6.1

CVSS3.1

CVE-2025-63499 -

Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:24 p.m.

7.0

CVSS3.1

CVE-2025-40248 - vsock: Ignore signal/timeout on connect() if already established

In the Linux kernel, the following vulnerability has been resolved: vsock: Ignore signal/timeout on connect() if already established During connect(), acting on a signal/timeout by disconnecting an already established socket leads to several issues: 1. connect() invoking vsock_transport_cancel_p…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

5.5

CVSS3.1

CVE-2025-40236 - virtio-net: zero unused hash fields

In the Linux kernel, the following vulnerability has been resolved: virtio-net: zero unused hash fields When GSO tunnel is negotiated virtio_net_hdr_tnl_from_skb() tries to initialize the tunnel metadata but forget to zero unused rxhash fields. This may leak information to another side. Fixing th…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

7.1

CVSS3.1

CVE-2025-40256 - xfrm: also call xfrm_state_delete_tunnel at destroy time for states that were never added

In the Linux kernel, the following vulnerability has been resolved: xfrm: also call xfrm_state_delete_tunnel at destroy time for states that were never added In commit b441cf3f8c4b ("xfrm: delete x->tunnel as we delete x"), I missed the case where state creation fails between full initialization …

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Jan. 19, 2026, 1:16 p.m.

7.0

CVSS3.1

CVE-2025-40254 - net: openvswitch: remove never-working support for setting nsh fields

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: remove never-working support for setting nsh fields The validation of the set(nsh(...)) action is completely wrong. It runs through the nsh_key_put_from_nlattr() function that is the same function that validates…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

5.5

CVSS3.1

CVE-2025-40222 - tty: serial: sh-sci: fix RSCI FIFO overrun handling

In the Linux kernel, the following vulnerability has been resolved: tty: serial: sh-sci: fix RSCI FIFO overrun handling The receive error handling code is shared between RSCI and all other SCIF port types, but the RSCI overrun_reg is specified as a memory offset, while for other SCIF types it is …

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

0.0

CVE-2025-40266 - KVM: arm64: Check the untrusted offset in FF-A memory share

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memory share Verify the offset to prevent OOB access in the hypervisor FF-A buffer in case an untrusted large enough value [U32_MAX - sizeof(struct ffa_composite_mem_region) + 1, U32…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 20, 2025, 8:51 a.m.

5.5

CVSS3.1

CVE-2025-40253 - s390/ctcm: Fix double-kfree

In the Linux kernel, the following vulnerability has been resolved: s390/ctcm: Fix double-kfree The function 'mpc_rcvd_sweep_req(mpcginfo)' is called conditionally from function 'ctcmpc_unpack_skb'. It frees passed mpcginfo. After that a call to function 'kfree' in function 'ctcmpc_unpack_skb' fr…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

4.1

CVSS3.1

CVE-2025-40265 - vfat: fix missing sb_min_blocksize() return value checks

In the Linux kernel, the following vulnerability has been resolved: vfat: fix missing sb_min_blocksize() return value checks When emulating an nvme device on qemu with both logical_block_size and physical_block_size set to 8 KiB, but without format, a kernel panic was triggered during the early b…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

7.5

CVSS3.1

CVE-2025-63363 -

A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to execute de-authentication attacks, allowing crafted deauthentication and disassociation frames to be broadca…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 8:57 p.m.
Total resulsts: 343749
Page 2288 of 34,375
Β« previous page Β» next page
Filters