7.5

CVSS3.1

CVE-2025-65287 -

An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker to read arbitrary files. The CGI concatenates the user-supplied params directly onto the base path (/var/www/files/userScript/) using memcpy + strcat without validation or canonic…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 8:15 p.m.

7.0

CVSS3.1

CVE-2023-53802 - wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function It is stated that ath9k_htc_rx_msg() either frees the provided skb or passes its management to another callback function. However, the skb is n…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

7.0

CVSS3.1

CVE-2023-53800 - ubi: Fix use-after-free when volume resizing failed

In the Linux kernel, the following vulnerability has been resolved: ubi: Fix use-after-free when volume resizing failed There is an use-after-free problem reported by KASAN: ================================================================== BUG: KASAN: use-after-free in ubi_eba_copy_table+0x1…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

5.5

CVSS3.1

CVE-2023-53859 - s390/idle: mark arch_cpu_idle() noinstr

In the Linux kernel, the following vulnerability has been resolved: s390/idle: mark arch_cpu_idle() noinstr linux-next commit ("cpuidle: tracing: Warn about !rcu_is_watching()") adds a new warning which hits on s390's arch_cpu_idle() function: RCU not on for: arch_cpu_idle+0x0/0x28 WARNING: CPU:…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:33 a.m.

9.8

CVSS3.1

CVE-2025-63742 -

SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the shouji and userid param…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 12:27 p.m.

8.1

CVSS3.1

CVE-2025-61075 -

Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authenticated, low-privileged users to carry out administrative functions and manipulate data of other users via unauthorized API calls.

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 2:43 p.m.

5.5

CVSS3.1

CVE-2023-53844 - drm/ttm: Don't leak a resource on swapout move error

In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Don't leak a resource on swapout move error If moving the bo to system for swapout failed, we were leaking a resource. Fix.

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

4.3

CVSS3.1

CVE-2025-63739 -

An issue was discovered in function phpinisaveAction in file webmain/system/cogini/coginiAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to authenticated users to modify PHP configuration files via the a parameter to the index.php endpoint.

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 12:29 p.m.

5.5

CVSS3.1

CVE-2023-53845 - nilfs2: fix infinite loop in nilfs_mdt_get_block()

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix infinite loop in nilfs_mdt_get_block() If the disk image that nilfs2 mounts is corrupted and a virtual block address obtained by block lookup for a metadata file is invalid, nilfs_bmap_lookup_at_level() may return the…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:33 a.m.

5.5

CVSS3.1

CVE-2023-53842 - ASoC: codecs: wcd-mbhc-v2: fix resource leaks on component remove

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd-mbhc-v2: fix resource leaks on component remove The MBHC resources must be released on component probe failure and removal so can not be tied to the lifetime of the component device. This is specifically needed…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.
Total resulsts: 343926
Page 2238 of 34,393
Β« previous page Β» next page
Filters