5.5

CVSS3.1

CVE-2025-38725 - net: usb: asix_devices: add phy_mask for ax88772 mdio bus

In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for ax88772 mdio bus, current driver may create at most 32 mdio phy devices with phy address range from 0x00 ~ 0x1f. DLink DUB-E100 H/W Ver B1 is โ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 3:33 p.m. ๐Ÿ”„ Last Modified: Jan. 8, 2026, 5:38 p.m.

7.1

CVSS3.1

CVE-2025-38715 - hfs: fix slab-out-of-bounds in hfs_bnode_read()

In the Linux kernel, the following vulnerability has been resolved: hfs: fix slab-out-of-bounds in hfs_bnode_read() This patch introduces is_bnode_offset_valid() method that checks the requested offset value. Also, it introduces check_and_correct_requested_length() method that checks and correct โ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 3:33 p.m. ๐Ÿ”„ Last Modified: March 17, 2026, 4:20 p.m.

7.8

CVSS3.1

CVE-2025-38708 - drbd: add missing kref_get in handle_write_conflicts

In the Linux kernel, the following vulnerability has been resolved: drbd: add missing kref_get in handle_write_conflicts With `two-primaries` enabled, DRBD tries to detect "concurrent" writes and handle write conflicts, so that even if you write to the same sector simultaneously on both nodes, thโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: March 17, 2026, 4:16 p.m.

5.5

CVSS3.1

CVE-2025-38693 - media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_readโ€ฆ

In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar In w7090p_tuner_write_serpar, msg is controlled by user. When msg[0].buf is null and msg[0].len is zero, former checks on โ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 3:45 p.m.

6.5

CVSS3.1

CVE-2025-25048 - IBM Jazz Foundation path traversal

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due to improper neutralization of sequences that can resolve to a restricted directory.

๐Ÿ“… Published: Sept. 4, 2025, 3:06 p.m. ๐Ÿ”„ Last Modified: Jan. 9, 2026, 2:31 a.m.

6.1

CVSS3.1

CVE-2024-43184 - IBM Jazz Foundation cross-site scripting

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 3:04 p.m. ๐Ÿ”„ Last Modified: Jan. 9, 2026, 2:31 a.m.

2.7

CVSS3.1

CVE-2025-2667 - IBM Sterling B2B Integrator information disclosure

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 could disclose sensitive system information about the server to a privileged user that could aid in further attacks against the systeโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 2:45 p.m. ๐Ÿ”„ Last Modified: Sept. 10, 2025, 5:19 p.m.

4.8

CVSS3.1

CVE-2025-2694 - IBM Sterling B2B Integrator cross-site scripting

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI tโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 2:43 p.m. ๐Ÿ”„ Last Modified: Sept. 10, 2025, 5:15 p.m.

4.7

CVSS4.0

CVE-2025-6785 - Tesla Model 3 Physical CAN Bus Injection

Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote start functions of the vehicle.ย  Testing completed onย Tesla Model 3 vehicles with software version v11.1 (2023.20.9 ee6de92ddac5).ย โ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 2:13 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2025-8311 -

dotCMS versionsย 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpoint. This endpoint uses the sites query parameter, which accepts a comma-separated list of site identifiers or keys. The vulnerability was triggered via the sites parameter, whicโ€ฆ

๐Ÿ“… Published: Sept. 4, 2025, 2:12 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4013 of 34,919
ยซ previous page ยป next page
Filters