π¨ CVE-2025-47343
Memory corruption while processing a video session to set video parameters.
π@cveNotify
Memory corruption while processing a video session to set video parameters.
π@cveNotify
π¨ CVE-2025-47346
Memory corruption while processing a secure logging command in the trusted application.
π@cveNotify
Memory corruption while processing a secure logging command in the trusted application.
π@cveNotify
π¨ CVE-2025-47356
Memory Corruption when multiple threads concurrently access and modify shared resources.
π@cveNotify
Memory Corruption when multiple threads concurrently access and modify shared resources.
π@cveNotify
π¨ CVE-2025-47369
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
π@cveNotify
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
π@cveNotify
π¨ CVE-2025-47388
Memory corruption while passing pages to DSP with an unaligned starting address.
π@cveNotify
Memory corruption while passing pages to DSP with an unaligned starting address.
π@cveNotify
π¨ CVE-2025-47394
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
π@cveNotify
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
π@cveNotify
π¨ CVE-2025-47395
Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.
π@cveNotify
Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.
π@cveNotify
π¨ CVE-2025-47396
Memory corruption occurs when a secure application is launched on a device with insufficient memory.
π@cveNotify
Memory corruption occurs when a secure application is launched on a device with insufficient memory.
π@cveNotify
π¨ CVE-2025-68637
The Uniffle HTTP client is configured to trust all SSL certificates and
disables hostname verification by default. This insecure configuration
exposes all REST API communication between the Uniffle CLI/client and the
Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks.
This issue affects all versions from before 0.10.0.
Users are recommended to upgrade to version 0.10.0, which fixes the issue.
π@cveNotify
The Uniffle HTTP client is configured to trust all SSL certificates and
disables hostname verification by default. This insecure configuration
exposes all REST API communication between the Uniffle CLI/client and the
Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks.
This issue affects all versions from before 0.10.0.
Users are recommended to upgrade to version 0.10.0, which fixes the issue.
π@cveNotify
π¨ CVE-2025-69080
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JanStudio Gecko gecko allows PHP Local File Inclusion.This issue affects Gecko: from n/a through <= 1.9.8.
π@cveNotify
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JanStudio Gecko gecko allows PHP Local File Inclusion.This issue affects Gecko: from n/a through <= 1.9.8.
π@cveNotify
Patchstack
Local File Inclusion in WordPress Gecko Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2025-69081
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hope charity-is-hope allows PHP Local File Inclusion.This issue affects Hope: from n/a through <= 3.0.0.
π@cveNotify
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hope charity-is-hope allows PHP Local File Inclusion.This issue affects Hope: from n/a through <= 3.0.0.
π@cveNotify
Patchstack
Local File Inclusion in WordPress Hope Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2025-69082
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo allows Reflected XSS.This issue affects Arlo: from n/a through <= 6.0.3.
π@cveNotify
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo allows Reflected XSS.This issue affects Arlo: from n/a through <= 6.0.3.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Arlo Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2025-69333
Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.8.1.1.
π@cveNotify
Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.8.1.1.
π@cveNotify
Patchstack
Broken Access Control in WordPress JetEngine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2025-69344
Missing Authorization vulnerability in themehunk Oneline Lite oneline-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Oneline Lite: from n/a through <= 6.6.
π@cveNotify
Missing Authorization vulnerability in themehunk Oneline Lite oneline-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Oneline Lite: from n/a through <= 6.6.
π@cveNotify
Patchstack
Broken Access Control in WordPress Oneline Lite Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2025-9611
Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victimβs web browser and send unauthorized requests to a locally running MCP server, resulting in unintended invocation of MCP tool endpoints.
π@cveNotify
Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victimβs web browser and send unauthorized requests to a locally running MCP server, resulting in unintended invocation of MCP tool endpoints.
π@cveNotify
GitHub
Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools
### Summary
Any malicious website or malvertizement can actuate any and all MCP server tool endpoints via a browser-based DNS rebinding attack.
TL;DR: This attack leverages the browser as a c...
Any malicious website or malvertizement can actuate any and all MCP server tool endpoints via a browser-based DNS rebinding attack.
TL;DR: This attack leverages the browser as a c...
π¨ CVE-2025-32303
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0.
π@cveNotify
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0.
π@cveNotify
Patchstack
SQL Injection in WordPress WPCHURCH Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2025-46256
Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through 3.2.10.
π@cveNotify
Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through 3.2.10.
π@cveNotify
Patchstack
Path Traversal in WordPress Advanced Database Cleaner PRO Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.