5.5

CVSS3.1

CVE-2025-38203 - jfs: Fix null-ptr-deref in jfs_ioc_trim

In the Linux kernel, the following vulnerability has been resolved: jfs: Fix null-ptr-deref in jfs_ioc_trim [ Syzkaller Report ] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000087: 0000 [#1 KASAN: null-ptr-deref in range [0x0000000000000438-0x000000000000043f] โ€ฆ

๐Ÿ“… Published: July 4, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 18, 2025, 9:20 p.m.

5.5

CVSS3.1

CVE-2025-38228 - media: imagination: fix a potential memory leak in e5010_probe()

In the Linux kernel, the following vulnerability has been resolved: media: imagination: fix a potential memory leak in e5010_probe() Add video_device_release() to release the memory allocated by video_device_alloc() if something goes wrong.

๐Ÿ“… Published: July 4, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 18, 2025, 4:37 p.m.

7.2

CVSS3.1

CVE-2025-5322 - VikRentCar Car Rental Management System <= 1.4.3 - Authenticated (Administrator+) Arbitrary File Upโ€ฆ

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the do_updatecar and createcar functions in all versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with Administratoโ€ฆ

๐Ÿ“… Published: July 3, 2025, 9:24 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:56 p.m.

8.4

CVSS4.0

CVE-2025-53367 - DjVuLibre OOB-Write Vulnerability in MMRDecoder

DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. Tโ€ฆ

๐Ÿ“… Published: July 3, 2025, 9:07 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-49826 - Next.js DoS vulnerability via cache poisoning

Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, a cache poisoning bug leading to a Denial of Service (DoS) condition was found in Next.js. This issue does not impact customers hosted on Vercel. Under certain conditions, this isโ€ฆ

๐Ÿ“… Published: July 3, 2025, 9:03 p.m. ๐Ÿ”„ Last Modified: Sept. 10, 2025, 3:28 p.m.

3.7

CVSS3.1

CVE-2025-49005 - Next.js cache poisoning due to omission of Vary header

Next.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3.3 and Vercel CLI from 41.4.1 to 42.2.0, a cache poisoning vulnerability was found. The issue allowed page requests for HTML content to return a React Server Component (RSC) payloaโ€ฆ

๐Ÿ“… Published: July 3, 2025, 9:01 p.m. ๐Ÿ”„ Last Modified: Sept. 10, 2025, 7:14 p.m.

4.9

CVSS4.0

CVE-2025-52554 - n8n Improper Authorization in Workflow Execution Stop Endpoint Allows Terminating Other Usersโ€™ Workโ€ฆ

n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /rest/executions/:id/stop endpoint of n8n. An authenticated user can stop workflow executions that they do not own or that have not been shared with them, leading to potential busineโ€ฆ

๐Ÿ“… Published: July 3, 2025, 8:08 p.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 4:53 p.m.

8.6

CVSS3.1

CVE-2025-53369 - Citizen Short Description stored XSS vulnerability through wikitext

Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descriptions are not properly sanitized before being inserted as HTML using mw.util.addSubtitle, allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue haโ€ฆ

๐Ÿ“… Published: July 3, 2025, 7:57 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-34089 - Remote for Mac Unauthenticated Remote Code Execution via AppleScript Injection

An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio, in versions up to and including 2025.7. When the application is configured with authentication disabled (i.e., the "Allow unknown devices" option is enabled), tโ€ฆ

๐Ÿ“… Published: July 3, 2025, 7:47 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9

CVSS4.0

CVE-2025-34087 - Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command Execution

An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain parameter is not properly sanitized, allowing an attacker to append OS commands to the domain string. These commands are executed on the undโ€ฆ

๐Ÿ“… Published: July 3, 2025, 7:46 p.m. ๐Ÿ”„ Last Modified: Nov. 19, 2025, 2:36 p.m.
Total resulsts: 344980
Page 4379 of 34,498
ยซ previous page ยป next page
Filters