CVE-2025-9516 – Atec Debug Plugin Arbitrary File Read Vulnerability in WordPress
The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 via the ‘custom_log’ parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to view the contents of files outside of the originally intended directory.
CVE-2025-36897 – Apache cd_CnMsgCodec Remote Code Execution Vulnerability
Affected Products The following products are affected by CVE-2025-36897 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet
CVE-2025-36899 – Apache HTTP Server Privilege Escalation Vulnerability
Affected Products The following products are affected by CVE-2025-36899 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet
CVE-2025-36907 – Qualcomm ABL Android Heap Buffer Overflow
In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege via USB fastboot, after a bootloader unlock, with no additional execution privileges needed. User interaction is needed for exploitation.
CVE-2025-36893 – Apache ReadTachyonCommands Uninitialized Data Information Leak
Affected Products The following products are affected by CVE-2025-36893 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet
CVE-2025-36891 – Apache HTTP Server Local File Inclusion
Affected Products The following products are affected by CVE-2025-36891 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet
CVE-2025-36896 – Apache Struts Deserialization RCE
Affected Products The following products are affected by CVE-2025-36896 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet
CVE-2025-36906 – Darwinn MLIR Converter AIDL Heap Buffer Overflow (EoP)
Affected Products The following products are affected by CVE-2025-36906 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet
CVE-2025-36909 – Apache Struts SSRF
Affected Products The following products are affected by CVE-2025-36909 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet
CVE-2025-36892 – Apache HTTP Server HTTP/2 Server Header Injection
Affected Products The following products are affected by CVE-2025-36892 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet