Overview
- Red Hat
- Red Hat Enterprise Linux 6
- yelp
03 Apr 2025
Published
11 Nov 2025
Updated
CVSS
Pending
EPSS
0.14%
KEV
Description
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
Statistics
- 1 Post
Last activity: 19 hours ago
Overview
Description
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream
This commit addresses a null pointer dereference issue in the
`commit_planes_for_stream` function at line 4140. The issue could occur
when `top_pipe_to_program` is null.
The fix adds a check to ensure `top_pipe_to_program` is not null before
accessing its stream_res. This prevents a null pointer dereference.
Reported by smatch:
drivers/gpu/drm/amd/amdgpu/../display/dc/core/dc.c:4140 commit_planes_for_stream() error: we previously assumed 'top_pipe_to_program' could be null (see line 3906)
Statistics
- 1 Post
Last activity: 18 hours ago
Bluesky
Overview
- ameliabooking
- Booking for Appointments and Events Calendar – Amelia
16 Nov 2025
Published
16 Nov 2025
Updated
CVSS v3.1
HIGH (7.5)
EPSS
0.06%
KEV
Description
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Statistics
- 1 Post
Last activity: 12 hours ago
Fediverse
⚠️ CVE-2025-12482: HIGH severity SQL Injection in Amelia Booking plugin for WordPress (<=1.2.35). Unauthenticated attackers can extract sensitive DB data via the search parameter. Monitor & restrict access. https://radar.offseq.com/threat/cve-2025-12482-cwe-89-improper-neutralization-of-s-530517f2 #OffSeq #WordPress #Infosec #SQLInjection
Overview
- JetBrains
- YouTrack
10 Nov 2025
Published
11 Nov 2025
Updated
CVSS v3.1
CRITICAL (9.6)
EPSS
0.00%
KEV
Description
In JetBrains YouTrack before 2025.3.104432 misconfiguration in the Junie could lead to exposure of the global Junie token
Statistics
- 1 Post
Last activity: 3 hours ago