7.8

CVSS3.1

CVE-2026-23233 - f2fs: fix to avoid mapping wrong physical block for swapfile

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid mapping wrong physical block for swapfile Xiaolong Guo reported a f2fs bug in bugzilla [1] [1] https://bugzilla.kernel.org/show_bug.cgi?id=220951 Quoted: "When using stress-ng's swap stress test on F2FS file…

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 5 p.m.

9.8

CVSS3.1

CVE-2025-70220 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4.

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: March 6, 2026, 5:51 p.m.

9.8

CVSS3.1

CVE-2025-66678 -

An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitrary read and write operations via a crafted request.

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: March 9, 2026, 5:33 p.m.

9.8

CVSS3.1

CVE-2025-70225 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfig component

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: March 6, 2026, 5:47 p.m.

9.6

CVSS3.1

CVE-2025-69969 -

A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is…

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: March 9, 2026, 5:26 p.m.

7.5

CVSS3.1

CVE-2026-26514 - Argument Injection in Traceroute Module Allows Denial of Service

An Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute module uses shlex.Split to parse user input without validation, allowing remote attackers to inject arbitrary flags (e.g., -w, -q) via the q parameter. This can be exploited to cause a Denial of Service (…

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 2 p.m.

5.5

CVSS3.1

CVE-2026-23237 - platform/x86: classmate-laptop: Add missing NULL pointer checks

In the Linux kernel, the following vulnerability has been resolved: platform/x86: classmate-laptop: Add missing NULL pointer checks In a few places in the Classmate laptop driver, code using the accel object may run before that object's address is stored in the driver data of the input device usi…

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 1:45 p.m.

7.8

CVSS3.1

CVE-2026-23234 - f2fs: fix to avoid UAF in f2fs_write_end_io()

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid UAF in f2fs_write_end_io() As syzbot reported an use-after-free issue in f2fs_write_end_io(). It is caused by below race condition: loop device umount - worker_thread - loop_process_work - do_req_fileba…

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 5 p.m.

5.5

CVSS3.1

CVE-2026-23238 - romfs: check sb_set_blocksize() return value

In the Linux kernel, the following vulnerability has been resolved: romfs: check sb_set_blocksize() return value romfs_fill_super() ignores the return value of sb_set_blocksize(), which can fail if the requested block size is incompatible with the block device's configuration. This can be trigge…

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 1:15 p.m.

9.8

CVSS3.1

CVE-2026-26478 - Remote Command Injection in Mobvoi Tichome Mini Smart Speaker Enabling Root Execution

A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code as the root account.

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 1:30 p.m.
Total resulsts: 349182
Page 1355 of 34,919
Β« previous page Β» next page
Filters