5.5

CVSS3.1

CVE-2025-39732 - wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask()

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask() ath11k_mac_disable_peer_fixed_rate() is passed as the iterator to ieee80211_iterate_stations_atomic(). Note in this case the iterator is required to be atom…

πŸ“… Published: Sept. 7, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 5:52 p.m.

5.3

CVSS4.0

CVE-2025-10063 - itsourcecode POS Point of Sale System deferred_table.php cross site scripting

A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/deferred_table.php. The manipulation of the argument scripts leads to cross site scripting. Remote exploitation …

πŸ“… Published: Sept. 6, 2025, 11:02 p.m. πŸ”„ Last Modified: Sept. 10, 2025, 7:39 p.m.

6.9

CVSS4.0

CVE-2025-10062 - itsourcecode Student Information Management System login.php sql injection

A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part of the file /admin/login.php. Executing manipulation of the argument uname can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed a…

πŸ“… Published: Sept. 6, 2025, 10:32 p.m. πŸ”„ Last Modified: Sept. 9, 2025, 3:43 p.m.

9.9

CVSS4.0

CVE-2025-58443 - FOG's authentication bypass leads to full SQL DB dump

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to perform an unauthenticated DB dump where they could pull a full SQL DB without credentials. A fix is e…

πŸ“… Published: Sept. 6, 2025, 8:04 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 1:49 p.m.

6.9

CVSS4.0

CVE-2025-58445 - Atlantis Exposes Service Version Publicly on /status API Endpoint

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target known vulnerabilitie…

πŸ“… Published: Sept. 6, 2025, 7:47 p.m. πŸ”„ Last Modified: Sept. 10, 2025, 7:43 p.m.

6.9

CVSS4.0

CVE-2025-58446 - xgrammar vulnerable to denial of service by huge enum grammar

xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very low rates, and can be used for DOS of model providers. This issue is fixed in version 0.1.24.

πŸ“… Published: Sept. 6, 2025, 7:06 p.m. πŸ”„ Last Modified: Sept. 18, 2025, 3:57 p.m.

9.4

CVSS4.0

CVE-2025-58438 - internetarchive is vulnerable to Directory Traversal through file downloads

internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory traversal (path traversal) vulnerability in the File.download() method of the internetarchive library. The file.download() method does not properly sanitize user-supplied filename…

πŸ“… Published: Sept. 6, 2025, 6:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-0034 -

Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_SPATIAL_PART and cause read or write past the end of allocated arrays, potentially resulting in a loss of platform integrity or denial of service.

πŸ“… Published: Sept. 6, 2025, 6:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-0032 -

Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load malicious CPU microcode, potentially resulting in loss of integrity of x86 instruction execution.

πŸ“… Published: Sept. 6, 2025, 6:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.3

CVSS3.1

CVE-2025-0011 -

Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address information potentially resulting in loss of confidentiality.

πŸ“… Published: Sept. 6, 2025, 6:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3970 of 34,919
Β« previous page Β» next page
Filters