5.5

CVSS3.1

CVE-2025-38646 - wifi: rtw89: avoid NULL dereference when RX problematic packet on unsupported 6 GHz band

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: avoid NULL dereference when RX problematic packet on unsupported 6 GHz band With a quite rare chance, RX report might be problematic to make SW think a packet is received on 6 GHz band even if the chip does not suppo…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 4:42 p.m.

5.5

CVSS3.1

CVE-2025-38635 - clk: davinci: Add NULL check in davinci_lpsc_clk_register()

In the Linux kernel, the following vulnerability has been resolved: clk: davinci: Add NULL check in davinci_lpsc_clk_register() devm_kasprintf() returns NULL when memory allocation fails. Currently, davinci_lpsc_clk_register() does not check for this case, which results in a NULL pointer derefere…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 4:27 p.m.

5.5

CVSS3.1

CVE-2025-38630 - fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref

In the Linux kernel, the following vulnerability has been resolved: fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref fb_add_videomode() can fail with -ENOMEM when its internal kmalloc() cannot allocate a struct fb_modelist. If that happens, the modelist stays empty but the driver c…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 4:34 p.m.

5.5

CVSS3.1

CVE-2025-38624 - PCI: pnv_php: Clean up allocated IRQs on unplug

In the Linux kernel, the following vulnerability has been resolved: PCI: pnv_php: Clean up allocated IRQs on unplug When the root of a nested PCIe bridge configuration is unplugged, the pnv_php driver leaked the allocated IRQ resources for the child bridges' hotplug event notifications, resulting…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 4:37 p.m.

7.5

CVSS3.1

CVE-2025-55634 -

Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to cause a Denial of Service (DoS) via initiating a large number of simultaneous ffmpeg-based stream pushes.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 1:57 p.m.

5.5

CVSS3.1

CVE-2025-38650 - hfsplus: remove mutex_lock check in hfsplus_free_extents

In the Linux kernel, the following vulnerability has been resolved: hfsplus: remove mutex_lock check in hfsplus_free_extents Syzbot reported an issue in hfsplus filesystem: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 4400 at fs/hfsplus/extents.c:346 hfsplus_free_extents+0x700/0xad…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 5:36 p.m.

9.8

CVSS3.1

CVE-2025-52095 -

An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines in SDCommon.dll

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Jan. 27, 2026, 7:07 p.m.

9.8

CVSS3.1

CVE-2025-57105 -

The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The sub_478D28 function in in mng_platform.asp, and sub_4A12DC function in wayos_ac_server.asp of the jhttpd program, with the parameter ac_mng_srv_host.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 1:07 p.m.

8.8

CVSS3.1

CVE-2025-52085 -

An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries via a request to a backend API endpoint. Successful exploitation enables extraction of sensitive database information, including but not limited to, the database server banner and…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Sept. 12, 2025, 7:30 p.m.

8.1

CVSS3.1

CVE-2025-51605 -

An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origin without any whitelist validation, while also enabling Access-Control-Allow-Credentials: true. This allows any malicious origin to make aut…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Sept. 12, 2025, 7:40 p.m.
Total resulsts: 349182
Page 4168 of 34,919
Β« previous page Β» next page
Filters