CVE-2021-47106 Vulnerability Analysis & Exploit Details

CVE-2021-47106
Vulnerability Scoring

7.8
/10
Very High Risk

Highly exploitable, CVE-2021-47106 poses a critical security risk that could lead to severe breaches.

Attack Complexity Details

  • Attack Complexity: Low
    Exploits can be performed without significant complexity or special conditions.
  • Attack Vector: Local
    Vulnerability requires local system access.
  • Privileges Required: Low
    Some privileges are necessary to exploit the vulnerability.
  • Scope: Unchanged
    Exploit remains within the originally vulnerable component.
  • User Interaction: None
    No user interaction is necessary for exploitation.

CVE-2021-47106 Details

Status: Analyzed

Last updated: 🕔 14 Jan 2025, 17:26 UTC
Originally published on: 🕖 04 Mar 2024, 19:15 UTC

Time between publication and last update: 315 days

CVSS Release: version 3

CVSS3 Source

nvd@nist.gov

CVSS3 Type

Primary

CVSS3 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2021-47106 Vulnerability Summary

CVE-2021-47106: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nft_set_catchall_destroy() We need to use list_for_each_entry_safe() iterator because we can not access @catchall after kfree_rcu() call. syzbot reported: BUG: KASAN: use-after-free in nft_set_catchall_destroy net/netfilter/nf_tables_api.c:4486 [inline] BUG: KASAN: use-after-free in nft_set_destroy net/netfilter/nf_tables_api.c:4504 [inline] BUG: KASAN: use-after-free in nft_set_destroy+0x3fd/0x4f0 net/netfilter/nf_tables_api.c:4493 Read of size 8 at addr ffff8880716e5b80 by task syz-executor.3/8871 CPU: 1 PID: 8871 Comm: syz-executor.3 Not tainted 5.16.0-rc5-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106 print_address_description.constprop.0.cold+0x8d/0x2ed mm/kasan/report.c:247 __kasan_report mm/kasan/report.c:433 [inline] kasan_report.cold+0x83/0xdf mm/kasan/report.c:450 nft_set_catchall_destroy net/netfilter/nf_tables_api.c:4486 [inline] nft_set_destroy net/netfilter/nf_tables_api.c:4504 [inline] nft_set_destroy+0x3fd/0x4f0 net/netfilter/nf_tables_api.c:4493 __nft_release_table+0x79f/0xcd0 net/netfilter/nf_tables_api.c:9626 nft_rcv_nl_event+0x4f8/0x670 net/netfilter/nf_tables_api.c:9688 notifier_call_chain+0xb5/0x200 kernel/notifier.c:83 blocking_notifier_call_chain kernel/notifier.c:318 [inline] blocking_notifier_call_chain+0x67/0x90 kernel/notifier.c:306 netlink_release+0xcb6/0x1dd0 net/netlink/af_netlink.c:788 __sock_release+0xcd/0x280 net/socket.c:649 sock_close+0x18/0x20 net/socket.c:1314 __fput+0x286/0x9f0 fs/file_table.c:280 task_work_run+0xdd/0x1a0 kernel/task_work.c:164 tracehook_notify_resume include/linux/tracehook.h:189 [inline] exit_to_user_mode_loop kernel/entry/common.c:175 [inline] exit_to_user_mode_prepare+0x27e/0x290 kernel/entry/common.c:207 __syscall_exit_to_user_mode_work kernel/entry/common.c:289 [inline] syscall_exit_to_user_mode+0x19/0x60 kernel/entry/common.c:300 do_syscall_64+0x42/0xb0 arch/x86/entry/common.c:86 entry_SYSCALL_64_after_hwframe+0x44/0xae RIP: 0033:0x7f75fbf28adb Code: 0f 05 48 3d 00 f0 ff ff 77 45 c3 0f 1f 40 00 48 83 ec 18 89 7c 24 0c e8 63 fc ff ff 8b 7c 24 0c 41 89 c0 b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 35 44 89 c7 89 44 24 0c e8 a1 fc ff ff 8b 44 RSP: 002b:00007ffd8da7ec10 EFLAGS: 00000293 ORIG_RAX: 0000000000000003 RAX: 0000000000000000 RBX: 0000000000000004 RCX: 00007f75fbf28adb RDX: 00007f75fc08e828 RSI: ffffffffffffffff RDI: 0000000000000003 RBP: 00007f75fc08a960 R08: 0000000000000000 R09: 00007f75fc08e830 R10: 00007ffd8da7ed10 R11: 0000000000000293 R12: 00000000002067c3 R13: 00007ffd8da7ed10 R14: 00007f75fc088f60 R15: 0000000000000032 </TASK> Allocated by task 8886: kasan_save_stack+0x1e/0x50 mm/kasan/common.c:38 kasan_set_track mm/kasan/common.c:46 [inline] set_alloc_info mm/kasan/common.c:434 [inline] ____kasan_kmalloc mm/kasan/common.c:513 [inline] ____kasan_kmalloc mm/kasan/common.c:472 [inline] __kasan_kmalloc+0xa6/0xd0 mm/kasan/common.c:522 kasan_kmalloc include/linux/kasan.h:269 [inline] kmem_cache_alloc_trace+0x1ea/0x4a0 mm/slab.c:3575 kmalloc include/linux/slab.h:590 [inline] nft_setelem_catchall_insert net/netfilter/nf_tables_api.c:5544 [inline] nft_setelem_insert net/netfilter/nf_tables_api.c:5562 [inline] nft_add_set_elem+0x232e/0x2f40 net/netfilter/nf_tables_api.c:5936 nf_tables_newsetelem+0x6ff/0xbb0 net/netfilter/nf_tables_api.c:6032 nfnetlink_rcv_batch+0x1710/0x25f0 net/netfilter/nfnetlink.c:513 nfnetlink_rcv_skb_batch net/netfilter/nfnetlink.c:634 [inline] nfnetlink_rcv+0x3af/0x420 net/netfilter/nfnetlink.c:652 netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline] netlink_unicast+0x533/0x7d0 net/netlink/af_netlink.c:1345 netlink_sendmsg+0x904/0xdf0 net/netlink/af_netlink.c:1921 sock_sendmsg_nosec net/ ---truncated---

Assessing the Risk of CVE-2021-47106

Access Complexity Graph

The exploitability of CVE-2021-47106 depends on two key factors: attack complexity (the level of effort required to execute an exploit) and privileges required (the access level an attacker needs).

