Author: Angelo Barbosa

CVE-2025-21642 | Linux Kernel up to 6.6.71/6.12.9/6.13-rc6 sysctl null pointer dereference

A vulnerability was found in Linux Kernel up to 6.6.71/6.12.9/6.13-rc6. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component sysctl. The manipulation leads to null pointer dereference. This vulnerability is known as CVE-2025-21642. Access to the local network is required for this attack to succeed. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2025-21634 | Linux Kernel up to 6.12.9/6.13-rc6 cpuset get_online_cpus deadlock

A vulnerability was found in Linux Kernel up to 6.12.9/6.13-rc6. It has been classified as critical. Affected is the function get_online_cpus of the component cpuset. The manipulation leads to deadlock. This vulnerability is traded as CVE-2025-21634. Access to the local network is required for this attack. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2025-0576 | Mobotix M15 4.3.4.83 p_qual cross site scripting

A vulnerability was found in Mobotix M15 4.3.4.83 and classified as problematic. This issue affects some unknown processing of the file /control/player?center&eventlist&pda&dummy_for_reload=1736177631&p_evt. The manipulation of the argument p_qual leads to cross site scripting. The identification of this vulnerability is CVE-2025-0576. The attack may be initiated remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any way. It is recommended to apply restrictive firewalling. The vendor was contacted early about this disclosure but did not respond in any...

Read More

CVE-2025-0575 | Union Bank of India Vyom 8.0.34 on Android Rooting Detection protection mechanism

A vulnerability has been found in Union Bank of India Vyom 8.0.34 on Android and classified as problematic. This vulnerability affects unknown code of the component Rooting Detection. The manipulation leads to protection mechanism failure. This vulnerability was named CVE-2025-0575. The attack needs to be approached locally. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any way. The vendor was contacted early about this disclosure but did not respond in any...

Read More

CVE-2024-8722 | Soflyy WP All Import Pro Plugin up to 4.9.7 on WordPress cross site scripting

A vulnerability, which was classified as problematic, was found in Soflyy WP All Import Pro Plugin up to 4.9.7 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2024-8722. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More