A vulnerability was found in Spotify Embed Creator Plugin up to 1.0.5 on WordPress. It has been classified as problematic. Impacted is the function spotify of the component Shortcode Handler. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2025-9879. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Side Slide Responsive Menu Plugin up to 1.0 on WordPress and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation results in cross-site request forgery.
This vulnerability is reported as CVE-2025-9880. The attack can be launched remotely. No exploit exists.
A vulnerability has been found in LWS Cleaner Plugin up to 2.4.1.3 on WordPress and classified as problematic. This vulnerability affects the function lws_cl_delete_file of the file wp-config.php. The manipulation leads to denial of service.
This vulnerability is documented as CVE-2025-8575. The attack can be initiated remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, was found in Liferay Portal and DXP. This affects an unknown part. Executing manipulation can lead to authorization bypass.
This vulnerability is registered as CVE-2025-43782. It is possible to launch the attack remotely. No exploit is available.
A vulnerability, which was classified as problematic, has been found in OpenPrinting CUPS up to 2.4.12. Affected by this issue is some unknown functionality. Performing manipulation results in denial of service.
This vulnerability is cataloged as CVE-2025-58364. The attack must originate from the local network. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic was found in Ultimate Blogroll Plugin up to 2.5.2 on WordPress. Affected by this vulnerability is an unknown functionality of the component Setting Handler. Such manipulation leads to cross-site request forgery.
This vulnerability is listed as CVE-2025-9881. The attack may be performed from remote. There is no available exploit.
A vulnerability classified as problematic has been found in Embed Google Datastudio Plugin up to 1.0.0 on WordPress. Affected is the function egds of the component Shortcode Handler. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2025-9877. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability described as problematic has been identified in Wind River Studio Developer. This impacts an unknown function. The manipulation results in privilege context switching error.
This vulnerability is identified as CVE-2025-26499. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is recommended.
This post first appeared on blog.netwrix.com and was written by Dirk Schrader. Data Security Posture Management (DSPM) delivers a data-first approach to security by discovering, classifying, and continuously monitoring sensitive data across your hybrid IT environment. This blog outlines how DSPM integrates into every layer of your modern security architecture, from IAM and DLP to SIEM/SOAR and DevSecOps. When paired with Netwrix solutions, DSPM becomes a proactive … Continued
In May 2025, the European Union levied financial sanctions on the owners of Stark Industries Solutions Ltd., a bulletproof hosting provider that materialized two weeks before Russia invaded Ukraine and quickly became a top source of Kremlin-linked cyberattacks and disinformation campaigns. But new data shows those sanctions have done little to stop Stark from simply rebranding and transferring their assets to other corporate entities controlled by its original hosting providers.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.6.102/6.12.43/6.16.3. This affects the function flush_cache_vmap of the component parisc. The manipulation leads to privilege escalation.
This vulnerability is referenced as CVE-2025-39781. The attack needs to be initiated within the local network. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in OpenPrinting CUPS up to 2.4.12. The impacted element is an unknown function. Executing manipulation can lead to improper authentication.
The identification of this vulnerability is CVE-2025-58060. The attack can only be executed locally. There is no exploit available.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Linux Kernel up to 5.15.189/6.1.148/6.6.102/6.12.43/6.16.3. The affected element is the function xfer_cb. Performing manipulation results in double free.
This vulnerability was named CVE-2025-39790. The attack needs to be approached within the local network. There is no available exploit.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.17-rc2. Impacted is the function br_multicast_query_expired. Such manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2025-39773. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.16.3. It has been rated as critical. This issue affects the function skcipher_walk of the component crypto. This manipulation causes allocation of resources.
This vulnerability is handled as CVE-2025-39789. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Linux Kernel up to 6.16.3. It has been declared as critical. This vulnerability affects the function list_del of the component PCI. The manipulation of the argument epf_group results in use after free.
This vulnerability is known as CVE-2025-39783. Access to the local network is required for this attack. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.16.3. It has been classified as critical. This affects the function syscalib_mode of the component iio. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2025-39786. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 6.16.1/6.17-rc1 and classified as critical. Affected by this issue is the function refcount_inc_not_zero of the component netfilter. Executing manipulation can lead to memory leak.
This vulnerability appears as CVE-2025-39764. The attacker needs to be present on the local network. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.16.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the component crypto. Performing manipulation results in incorrect control flow.
This vulnerability is reported as CVE-2025-39777. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.