F5 Fixes HTTP/2 Vulnerability Enabling Massive DoS Attacks

F5 Fixes HTTP/2 Vulnerability Enabling Massive DoS Attacks F5 Networks has disclosed a new HTTP/2 vulnerability affecting multiple BIG-IP products that could allow remote attackers to launch denial-of-service attacks against corporate networks. The security f … Read more Published Date: Aug 16, 2025 (3 hours, 38 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-54500

CVE-2025-8878 – ProfilePress WordPress Arbitrary Shortcode Execution Vulnerability

CVE ID : CVE-2025-8878 Published : Aug. 16, 2025, 12:15 p.m. | 25 minutes ago Description : The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.4. This is due to […]

CVE-2025-8142 – Soledad Theme for WordPress Local File Inclusion Vulnerability

CVE ID : CVE-2025-8142 Published : Aug. 16, 2025, 12:15 p.m. | 25 minutes ago Description : The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via the ‘header_layout’ parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute […]

CVE-2025-8105 – Soledad Theme for WordPress Shortcode Execution Vulnerability

CVE ID : CVE-2025-8105 Published : Aug. 16, 2025, 12:15 p.m. | 25 minutes ago Description : The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the software allowing users to execute an action that does not properly validate a value […]

CVE-2025-8143 – Soledad WordPress Stored Cross-Site Scripting

CVE ID : CVE-2025-8143 Published : Aug. 16, 2025, 12:15 p.m. | 25 minutes ago Description : The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pcsml_smartlists_h’ parameter in all versions up to, and including, 8.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with […]

CVE-2025-38552 – Linux Kernel MPTCP Subflow Creation Race Condition Vulnerability

The following table lists the changes that have been made to the CVE-2025-38552 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Aug. 16, 2025 Action […]

CVE-2025-38551 – “Virtio-Net Deadlock Vulnerability”

The following table lists the changes that have been made to the CVE-2025-38551 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Aug. 16, 2025 Action […]

CVE-2025-38550 – Linux Kernel IPv6 Multicast Delayed Put Reference Vulnerability

The following table lists the changes that have been made to the CVE-2025-38550 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Aug. 16, 2025 Action […]

CVE-2025-38549 – Linux efivarfs Memory Leak

In the Linux kernel, the following vulnerability has been resolved: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths When processing mount options, efivarfs allocates efivarfs_fs_info (sfi) early in fs_context initialization. However, sfi is associated with the superblock and typically freed when the superblock is destroyed. If the fs_context is released (final put) before […]

CVE-2025-38544 – Linux Kernel rxrpc Call ID Preallocation Collision Vulnerability

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix bug due to prealloc collision When userspace is using AF_RXRPC to provide a server, it has to preallocate incoming calls and assign to them call IDs that will be used to thread related recvmsg() and sendmsg() together. The preallocated call IDs will automatically […]