A vulnerability, which was classified as problematic, was found in Popup Maker Plugin up to 1.20.4 on WordPress. Affected is an unknown function. The manipulation of the argument popupID leads to cross site scripting.
This vulnerability is traded as CVE-2025-4205. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in Music Player for Elementor Plugin up to 2.4.6 on WordPress. This issue affects some unknown processing. The manipulation of the argument album_buy_url leads to cross site scripting.
The identification of this vulnerability is CVE-2025-5340. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as problematic was found in Shared Files Plugin up to 1.7.48 on WordPress. This vulnerability affects the function sanitize_file. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-4392. The attack can be initiated remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Profile Builder Plugin up to 3.13.8 on WordPress. This affects the function user_meta/compare of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-4671. It is possible to initiate the attack remotely. There is no exploit available.
Google on Monday released out-of-band fixes to address three security issues in its Chrome browser, including one that it said has come under active exploitation in the wild.
The high-severity flaw is being tracked as CVE-2025-5419 (CVSS score: 8.8), and has been flagged as an out-of-bounds read and write vulnerability in the V8 JavaScript and WebAssembly engine.
"Out-of-bounds read and
A vulnerability was found in D-Link Go-RT-AC750 revA_v101b03. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi. The manipulation of the argument service leads to command injection.
This vulnerability is known as CVE-2023-48842. The attack needs to be initiated within the local network. There is no exploit available.
A vulnerability, which was classified as critical, has been found in Realtek Bluetooth HCI Adaptor. Affected by this issue is some unknown functionality. The manipulation leads to link following.
This vulnerability is handled as CVE-2024-11857. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in MediaTek MT7902, MT7921, MT7922, MT7925 and MT7927. This affects an unknown part of the component Bluetooth Driver. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2025-20672. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability has been found in MediaTek MT7902, MT7921, MT7922, MT7925 and MT7927 and classified as problematic. This vulnerability affects unknown code of the component WLAN STA driver. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2025-20673. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in MediaTek MT7902, MT7921, MT7922, MT7925 and MT7927 and classified as problematic. This issue affects some unknown processing of the component WLAN STA driver. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2025-20675. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in MediaTek MT7902, MT7921, MT7922, MT7925 and MT7927. It has been classified as problematic. Affected is an unknown function of the component WLAN STA driver. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2025-20676. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in MediaTek MT7902, MT7921, MT7922, MT7925 and MT7927. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Bluetooth Driver. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2025-20677. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Arris VIP1113 up to 2025-05-30. It has been rated as critical. Affected by this issue is some unknown functionality of the file /usr/bin/gunzip of the component KreaTV SDK. The manipulation leads to improper protection of alternate path.
This vulnerability is handled as CVE-2025-49163. It is possible to launch the attack on the local host. There is no exploit available.
A vulnerability was found in Arris VIP1113 up to 2025-05-30. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component KreaTV SDK. The manipulation leads to use of hard-coded cryptographic key
.
This vulnerability is known as CVE-2025-49164. Attacking locally is a requirement. There is no exploit available.
A vulnerability was found in Arris VIP1113 up to 2025-05-30. It has been classified as critical. Affected is an unknown function of the component KreaTV SDK. The manipulation leads to improper protection of alternate path.
This vulnerability is traded as CVE-2025-49162. It is possible to launch the attack on the physical device. There is no exploit available.
A vulnerability was found in Google Chrome and classified as critical. This issue affects some unknown processing of the component V8. The manipulation leads to out-of-bounds write.
The identification of this vulnerability is CVE-2025-5419. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Google Chrome and classified as critical. This vulnerability affects unknown code of the component Blink. The manipulation leads to use after free.
This vulnerability was named CVE-2025-5068. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.