6.5

CVSS3.1

CVE-2025-61148 -

An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint.

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 5:51 p.m.

7.0

CVSS3.1

CVE-2025-40244 - hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent() The syzbot reported issue in __hfsplus_ext_cache_extent(): [ 70.194323][ T9350] BUG: KMSAN: uninit-value in __hfsplus_ext_cache_extent+0x7d0/0x990 [ 70.19…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:33 p.m.

5.5

CVSS3.1

CVE-2025-40241 - erofs: fix crafted invalid cases for encoded extents

In the Linux kernel, the following vulnerability has been resolved: erofs: fix crafted invalid cases for encoded extents Robert recently reported two corrupted images that can cause system crashes, which are related to the new encoded extents introduced in Linux 6.15: - The first one [1] has p…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

7.0

CVSS3.1

CVE-2025-40239 - net: phy: micrel: always set shared->phydev for LAN8814

In the Linux kernel, the following vulnerability has been resolved: net: phy: micrel: always set shared->phydev for LAN8814 Currently, during the LAN8814 PTP probe shared->phydev is only set if PTP clock gets actually set, otherwise the function will return before setting it. This is an issue as…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

7.1

CVSS3.1

CVE-2025-40246 - xfs: fix out of bounds memory read error in symlink repair

In the Linux kernel, the following vulnerability has been resolved: xfs: fix out of bounds memory read error in symlink repair xfs/286 produced this report on my test fleet: ================================================================== BUG: KFENCE: out-of-bounds read in memcpy_orig+0x54/0…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

5.5

CVSS3.1

CVE-2025-40228 - mm/damon/sysfs: catch commit test ctx alloc failure

In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: catch commit test ctx alloc failure Patch series "mm/damon/sysfs: fix commit test damon_ctx [de]allocation". DAMON sysfs interface dynamically allocates and uses a damon_ctx object for testing if given inputs for…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

7.0

CVSS3.1

CVE-2025-40214 - af_unix: Initialise scc_index in unix_add_edge().

In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a receive queue of an alive in-flight socket, with a nice repro. The repro consists of three stages. 1) 1-a. Cr…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

5.5

CVSS3.1

CVE-2025-40227 - mm/damon/sysfs: dealloc commit test ctx always

In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: dealloc commit test ctx always The damon_ctx for testing online DAMON parameters commit inputs is deallocated only when the test fails. This means memory is leaked for every successful online DAMON parameters com…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

5.5

CVSS3.1

CVE-2025-40221 - media: pci: mg4b: fix uninitialized iio scan data

In the Linux kernel, the following vulnerability has been resolved: media: pci: mg4b: fix uninitialized iio scan data Fix potential leak of uninitialized stack data to userspace by ensuring that the `scan` structure is zeroed before use.

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

5.7

CVSS3.1

CVE-2025-63361 -

Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to render the Administrator password in plaintext.

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 3:35 p.m.
Total resulsts: 343942
Page 2309 of 34,395
Β« previous page Β» next page
Filters