CVE-2025-21839 – KVM Linux Kernel DR6 Load Vulnerability

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop Move the conditional loading of hardware DR6 with the guest’s DR6 value out of the core .vcpu_run() loop to fix a bug where KVM can load hardware with a stale vcpu->arch.dr6. When the […]

CVE-2025-21838 – “Linux USB Gadget Workqueue Queue Flush Denial of Service”

The following table lists the changes that have been made to the CVE-2025-21838 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Mar. 07, 2025 Action […]

CVE-2025-21837 – Linux Kernel io_uring SQE Copying Information Disclosure Vulnerability

In the Linux kernel, the following vulnerability has been resolved: io_uring/uring_cmd: unconditionally copy SQEs at prep time This isn’t generally necessary, but conditions have been observed where SQE data is accessed from the original SQE after prep has been done and outside of the initial issue. Opcode prep handlers must ensure that any SQE related […]

CVE-2025-21836 – Linux Kernel IoUring Buffer Reuse Vulnerability

The following table lists the changes that have been made to the CVE-2025-21836 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Mar. 07, 2025 Action […]

CVE-2025-1315 – InWave Jobs WordPress Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-1315 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 07, 2025 Action […]

CVE-2025-0959 – The Eventer – WordPress Event & Booking Manager Plugin SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-0959 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 07, 2025 Action […]

CVE-2024-9658 – “WordPress School Management System Privilege Escalation Vulnerability”

The School Management System for WordPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0. This is due to the plugin not properly validating a user’s identity prior to updating their details like email and password through the mj_smgt_update_user() and mj_smgt_add_admission() functions, along with a […]

CVE-2024-13904 – Platform.ly for WooCommerce Blind Server-Side Request Forgery Vulnerability

The following table lists the changes that have been made to the CVE-2024-13904 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 07, 2025 Action […]

CVE-2024-12610 – “WordPress School Management System Unauthenticated Post Deletion Vulnerability”

The following table lists the changes that have been made to the CVE-2024-12610 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 07, 2025 Action […]

CVE-2024-13781 – “Hero Maps Premium for WordPress SQL Injection Vulnerability”

The following table lists the changes that have been made to the CVE-2024-13781 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 07, 2025 Action […]