5.5

CVSS3.1

CVE-2025-40003 - net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work The origin code calls cancel_delayed_work() in ocelot_stats_deinit() to cancel the cyclic delayed work item ocelot->stats_work. However, cancel_delayed_work() ma…

πŸ“… Published: Oct. 18, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

5.5

CVSS3.1

CVE-2025-40002 - thunderbolt: Fix use-after-free in tb_dp_dprx_work

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix use-after-free in tb_dp_dprx_work The original code relies on cancel_delayed_work() in tb_dp_dprx_stop(), which does not ensure that the delayed work item tunnel->dprx_work has fully completed if it was already r…

πŸ“… Published: Oct. 18, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

2.1

CVSS4.0

CVE-2025-62655 - SQL injection in Cargo via Special:CargoExport

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki Cargo extension allows SQL Injection.This issue affects MediaWiki Cargo extension: 1.39, 1.43, 1.44.

πŸ“… Published: Oct. 17, 2025, 10:46 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

2

CVSS4.0

CVE-2025-62654 - Stored XSS through system messages in QuizGame

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki QuizGame extension allows Stored XSS.This issue affects MediaWiki QuizGame extension: 1.39, 1.43, 1.44.

πŸ“… Published: Oct. 17, 2025, 10:38 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

2

CVSS4.0

CVE-2025-62653 - Stored XSS through system messages in PollNY

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki PollNY extension allows Stored XSS.This issue affects MediaWiki PollNY extension: 1.39, 1.43, 1.44.

πŸ“… Published: Oct. 17, 2025, 10:23 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

5.8

CVSS4.0

CVE-2025-62652 - Stored XSS in WebAuthn key name

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44.

πŸ“… Published: Oct. 17, 2025, 10:15 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

9.8

CVSS3.1

CVE-2025-62515 - Remote Code Execution by Pickle Deserialization via FlightServer in pyquokka

pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class directly uses pickle.loads() to deserialize action bodies received from Flight clients without any sanitization or validation in the do_action() method. The vulnerable code is loc…

πŸ“… Published: Oct. 17, 2025, 8:38 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

5.3

CVSS4.0

CVE-2025-11914 - Shenzhen Ruiming Technology Streamax Crocus DeviceFileReport.do download path traversal

A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function Download of the file /DeviceFileReport.do?Action=Download. Performing manipulation of the argument FilePath results in path traversal. The attack may be initiated remotely. The ex…

πŸ“… Published: Oct. 17, 2025, 8:32 p.m. πŸ”„ Last Modified: Oct. 31, 2025, 4:58 p.m.

6.5

CVSS3.1

CVE-2025-62508 - Citizen vulnerable to stored XSS in sticky header button messages

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulnerable to stored cross-site scripting in the sticky header button message handling. In stickyHeader.js the copyButtonAttributes function assigns innerHTML from a source element’s t…

πŸ“… Published: Oct. 17, 2025, 8:29 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

5.3

CVSS4.0

CVE-2025-11913 - Shenzhen Ruiming Technology Streamax Crocus Service.do download path traversal

A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is the function Download of the file /Service.do?Action=Download. Such manipulation of the argument Path leads to path traversal. The attack can be launched remotely. The exploit has…

πŸ“… Published: Oct. 17, 2025, 8:02 p.m. πŸ”„ Last Modified: Oct. 31, 2025, 5:04 p.m.
Total resulsts: 343975
Page 2857 of 34,398
Β« previous page Β» next page
Filters