8.5

CVSS4.0

CVE-2025-68130 - tRPC has possible prototype pollution in `experimental_nextAppDirCaller`

tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and 11.8.0, a A prototype pollution vulnerability exists in `@trpc/server`'s `formDataToObject` function, which is used by the Next.js App Router …

πŸ“… Published: Dec. 16, 2025, 4:50 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 4:50 p.m.

8.9

CVSS3.1

CVE-2025-68116 - FileRise vulnerable to Cross-Site Scripting (XSS) in SVG File Handling

FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site Scripting (XSS) due to unsafe handling of browser-renderable user uploads when served through the sharing and download endpoints. An attacker who can get a crafted SVG (primary) o…

πŸ“… Published: Dec. 16, 2025, 4:43 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 4:43 p.m.

6.5

CVSS3.1

CVE-2025-59935 - GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch.

πŸ“… Published: Dec. 16, 2025, 4:34 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 4:34 p.m.

10

CVSS3.1

CVE-2025-37164 -

A remote code execution issue exists in HPE OneView.

πŸ“… Published: Dec. 16, 2025, 4:30 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 4:30 p.m.

6.1

CVSS4.0

CVE-2025-10450 - Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Prof…

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.This issue affects Connext Professional: from 7.4.0 before 7.*, from 7.2.0 before 7.3.1.

πŸ“… Published: Dec. 16, 2025, 4:09 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 4:09 p.m.

0.0

CVE-2025-68322 - parisc: Avoid crash due to unaligned access in unwinder

In the Linux kernel, the following vulnerability has been resolved: parisc: Avoid crash due to unaligned access in unwinder Guenter Roeck reported this kernel crash on his emulated B160L machine: Starting network: udhcpc: started, v1.36.1 Backtrace: [<104320d4>] unwind_once+0x1c/0x5c [<1043…

πŸ“… Published: Dec. 16, 2025, 3:44 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:44 p.m.

0.0

CVE-2025-68321 - page_pool: always add GFP_NOWARN for ATOMIC allocations

In the Linux kernel, the following vulnerability has been resolved: page_pool: always add GFP_NOWARN for ATOMIC allocations Driver authors often forget to add GFP_NOWARN for page allocation from the datapath. This is annoying to users as OOMs are a fact of life, and we pretty much expect network …

πŸ“… Published: Dec. 16, 2025, 3:44 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:44 p.m.

0.0

CVE-2025-68320 - lan966x: Fix sleeping in atomic context

In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix sleeping in atomic context The following warning was seen when we try to connect using ssh to the device. BUG: sleeping function called from invalid context at kernel/locking/mutex.c:575 in_atomic(): 1, irqs_disable…

πŸ“… Published: Dec. 16, 2025, 3:44 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:44 p.m.

0.0

CVE-2025-68319 - netconsole: Acquire su_mutex before navigating configs hierarchy

In the Linux kernel, the following vulnerability has been resolved: netconsole: Acquire su_mutex before navigating configs hierarchy There is a race between operations that iterate over the userdata cg_children list and concurrent add/remove of userdata items through configfs. The update_userdata…

πŸ“… Published: Dec. 16, 2025, 3:39 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:39 p.m.

0.0

CVE-2025-68318 - clk: thead: th1520-ap: set all AXI clocks to CLK_IS_CRITICAL

In the Linux kernel, the following vulnerability has been resolved: clk: thead: th1520-ap: set all AXI clocks to CLK_IS_CRITICAL The AXI crossbar of TH1520 has no proper timeout handling, which means gating AXI clocks can easily lead to bus timeout and thus system hang. Set all AXI clock gates t…

πŸ“… Published: Dec. 16, 2025, 3:39 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:39 p.m.
Total resulsts: 322971
Page 24 of 32,298
Β« previous page Β» next page
Filters