-47337
Memory corruption while accessing a synchronization object during concurrent operations.
π@cveNotify
Memory corruption while accessing a synchronization object during concurrent operations.
π@cveNotify
π¨ CVE-2025-47343
Memory corruption while processing a video session to set video parameters.
π@cveNotify
Memory corruption while processing a video session to set video parameters.
π@cveNotify
π¨ CVE-2025-47346
Memory corruption while processing a secure logging command in the trusted application.
π@cveNotify
Memory corruption while processing a secure logging command in the trusted application.
π@cveNotify
π¨ CVE-2025-47356
Memory Corruption when multiple threads concurrently access and modify shared resources.
π@cveNotify
Memory Corruption when multiple threads concurrently access and modify shared resources.
π@cveNotify
π¨ CVE-2025-47369
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
π@cveNotify
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
π@cveNotify
π¨ CVE-2025-47388
Memory corruption while passing pages to DSP with an unaligned starting address.
π@cveNotify
Memory corruption while passing pages to DSP with an unaligned starting address.
π@cveNotify
π¨ CVE-2025-47394
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
π@cveNotify
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
π@cveNotify
π¨ CVE-2025-47395
Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.
π@cveNotify
Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.
π@cveNotify
π¨ CVE-2025-47396
Memory corruption occurs when a secure application is launched on a device with insufficient memory.
π@cveNotify
Memory corruption occurs when a secure application is launched on a device with insufficient memory.
π@cveNotify
π¨ CVE-2025-68637
The Uniffle HTTP client is configured to trust all SSL certificates and
disables hostname verification by default. This insecure configuration
exposes all REST API communication between the Uniffle CLI/client and the
Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks.
This issue affects all versions from before 0.10.0.
Users are recommended to upgrade to version 0.10.0, which fixes the issue.
π@cveNotify
The Uniffle HTTP client is configured to trust all SSL certificates and
disables hostname verification by default. This insecure configuration
exposes all REST API communication between the Uniffle CLI/client and the
Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks.
This issue affects all versions from before 0.10.0.
Users are recommended to upgrade to version 0.10.0, which fixes the issue.
π@cveNotify
π¨ CVE-2025-69080
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JanStudio Gecko gecko allows PHP Local File Inclusion.This issue affects Gecko: from n/a through <= 1.9.8.
π@cveNotify
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JanStudio Gecko gecko allows PHP Local File Inclusion.This issue affects Gecko: from n/a through <= 1.9.8.
π@cveNotify
Patchstack
Local File Inclusion in WordPress Gecko Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2025-69081
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hope charity-is-hope allows PHP Local File Inclusion.This issue affects Hope: from n/a through <= 3.0.0.
π@cveNotify
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hope charity-is-hope allows PHP Local File Inclusion.This issue affects Hope: from n/a through <= 3.0.0.
π@cveNotify
Patchstack
Local File Inclusion in WordPress Hope Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2025-69082
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo allows Reflected XSS.This issue affects Arlo: from n/a through <= 6.0.3.
π@cveNotify
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo allows Reflected XSS.This issue affects Arlo: from n/a through <= 6.0.3.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Arlo Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2025-69333
Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.8.1.1.
π@cveNotify
Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.8.1.1.
π@cveNotify
Patchstack
Broken Access Control in WordPress JetEngine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2025-69344
Missing Authorization vulnerability in themehunk Oneline Lite oneline-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Oneline Lite: from n/a through <= 6.6.
π@cveNotify
Missing Authorization vulnerability in themehunk Oneline Lite oneline-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Oneline Lite: from n/a through <= 6.6.
π@cveNotify
Patchstack
Broken Access Control in WordPress Oneline Lite Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2025-9611
Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victimβs web browser and send unauthorized requests to a locally running MCP server, resulting in unintended invocation of MCP tool endpoints.
π@cveNotify
Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victimβs web browser and send unauthorized requests to a locally running MCP server, resulting in unintended invocation of MCP tool endpoints.
π@cveNotify
GitHub
Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools
### Summary
Any malicious website or malvertizement can actuate any and all MCP server tool endpoints via a browser-based DNS rebinding attack.
TL;DR: This attack leverages the browser as a c...
Any malicious website or malvertizement can actuate any and all MCP server tool endpoints via a browser-based DNS rebinding attack.
TL;DR: This attack leverages the browser as a c...
π¨ CVE-2025-32303
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0.
π@cveNotify
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0.
π@cveNotify
Patchstack
SQL Injection in WordPress WPCHURCH Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.