5.3

CVSS4.0

CVE-2025-10825 - Campcodes Online Beauty Parlor Management System view-appointment.php sql injection

A vulnerability was identified in Campcodes Online Beauty Parlor Management System 1.0. Affected is an unknown function of the file /admin/view-appointment.php. The manipulation of the argument viewid leads to sql injection. The attack can be initiated remotely. The exploit is publicly available an…

πŸ“… Published: Sept. 23, 2025, 12:02 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 6:08 p.m.

4.8

CVSS4.0

CVE-2025-10824 - axboe fio init.c __parse_jobs_ini use after free

A vulnerability was determined in axboe fio up to 3.41. This impacts the function __parse_jobs_ini of the file init.c. Executing manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized.

πŸ“… Published: Sept. 23, 2025, 12:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-29083 -

SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Plugin_Manager.php file.

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Sept. 25, 2025, 4:09 p.m.

7.1

CVSS3.1

CVE-2025-39883 - mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory

In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory When I did memory failure tests, below panic occurs: page dumped because: VM_BUG_ON_PAGE(PagePoisoned(page)) kernel BUG at include/linux/page-flags.h…

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 7:26 p.m.

5.5

CVSS3.1

CVE-2025-39872 - hsr: hold rcu and dev lock for hsr_get_port_ndev

In the Linux kernel, the following vulnerability has been resolved: hsr: hold rcu and dev lock for hsr_get_port_ndev hsr_get_port_ndev calls hsr_for_each_port, which need to hold rcu lock. On the other hand, before return the port device, we need to hold the device reference to avoid UaF in the c…

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 10:15 a.m.

5.5

CVSS3.1

CVE-2025-39886 - bpf: Tell memcg to use allow_spinning=false path in bpf_timer_init()

In the Linux kernel, the following vulnerability has been resolved: bpf: Tell memcg to use allow_spinning=false path in bpf_timer_init() Currently, calling bpf_map_kmalloc_node() from __bpf_async_init() can cause various locking issues; see the following stack trace (edited for style) as one exam…

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

7.8

CVSS3.1

CVE-2025-39880 - libceph: fix invalid accesses to ceph_connection_v1_info

In the Linux kernel, the following vulnerability has been resolved: libceph: fix invalid accesses to ceph_connection_v1_info There is a place where generic code in messenger.c is reading and another place where it is writing to con->v1 union member without checking that the union member is active…

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Jan. 20, 2026, 8:27 p.m.

4.7

CVSS3.1

CVE-2025-39884 - btrfs: fix subvolume deletion lockup caused by inodes xarray race

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix subvolume deletion lockup caused by inodes xarray race There is a race condition between inode eviction and inode caching that can cause a live struct btrfs_inode to be missing from the root->inodes xarray. Specificall…

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

7.8

CVSS3.1

CVE-2025-39882 - drm/mediatek: fix potential OF node use-after-free

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: fix potential OF node use-after-free The for_each_child_of_node() helper drops the reference it takes to each node as it iterates over children and an explicit of_node_put() is only needed when exiting the loop earl…

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

5.4

CVSS3.1

CVE-2025-57407 -

A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or HTML via a crafted User-Agent header. The script is executed in an administrator's browser when they view the security log page, whic…

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Oct. 8, 2025, 6:10 p.m.
Total resulsts: 349182
Page 3713 of 34,919
Β« previous page Β» next page
Filters