7.2

CVSS3.1

CVE-2025-50891 -

The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1).

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-38559 - platform/x86/intel/pmt: fix a crashlog NULL pointer access

In the Linux kernel, the following vulnerability has been resolved: platform/x86/intel/pmt: fix a crashlog NULL pointer access Usage of the intel_pmt_read() for binary sysfs, requires a pcidev. The current use of the endpoint value is only valid for telemetry endpoint usage. Without the ep, the …

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Nov. 28, 2025, 2:42 p.m.

6.5

CVSS3.1

CVE-2025-51506 -

In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKey parameter. This flaw enables any authenticated user to execute arbitrary SQL queries, via crafted payloads to valueKey to the api/smartlibrary/v2/en/dictionaries/options/lookup …

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 9:08 p.m.

7.1

CVSS3.1

CVE-2025-38592 - Bluetooth: hci_devcd_dump: fix out-of-bounds via dev_coredumpv

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_devcd_dump: fix out-of-bounds via dev_coredumpv Currently both dev_coredumpv and skb_put_data in hci_devcd_dump use hdev->dump.head. However, dev_coredumpv can free the buffer. From dev_coredumpm_timeout documentat…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 5:59 p.m.

5.3

CVSS3.1

CVE-2025-51539 -

EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due to improper access control and insufficient input validation in a script exposed via the web interface. A remote attacker can supply a crafted path parameter to a PHP script to read arbitrary files from the filesystem. T…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 9:06 p.m.

4.7

CVSS3.1

CVE-2025-38567 - nfsd: avoid ref leak in nfsd_open_local_fh()

In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid ref leak in nfsd_open_local_fh() If two calls to nfsd_open_local_fh() race and both successfully call nfsd_file_acquire_local(), they will both get an extra reference to the net to accompany the file reference stored …

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 8:05 p.m.

5.5

CVSS3.1

CVE-2025-38607 - bpf: handle jset (if a & b ...) as a jump in CFG computation

In the Linux kernel, the following vulnerability has been resolved: bpf: handle jset (if a & b ...) as a jump in CFG computation BPF_JSET is a conditional jump and currently verifier.c:can_jump() does not know about that. This can lead to incorrect live registers and SCC computation. E.g. in the…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 5:40 p.m.

4.3

CVSS3.1

CVE-2025-50897 -

A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translations configured with write permissions (PTE_W) in SV39 mode may incorrectly trigger a Store/AMO access fault during store instructions (sd). This occurs despite th…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 4:55 p.m.

5.5

CVSS3.1

CVE-2025-38581 - crypto: ccp - Fix crash when rebind ccp device for ccp.ko

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix crash when rebind ccp device for ccp.ko When CONFIG_CRYPTO_DEV_CCP_DEBUGFS is enabled, rebinding the ccp device causes the following crash: $ echo '0000:0a:00.2' > /sys/bus/pci/drivers/ccp/unbind $ echo '0000:0…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 1:55 p.m.

5.5

CVSS3.1

CVE-2025-38553 - net/sched: Restrict conditions for adding duplicating netems to qdisc tree

In the Linux kernel, the following vulnerability has been resolved: net/sched: Restrict conditions for adding duplicating netems to qdisc tree netem_enqueue's duplication prevention logic breaks when a netem resides in a qdisc tree with other netems - this can lead to a soft lockup and OOM loop i…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 8:49 p.m.
Total resulsts: 349182
Page 4233 of 34,919
Β« previous page Β» next page
Filters