7.0

CVSS3.1

CVE-2025-39970 - i40e: fix input validation logic for action_meta

In the Linux kernel, the following vulnerability has been resolved: i40e: fix input validation logic for action_meta Fix condition to check 'greater or equal' to prevent OOB dereference.

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-39996 - media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove

In the Linux kernel, the following vulnerability has been resolved: media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove The original code uses cancel_delayed_work() in flexcop_pci_remove(), which does not guarantee that the delayed work item irq_check_work has fully co…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.2

CVSS3.1

CVE-2025-56746 -

Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 7:42 p.m.

7.0

CVSS3.1

CVE-2025-39971 - i40e: fix idx validation in config queues msg

In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in config queues msg Ensure idx is within range of active/initialized TCs when iterating over vf->ch[idx] in i40e_vc_config_queues_msg().

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.5

CVSS4.0

CVE-2025-62376 - pwn.college DOJO vulnerable to improper authentication in workspace endpoint allowing unauthorized …

pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef, the /workspace endpoint contains an improper authentication vulnerability that allows an attacker to access any active Windows VM without proper authorization. The vulnera…

πŸ“… Published: Oct. 14, 2025, 9:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-49552 - Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate …

πŸ“… Published: Oct. 14, 2025, 9:53 p.m. πŸ”„ Last Modified: April 28, 2026, 1:44 a.m.

9.3

CVSS3.1

CVE-2025-49553 - Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted we…

πŸ“… Published: Oct. 14, 2025, 9:53 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

4.3

CVSS3.1

CVE-2025-54196 - Adobe Connect | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)

Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a victim must click on a …

πŸ“… Published: Oct. 14, 2025, 9:53 p.m. πŸ”„ Last Modified: April 28, 2026, 2:15 a.m.

5.4

CVSS3.1

CVE-2025-61797 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse…

πŸ“… Published: Oct. 14, 2025, 9:18 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 3:29 p.m.

5.4

CVSS3.1

CVE-2025-54272 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse…

πŸ“… Published: Oct. 14, 2025, 9:18 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 3:33 p.m.
Total resulsts: 349182
Page 3417 of 34,919
Β« previous page Β» next page
Filters