3.7

CVSS3.1

CVE-2025-8283 - Netavark: podman: netavark may resolve hostnames to unexpected hosts

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 10:15 p.m.

4.1

CVSS3.1

CVE-2023-53158 - gix-transport: gix Command Execution Vulnerability

The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit.

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-38474 - usb: net: sierra: check for no status endpoint

In the Linux kernel, the following vulnerability has been resolved: usb: net: sierra: check for no status endpoint The driver checks for having three endpoints and having bulk in and out endpoints, but not that the third endpoint is interrupt input. Rectify the omission.

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 7:29 p.m.

7.5

CVSS3.1

CVE-2025-50494 -

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: July 29, 2025, 9:15 p.m.

5.5

CVSS3.1

CVE-2025-38468 - net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree

In the Linux kernel, the following vulnerability has been resolved: net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree htb_lookup_leaf has a BUG_ON that can trigger with the following: tc qdisc del dev lo root tc qdisc add dev lo root handle 1: htb default 1 tc class add dev …

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 7:36 p.m.

7.8

CVSS3.1

CVE-2025-38490 - net: libwx: remove duplicate page_pool_put_full_page()

In the Linux kernel, the following vulnerability has been resolved: net: libwx: remove duplicate page_pool_put_full_page() page_pool_put_full_page() should only be invoked when freeing Rx buffers or building a skb if the size is too short. At other times, the pages need to be reused. So remove th…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 5:46 p.m.

7.1

CVSS3.1

CVE-2025-38483 - comedi: das16m1: Fix bit shift out of bounds

In the Linux kernel, the following vulnerability has been resolved: comedi: das16m1: Fix bit shift out of bounds When checking for a supported IRQ number, the following test is used: /* only irqs 2, 3, 4, 5, 6, 7, 10, 11, 12, 14, and 15 are valid */ if ((1 << it->options[1]) & 0xdcfc) { Howev…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 4:25 p.m.

5.5

CVSS3.1

CVE-2025-38491 - mptcp: make fallback action and fallback decision atomic

In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision atomic Syzkaller reported the following splat: WARNING: CPU: 1 PID: 7704 at net/mptcp/protocol.h:1223 __mptcp_do_fallback net/mptcp/protocol.h:1223 [inline] WARNING: CPU: 1 P…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 4:26 p.m.

9.8

CVSS3.1

CVE-2025-30133 -

An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app for authentication, but its HTTP server lacks this restriction. Once connected to the dashcam's Wi-Fi network via the default password ("…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 8:07 p.m.

7.5

CVSS3.1

CVE-2025-50492 -

Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a session hijacking attack.

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: July 29, 2025, 9:17 p.m.
Total resulsts: 347394
Page 4316 of 34,740
Β« previous page Β» next page
Filters