5.5

CVSS3.1

CVE-2025-40089 - cxl/features: Add check for no entries in cxl_feature_info

In the Linux kernel, the following vulnerability has been resolved: cxl/features: Add check for no entries in cxl_feature_info cxl EDAC calls cxl_feature_info() to get the feature information and if the hardware has no Features support, cxlfs may be passed in as NULL. [ 51.957498] BUG: kernel …

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2025-40102 - KVM: arm64: Prevent access to vCPU events before init

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Prevent access to vCPU events before init Another day, another syzkaller bug. KVM erroneously allows userspace to pend vCPU events for a vCPU that hasn't been initialized yet, leading to KVM interpreting a bunch of un…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2025-40092 - usb: gadget: f_ncm: Refactor bind path to use __free()

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Refactor bind path to use __free() After an bind/unbind cycle, the ncm->notify_req is left stale. If a subsequent bind fails, the unified error label attempts to free this stale request, leading to a NULL poin…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

6.1

CVSS3.1

CVE-2025-50574 -

Cross-site scripting (XSS) vulnerability in blog-details.php in Hiruna Gallage's Glamour Salon Management System v1 allows remote attackers to inject arbitrary web script or HTML via the blog comment section parameter.

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 6:43 p.m.

6.5

CVSS3.1

CVE-2025-57109 -

Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When processing GLTF files with invalid scene node references, the application accesses string members of mesh objects that have been previously freed during actor import operations.

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2025-61121 -

Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., contains a credential leakage vulnerability. Improper handling of cloud service credentials may allow attackers to obtain them and carry out unauthorized actions, such as sensitiv…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

6.1

CVSS3.1

CVE-2025-60950 -

An arbitrary file upload vulnerability in the Data Preparation function of AIxBlock commit f60975 allows attackers to execute arbitrary code via a crafted SVG file.

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2025-61114 -

2nd Line Android App version v1.2.92 and before (package name com.mysecondline.app), developed by AutoBizLine, Inc., contains an improper access control vulnerability in its authentication mechanism. The server only validates the first character of the user_token, enabling attackers to brute force …

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

6.1

CVSS3.1

CVE-2025-63885 -

A stored cross-site scripting (XSS) vulnerability in AIxBlock commit 04f305 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the model_desc field.

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2025-61120 -

AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., contains improper access control vulnerabilities. Exposed credentials in traffic may allow attackers to misuse cloud resources, and predictable verification codes make brute-force ac…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.
Total resulsts: 317452
Page 120 of 31,746
Β« previous page Β» next page
Filters