5.8

CVSS3.1

CVE-2026-24137 - sigstore legacy TUF client allows for arbitrary file writes with target cache path traversal

sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path by joining a cache base directory with a target name sourced from sig…

πŸ“… Published: Jan. 23, 2026, 12:04 a.m. πŸ”„ Last Modified: April 18, 2026, 3:30 a.m.

5.5

CVSS3.1

CVE-2026-22983 - net: do not write to msg_get_inq in callee

In the Linux kernel, the following vulnerability has been resolved: net: do not write to msg_get_inq in callee NULL pointer dereference fix. msg_get_inq is an input field from caller to callee. Don't set it in the callee, as the caller may not clear it on struct reuse. This is a kernel-internal…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 3:15 a.m.

9.8

CVSS3.1

CVE-2025-70457 -

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save pro…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Jan. 30, 2026, 5:59 p.m.

7.5

CVSS3.1

CVE-2025-69907 -

An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and access control on the /omnidocs/GetListofCabinet API endpoint. A remote attacker can access this endpoint without valid credentials to retrieve sensitive internal configuration inform…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-70985 -

Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Jan. 30, 2026, 9:27 p.m.

5.5

CVSS3.1

CVE-2025-71151 - cifs: Fix memory and information leak in smb3_reconfigure()

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory and information leak in smb3_reconfigure() In smb3_reconfigure(), if smb3_sync_session_ctx_passwords() fails, the function returns immediately without freeing and erasing the newly allocated new_password and new_…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 8:29 p.m.

5.5

CVSS3.1

CVE-2026-22987 - net/sched: act_api: avoid dereferencing ERR_PTR in tcf_idrinfo_destroy

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: avoid dereferencing ERR_PTR in tcf_idrinfo_destroy syzbot reported a crash in tc_act_in_hw() during netns teardown where tcf_idrinfo_destroy() passed an ERR_PTR(-EBUSY) value as a tc_action pointer, leading to…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 3:15 p.m.

5.5

CVSS3.1

CVE-2025-71150 - ksmbd: Fix refcount leak when invalid session is found on session lookup

In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix refcount leak when invalid session is found on session lookup When a session is found but its state is not SMB2_SESSION_VALID, It indicates that no valid session was found, but it is missing to decrement the reference …

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 5:30 p.m.

5.5

CVSS3.1

CVE-2025-71146 - netfilter: nf_conncount: fix leaked ct in error paths

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix leaked ct in error paths There are some situations where ct might be leaked as error paths are skipping the refcounted check and return immediately. In order to solve it make sure that the check is al…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 8:25 p.m.

5.9

CVSS3.1

CVE-2025-67231 -

A reflected cross-site scripting (XSS) vulnerability in ToDesktop Builder v0.33.1 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload.

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Jan. 29, 2026, 6:42 p.m.
Total resulsts: 349182
Page 1984 of 34,919
Β« previous page Β» next page
Filters