5.5

CVSS3.1

CVE-2025-38049 - x86/resctrl: Fix allocation of cleanest CLOSID on platforms with no monitors

In the Linux kernel, the following vulnerability has been resolved: x86/resctrl: Fix allocation of cleanest CLOSID on platforms with no monitors Commit 6eac36bb9eb0 ("x86/resctrl: Allocate the cleanest CLOSID by searching closid_num_dirty_rmid") added logic that causes resctrl to search for tโ€ฆ

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

4.7

CVSS3.1

CVE-2025-28355 -

Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

0.0

CVE-2025-28233 -

Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1.6.0, Control Version: 1.0, AIO Firmware Version: 1.7 allows attackers to access log files and extract session identifiers to execute a session hijackโ€ฆ

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

0.0

CVE-2025-28229 -

Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

0.0

CVE-2025-28228 -

A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.4

CVSS3.1

CVE-2024-41447 -

A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

0.0

CVE-2024-29643 -

An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

9.8

CVSS3.1

CVE-2025-29058 -

An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.5

CVSS3.1

CVE-2025-39930 - ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai()

In the Linux kernel, the following vulnerability has been resolved: ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai() commit 419d1918105e ("ASoC: simple-card-utils: use __free(device_node) for device node") uses __free(device_node) for dlc->of_node, but we need to kโ€ฆ

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.5

CVSS3.1

CVE-2025-39688 - nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid()

In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid() The pynfs DELEG8 test fails when run against nfsd. It acquires a delegation and then lets the lease time out. It then tries to use the deleg stateid and expeโ€ฆ

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.
Total resulsts: 291043
Page 20 of 29,105
ยซ previous page ยป next page
Filters