24h | 7d | 30d

Overview

  • Red Hat
  • Red Hat Enterprise Linux 6
  • yelp

03 Apr 2025
Published
11 Nov 2025
Updated

CVSS
Pending
EPSS
0.14%

KEV

Description

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture
Critical vulnerability (CVE-2025-3155) found in Yelp, the default help viewer for #GNOME Linux distros (Ubuntu, Fedora). Allows local file theft & script execution. Patch to v42.2+ now! Read more: 👉 tinyurl.com/2pm6xp8p #Mageia
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Linux
  • Linux

21 Oct 2024
Published
03 Nov 2025
Updated

CVSS
Pending
EPSS
0.04%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream This commit addresses a null pointer dereference issue in the `commit_planes_for_stream` function at line 4140. The issue could occur when `top_pipe_to_program` is null. The fix adds a check to ensure `top_pipe_to_program` is not null before accessing its stream_res. This prevents a null pointer dereference. Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/core/dc.c:4140 commit_planes_for_stream() error: we previously assumed 'top_pipe_to_program' could be null (see line 3906)

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture
The Phantom Menace: How a Fake CVE-2024-49913 Exploit is Hijacking Systems Globally Introduction: A sophisticated social engineering campaign is exploiting the trust of IT professionals by circulating a fake proof-of-concept (PoC) exploit for a non-existent critical vulnerability, CVE-2024-49913.…
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • ameliabooking
  • Booking for Appointments and Events Calendar – Amelia

16 Nov 2025
Published
16 Nov 2025
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.06%

KEV

Description

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture

⚠️ CVE-2025-12482: HIGH severity SQL Injection in Amelia Booking plugin for WordPress (<=1.2.35). Unauthenticated attackers can extract sensitive DB data via the search parameter. Monitor & restrict access. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • JetBrains
  • YouTrack

10 Nov 2025
Published
11 Nov 2025
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
0.00%

KEV

Description

In JetBrains YouTrack before 2025.3.104432 misconfiguration in the Junie could lead to exposure of the global Junie token

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture
📌 Critical JetBrains YouTrack Flaw Exposes AI Agent Token (CVE-2025-64689) https://www.cyberhub.blog/article/15652-critical-jetbrains-youtrack-flaw-exposes-ai-agent-token-cve-2025-64689
  • 0
  • 0
  • 0
  • 3h ago
Showing 11 to 14 of 14 CVEs