5.5

CVSS3.1

CVE-2025-71233 - PCI: endpoint: Avoid creating sub-groups asynchronously

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Avoid creating sub-groups asynchronously The asynchronous creation of sub-groups by a delayed work could lead to a NULL pointer dereference when the driver directory is removed before the work completes. The crash…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: March 18, 2026, 5:14 p.m.

5.3

CVSS3.1

CVE-2026-2681 - Github.com/supranational/blst: blst cryptographic library: denial of service via out-of-bounds stac…

A flaw was found in the blst cryptographic library. This out-of-bounds stack write vulnerability, specifically in the blst_sha256_bcopy assembly routine, occurs due to a missing zero-length guard. A remote attacker can exploit this by providing a zero-length salt parameter to key generation functio…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 19, 2026, 9:32 p.m.

5.5

CVSS3.1

CVE-2026-23214 - btrfs: reject new transactions if the fs is fully read-only

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject new transactions if the fs is fully read-only [BUG] There is a bug report where a heavily fuzzed fs is mounted with all rescue mount options, which leads to the following warnings during unmount: BTRFS: Transacti…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: March 18, 2026, 8:34 p.m.

7.8

CVSS3.1

CVE-2026-23216 - scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count()

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() In iscsit_dec_conn_usage_count(), the function calls complete() while holding the conn->conn_usage_lock. As soon as complete() is invoked, the waiter (such …

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: March 18, 2026, 8:28 p.m.

9.1

CVSS3.1

CVE-2025-70146 -

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a …

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 20, 2026, 8:07 p.m.

8.8

CVSS3.1

CVE-2026-2648 - chromium-browser: Heap buffer overflow in PDFium

Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file. (Chromium security severity: High)

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

5.5

CVSS3.1

CVE-2026-23218 - gpio: loongson-64bit: Fix incorrect NULL check after devm_kcalloc()

In the Linux kernel, the following vulnerability has been resolved: gpio: loongson-64bit: Fix incorrect NULL check after devm_kcalloc() Fix incorrect NULL check in loongson_gpio_init_irqchip(). The function checks chip->parent instead of chip->irq.parents.

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: March 18, 2026, 5:31 p.m.

8.8

CVSS3.1

CVE-2025-70064 -

PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after authentication. This…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 9:03 p.m.

7.1

CVSS3.1

CVE-2025-71231 - crypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode

In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode The local variable 'i' is initialized with -EINVAL, but the for loop immediately overwrites it and -EINVAL is never returned. If no empty compression mode …

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: March 18, 2026, 5:18 p.m.

8.8

CVSS3.1

CVE-2026-2650 - chromium-browser: Heap buffer overflow in Media

Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.
Total resulsts: 343924
Page 1077 of 34,393
Β« previous page Β» next page
Filters