6.4

CVSS3.1

CVE-2025-59788 -

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: March 25, 2026, 9:35 p.m.

5.5

CVSS3.1

CVE-2025-40229 - mm/damon/core: fix potential memory leak by cleaning ops_filter in damon_destroy_scheme

In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: fix potential memory leak by cleaning ops_filter in damon_destroy_scheme Currently, damon_destroy_scheme() only cleans up the filter list but leaves ops_filter untouched, which could lead to memory leaks when a sch…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

7.5

CVSS3.1

CVE-2025-40240 - sctp: avoid NULL dereference when chunk data buffer is missing

In the Linux kernel, the following vulnerability has been resolved: sctp: avoid NULL dereference when chunk data buffer is missing chunk->skb pointer is dereferenced in the if-block where it's supposed to be NULL only. chunk->skb can only be NULL if chunk->head_skb is not. Check for frag_list in…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

5.5

CVSS3.1

CVE-2025-40245 - nios2: ensure that memblock.current_limit is set when setting pfn limits

In the Linux kernel, the following vulnerability has been resolved: nios2: ensure that memblock.current_limit is set when setting pfn limits On nios2, with CONFIG_FLATMEM set, the kernel relies on memblock_get_current_limit() to determine the limits of mem_map, in particular for max_low_pfn. Unfo…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:33 p.m.

5.5

CVSS3.1

CVE-2025-40232 - rv: Fully convert enabled_monitors to use list_head as iterator

In the Linux kernel, the following vulnerability has been resolved: rv: Fully convert enabled_monitors to use list_head as iterator The callbacks in enabled_monitors_seq_ops are inconsistent. Some treat the iterator as struct rv_monitor *, while others treat the iterator as struct list_head *. T…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

6.1

CVSS3.1

CVE-2025-65516 -

A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. When Seafile is configured with the Golang file server, an attacker can upload a crafted SVG file containing malicious JavaScript and share it using a public link. Opening the lin…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 11, 2025, 6:16 p.m.

7.5

CVSS3.1

CVE-2025-63364 -

Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to transmit Administrator credentials in plaintext.

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 8:59 p.m.

9.8

CVSS3.1

CVE-2025-54304 -

An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The display server listens on all network interfaces and is accessible over port 6000. The X11 access control list, by default, allows connections from 127…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 6:54 p.m.

7.0

CVSS3.1

CVE-2025-40238 - net/mlx5: Fix IPsec cleanup over MPV device

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix IPsec cleanup over MPV device When we do mlx5e_detach_netdev() we eventually disable blocking events notifier, among those events are IPsec MPV events from IB to core. So before disabling those blocking events, mak…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

8.8

CVSS3.1

CVE-2025-54307 -

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/upload/zip/ and /configure/newupdates/offline/bundle/upload/ endpoints allow low-privilege users to upload ZIP files to the server. The plupload_file_upload function handles these fil…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 6:46 p.m.
Total resulsts: 343923
Page 2302 of 34,393
Β« previous page Β» next page
Filters