7.0

CVSS3.1

CVE-2025-40158 - ipv6: use RCU in ip6_output()

In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_output() Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent possible UAF. We can remove rcu_read_lock()/rcu_read_unlock() pairs from ip6_finish_output2().

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-40162 - ASoC: amd/sdw_utils: avoid NULL deref when devm_kasprintf() fails

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd/sdw_utils: avoid NULL deref when devm_kasprintf() fails devm_kasprintf() may return NULL on memory allocation failure, but the debug message prints cpus->dai_name before checking it. Move the dev_dbg() call after the NU…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2025-65001 -

Fujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and availability.

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-63679 -

free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes.

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 4:12 p.m.

7.5

CVSS3.1

CVE-2025-63667 -

Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API endpoints without authentication.

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 6:15 p.m.

4

CVSS3.1

CVE-2025-63927 -

A heap-use-after-free vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). During multi-threaded client execution, the function Iec10x_Scheduled can access memory that has already been freed, potentially causing program crashes or undefined behavior. This may be exploited to …

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 7:35 p.m.

7.5

CVSS3.1

CVE-2024-47866 - RGW DoS attack with empty HTTP header in S3 object copy

Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object and specifying an empty string as its content leads to the RGW daemon crashing, resulting in a DoS attack. As of time of publication, no kn…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 4:23 p.m.

7.0

CVSS3.1

CVE-2025-40203 - listmount: don't call path_put() under namespace semaphore

In the Linux kernel, the following vulnerability has been resolved: listmount: don't call path_put() under namespace semaphore Massage listmount() and make sure we don't call path_put() under the namespace semaphore. If we put the last reference we're fscked.

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-63645 -

A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the application's message system. Unsanitized message content submitted by one user is persisted by the server and later rendered in another user's Inbox view without appropriate context-aware en…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Feb. 13, 2026, 4:42 p.m.

9.8

CVSS3.1

CVE-2025-63353 -

A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID. The device generates default passwords using a deterministic algorithm that derives the router passphrase from the SSID, enabling an atta…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 4:52 p.m.
Total resulsts: 349182
Page 3047 of 34,919
Β« previous page Β» next page
Filters