5.5

CVSS3.1

CVE-2025-38569 - benet: fix BUG when creating VFs

In the Linux kernel, the following vulnerability has been resolved: benet: fix BUG when creating VFs benet crashes as soon as SRIOV VFs are created: kernel BUG at mm/vmalloc.c:3457! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 4 UID: 0 PID: 7408 Comm: test.sh Kdump: loaded Not tainted…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 9:08 p.m.

5.5

CVSS3.1

CVE-2025-38589 - neighbour: Fix null-ptr-deref in neigh_flush_dev().

In the Linux kernel, the following vulnerability has been resolved: neighbour: Fix null-ptr-deref in neigh_flush_dev(). kernel test robot reported null-ptr-deref in neigh_flush_dev(). [0] The cited commit introduced per-netdev neighbour list and converted neigh_flush_dev() to use it instead of t…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 5:58 p.m.

7.5

CVSS3.1

CVE-2025-38566 - sunrpc: fix handling of server side tls alerts

In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix handling of server side tls alerts Scott Mayhew discovered a security exploit in NFS over TLS in tls_alert_recv() due to its assumption it can read data from the msg iterator's kvec.. kTLS implementation splits TLS n…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 6:15 p.m.

5.5

CVSS3.1

CVE-2025-38583 - clk: xilinx: vcu: unregister pll_post only if registered correctly

In the Linux kernel, the following vulnerability has been resolved: clk: xilinx: vcu: unregister pll_post only if registered correctly If registration of pll_post is failed, it will be set to NULL or ERR, unregistering same will fail with following call trace: Unable to handle kernel NULL pointe…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 1:53 p.m.

9.8

CVSS3.1

CVE-2025-54336 -

In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-52338 -

An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user accounts via a bruteforce attack.

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.5

CVSS3.1

CVE-2025-51487 -

A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing to execute arbitrary JavaScript by using "javascript:" payload, instead of the expected HTTPS protocol, in the CutCode Link parameter when creating/updating a new Article.

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 2:29 p.m.

10

CVSS3.1

CVE-2025-50567 -

Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interpolate SQL query parameters. This leads to injection of user-controlled SQL statements, potentially leading to arbitrary PHP cod…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-38615 - fs/ntfs3: cancle set bad inode after removing name fails

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: cancle set bad inode after removing name fails The reproducer uses a file0 on a ntfs3 file system with a corrupted i_link. When renaming, the file0's inode is marked as a bad inode because the file name cannot be delete…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 5:41 p.m.

5.5

CVSS3.1

CVE-2025-38612 - staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc()

In the Linux kernel, the following vulnerability has been resolved: staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc() In the error paths after fb_info structure is successfully allocated, the memory allocated in fb_deferred_io_init() for info->pagerefs is not freed. Fix that …

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 6:21 p.m.
Total resulsts: 349182
Page 4230 of 34,919
Β« previous page Β» next page
Filters