4.3

CVSS3.1

CVE-2025-5933 - RD Contacto <= 1.4 - Cross-Site Request Forgery to Settings Update

The RD Contacto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the rdWappUpdateData() function. This makes it possible for unauthenticated attackers to update plugin settings via a f…

πŸ“… Published: July 4, 2025, 1:44 a.m. πŸ”„ Last Modified: July 4, 2025, 3:15 a.m.

5.3

CVSS3.1

CVE-2025-6786 - DocCheck Login <= 1.1.5 - Unauthorized Post Access

The DocCheck Login plugin for WordPress is vulnerable to unauthorized post access in all versions up to, and including, 1.1.5. This is due to plugin redirecting a user to login on a password protected post after the page has loaded. This makes it possible for unauthenticated attackers to read posts…

πŸ“… Published: July 4, 2025, 1:43 a.m. πŸ”„ Last Modified: July 4, 2025, 3:15 a.m.

7.8

CVSS3.1

CVE-2025-49809 - mtr: From CVEorg collector

mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect consequence of Homebrew not installing setuid binaries.

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: July 4, 2025, 1:15 p.m.

5.5

CVSS3.1

CVE-2025-38175 - binder: fix yet another UAF in binder_devices

In the Linux kernel, the following vulnerability has been resolved: binder: fix yet another UAF in binder_devices Commit e77aff5528a18 ("binderfs: fix use-after-free in binder_devices") addressed a use-after-free where devices could be released without first being removed from the binder_devices …

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: July 4, 2025, 11:15 a.m.

5.5

CVSS3.1

CVE-2025-38233 - powerpc64/ftrace: fix clobbered r15 during livepatching

In the Linux kernel, the following vulnerability has been resolved: powerpc64/ftrace: fix clobbered r15 during livepatching While r15 is clobbered always with PPC_FTRACE_OUT_OF_LINE, it is not restored in livepatch sequence leading to not so obvious fails like below: BUG: Unable to handle kern…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

5.5

CVSS3.1

CVE-2025-38222 - ext4: inline: fix len overflow in ext4_prepare_inline_data

In the Linux kernel, the following vulnerability has been resolved: ext4: inline: fix len overflow in ext4_prepare_inline_data When running the following code on an ext4 filesystem with inline_data feature enabled, it will lead to the bug below. fd = open("file1", O_RDWR | O_CREAT | O_TR…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

5.5

CVSS3.1

CVE-2025-38217 - hwmon: (ftsteutates) Fix TOCTOU race in fts_read()

In the Linux kernel, the following vulnerability has been resolved: hwmon: (ftsteutates) Fix TOCTOU race in fts_read() In the fts_read() function, when handling hwmon_pwm_auto_channels_temp, the code accesses the shared variable data->fan_source[channel] twice without holding any locks. It is fir…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

7.0

CVSS3.1

CVE-2025-38210 - configfs-tsm-report: Fix NULL dereference of tsm_ops

In the Linux kernel, the following vulnerability has been resolved: configfs-tsm-report: Fix NULL dereference of tsm_ops Unlike sysfs, the lifetime of configfs objects is controlled by userspace. There is no mechanism for the kernel to find and delete all created config-items. Instead, the config…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

7.0

CVSS3.1

CVE-2025-38208 - smb: client: add NULL check in automount_fullpath

In the Linux kernel, the following vulnerability has been resolved: smb: client: add NULL check in automount_fullpath page is checked for null in __build_path_from_dentry_optional_prefix when tcon->origin_fullpath is not set. However, the check is missing when it is set. Add a check to prevent a …

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

5.5

CVSS3.1

CVE-2025-38207 - mm: fix uprobe pte be overwritten when expanding vma

In the Linux kernel, the following vulnerability has been resolved: mm: fix uprobe pte be overwritten when expanding vma Patch series "Fix uprobe pte be overwritten when expanding vma". This patch (of 4): We encountered a BUG alert triggered by Syzkaller as follows: BUG: Bad rss-counter sta…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.
Total resulsts: 300547
Page 18 of 30,055
Β« previous page Β» next page
Filters