Exploitability Analysis for CVE-2021-47106

CVE-2021-47106 presents an accessible attack vector with minimal effort required. Restricting access controls and implementing security updates are critical to reducing exploitation risks.

Understanding AC and PR

A lower complexity and fewer privilege requirements make exploitation easier. Security teams should evaluate these aspects to determine the urgency of mitigation strategies, such as patch management and access control policies.

Attack Complexity (AC) measures the difficulty in executing an exploit. A high AC means that specific conditions must be met, making an attack more challenging, while a low AC means the vulnerability can be exploited with minimal effort.

Privileges Required (PR) determine the level of system access necessary for an attack. Vulnerabilities requiring no privileges are more accessible to attackers, whereas high privilege requirements limit exploitation to authorized users with elevated access.

CVSS Score Breakdown Chart

Above is the CVSS Sub-score Breakdown for CVE-2021-47106, illustrating how Base, Impact, and Exploitability factors combine to form the overall severity rating. A higher sub-score typically indicates a more severe or easier-to-exploit vulnerability.

CIA Impact Analysis

Below is the Impact Analysis for CVE-2021-47106, showing how Confidentiality, Integrity, and Availability might be affected if the vulnerability is exploited. Higher values usually signal greater potential damage.

  • Confidentiality: High
    Exploiting CVE-2021-47106 can result in unauthorized access to sensitive data, severely compromising data privacy.
  • Integrity: High
    CVE-2021-47106 could allow unauthorized modifications to data, potentially affecting system reliability and trust.
  • Availability: High
    CVE-2021-47106 can disrupt system operations, potentially causing complete denial of service (DoS).

Exploit Prediction Scoring System (EPSS)

The EPSS score estimates the probability that this vulnerability will be exploited in the near future.

EPSS Score: 0.043% (probability of exploit)

EPSS Percentile: 11.87% (lower percentile = lower relative risk)
This vulnerability is less risky than approximately 88.13% of others.

CVE-2021-47106 References

External References

CWE Common Weakness Enumeration

CWE-416

Vulnerable Configurations

  • cpe:2.3:o:linux:linux_kernel:5.13:-:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13:-:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.0-52:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.0-52:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.1:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.1:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.2:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.2:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.3:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.3:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.4:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.4:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.5:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.5:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.6:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.6:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.7:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.7:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.8:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.8:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.9:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.9:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.10:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.10:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.11:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.11:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.12:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.12:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.13:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.13:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.14:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.14:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.15:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.15:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.16:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.16:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.17:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.17:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.18:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.18:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13.19:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13.19:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13:rc1:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13:rc1:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13:rc2:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13:rc2:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13:rc3:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13:rc3:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13:rc4:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13:rc4:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13:rc5:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13:rc5:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13:rc6:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13:rc6:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.13:rc7:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.13:rc7:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14:-:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14:-:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.1:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.1:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.2:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.2:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.3:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.3:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.4:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.4:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.5:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.5:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.6:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.6:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.7:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.7:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.8:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.8:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.9:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.9:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.10:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.10:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.11:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.11:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.12:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.12:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.13:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.13:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.14:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.14:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.15:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.15:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.16:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.16:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.17:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.17:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.18:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.18:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.19:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.19:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.20:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.20:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14:rc1:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14:rc1:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14:rc2:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14:rc2:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14:rc3:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14:rc3:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14:rc4:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14:rc4:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14:rc5:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14:rc5:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.14:rc6:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.14:rc6:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15:-:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15:-:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.0:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.0:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.0-58:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.0-58:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.1:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.1:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.2:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.2:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.3:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.3:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.3:-:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.3:-:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.4:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.4:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.5:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.5:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.6:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.6:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.7:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.7:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.8:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.8:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.9:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.9:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.10:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.10:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.11:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.11:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.16:rc1:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.16:rc1:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.16:rc2:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.16:rc2:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.16:rc3:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.16:rc3:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.16:rc4:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.16:rc4:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.16:rc5:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.16:rc5:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.16:rc6:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.16:rc6:*:*:*:*:*:*

Protect Your Infrastructure against CVE-2021-47106: Combat Critical CVE Threats

Stay updated with real-time CVE vulnerabilities and take action to secure your systems. Enhance your cybersecurity posture with the latest threat intelligence and mitigation techniques. Develop the skills necessary to defend against CVEs and secure critical infrastructures. Join the top cybersecurity professionals safeguarding today's infrastructures.

Other 5 Recently Published CVEs Vulnerabilities

  • CVE-2025-2129 – A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The manipulation leads to insecur...
  • CVE-2025-2127 – A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of th...
  • CVE-2025-2126 – A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the...
  • CVE-2025-2125 – A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. This vulnerability affects unknown code of the file /v2...
  • CVE-2025-2124 – A vulnerability, which was classified as problematic, was found in Control iD RH iD 25.2.25.0. This affects an unknown part of the file /v2/custome...