7.5

CVSS3.1

CVE-2025-61118 -

mCarFix Motorists App version 2.3 (package name com.skytop.mcarfix), developed by Paniel Mwaura, contains improper access control vulnerabilities. Attackers may bypass verification to arbitrarily register accounts, and by tampering with sequential numeric IDs, gain unauthorized access to user data …

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

5.5

CVSS3.1

CVE-2025-40098 - ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state()

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state() Return value of a function acpi_evaluate_dsm() is dereferenced without checking for NULL, but it is usually checked for this function. acpi_evalu…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2025-40097 - ALSA: hda: Fix missing pointer check in hda_component_manager_init function

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix missing pointer check in hda_component_manager_init function The __component_match_add function may assign the 'matchptr' pointer the value ERR_PTR(-ENOMEM), which will subsequently be dereferenced. The call stack…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

7.0

CVSS3.1

CVE-2025-40096 - drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies When adding dependencies with drm_sched_job_add_dependency(), that function consumes the fence reference both on success and failure, so in the latter ca…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2025-40095 - usb: gadget: f_rndis: Refactor bind path to use __free()

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_rndis: Refactor bind path to use __free() After an bind/unbind cycle, the rndis->notify_req is left stale. If a subsequent bind fails, the unified error label attempts to free this stale request, leading to a NULL …

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2025-40093 - usb: gadget: f_ecm: Refactor bind path to use __free()

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ecm: Refactor bind path to use __free() After an bind/unbind cycle, the ecm->notify_req is left stale. If a subsequent bind fails, the unified error label attempts to free this stale request, leading to a NULL poin…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

7.5

CVSS3.1

CVE-2025-61115 -

ABC Fine Wine & Spirits Android App version v.11.27.5 and before (package name com.cta.abcfinewineandspirits), developed by ABC Liquors, Inc., contains an improper access control vulnerability in its login mechanism. The application does not properly validate user passwords during authentication, a…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.0

CVSS3.1

CVE-2025-40091 - ixgbe: fix too early devlink_free() in ixgbe_remove()

In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix too early devlink_free() in ixgbe_remove() Since ixgbe_adapter is embedded in devlink, calling devlink_free() prematurely in the ixgbe_remove() path can lead to UAF. Move devlink_free() to the end. KASAN report: BUG…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

7.5

CVSS3.1

CVE-2025-63422 -

Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to arbitrarily change the administrator username and password via sending a crafted GET request.

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

6.1

CVSS3.1

CVE-2025-50736 -

An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external websites via the file parameter to the /gradio_api endpoint. This vulnerability could be exploited for phishing attacks or t…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 4:16 p.m.
Total resulsts: 317435
Page 116 of 31,744
Β« previous page Β» next page
Filters