5.5

CVSS3.1

CVE-2025-68341 - veth: reduce XDP no_direct return section to fix race

In the Linux kernel, the following vulnerability has been resolved: veth: reduce XDP no_direct return section to fix race As explain in commit fa349e396e48 ("veth: Fix race with AF_XDP exposing old or uninitialized descriptors") for veth there is a chance after napi_complete_done() that another Cโ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

4

CVSS3.1

CVE-2025-65713 -

Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.

๐Ÿ“… Published: Dec. 23, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 6, 2026, 5:27 p.m.

10

CVSS3.1

CVE-2025-67109 -

Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.

๐Ÿ“… Published: Dec. 23, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 6, 2026, 5:42 p.m.

10

CVSS3.1

CVE-2025-67108 -

eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.

๐Ÿ“… Published: Dec. 23, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 5:49 p.m.

0.0

CVE-2025-68339 - atm/fore200e: Fix possible data race in fore200e_open()

In the Linux kernel, the following vulnerability has been resolved: atm/fore200e: Fix possible data race in fore200e_open() Protect access to fore200e->available_cell_rate with rate_mtx lock in the error handling path of fore200e_open() to prevent a data race. The field fore200e->available_cell_โ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

7.0

CVSS3.1

CVE-2025-68342 - can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing data

In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing data The URB received in gs_usb_receive_bulk_callback() contains a struct gs_host_frame. The length of the data after the header depends on the gs_โ€ฆ

๐Ÿ“… Published: Dec. 23, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 23, 2025, 2:51 p.m.

9.8

CVSS3.1

CVE-2025-51511 -

Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.

๐Ÿ“… Published: Dec. 23, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 6, 2026, 5:26 p.m.

9.8

CVSS3.1

CVE-2025-50526 -

Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.

๐Ÿ“… Published: Dec. 23, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 2:45 p.m.

6.5

CVSS3.1

CVE-2025-45493 -

Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.

๐Ÿ“… Published: Dec. 23, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 5, 2026, 6:13 p.m.

9.8

CVSS3.1

CVE-2025-29229 -

linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

๐Ÿ“… Published: Dec. 23, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 6, 2026, 5:32 p.m.
Total resulsts: 343996
Page 1955 of 34,400
ยซ previous page ยป next page
Filters