6.1

CVSS3.1

CVE-2025-45662 -

A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 6:56 p.m.

5.5

CVSS3.1

CVE-2025-38343 - wifi: mt76: mt7996: drop fragments with multicast or broadcast RA

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: drop fragments with multicast or broadcast RA IEEE 802.11 fragmentation can only be applied to unicast frames. Therefore, drop fragments with multicast or broadcast RA. This patch addresses vulnerabilities suc…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 12:52 p.m.

5.5

CVSS3.1

CVE-2025-38304 - Bluetooth: Fix NULL pointer deference on eir_get_service_data

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix NULL pointer deference on eir_get_service_data The len parameter is considered optional so it can be NULL so it cannot be used for skipping to next entry of EIR_SERVICE_DATA.

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 5:57 p.m.

7.1

CVSS3.1

CVE-2025-38286 - pinctrl: at91: Fix possible out-of-boundary access

In the Linux kernel, the following vulnerability has been resolved: pinctrl: at91: Fix possible out-of-boundary access at91_gpio_probe() doesn't check that given OF alias is not available or something went wrong when trying to get it. This might have consequences when accessing gpio_chips array w…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 4:44 p.m.

5.5

CVSS3.1

CVE-2025-38318 - perf: arm-ni: Fix missing platform_set_drvdata()

In the Linux kernel, the following vulnerability has been resolved: perf: arm-ni: Fix missing platform_set_drvdata() Add missing platform_set_drvdata in arm_ni_probe(), otherwise calling platform_get_drvdata() in remove returns NULL.

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 12:54 p.m.

5.5

CVSS3.1

CVE-2025-38332 - scsi: lpfc: Use memcpy() for BIOS version

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Use memcpy() for BIOS version The strlcat() with FORTIFY support is triggering a panic because it thinks the target buffer will overflow although the correct target buffer size is passed in. Anyway, instead of memset…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:30 p.m.

5.5

CVSS3.1

CVE-2025-38282 - kernfs: Relax constraint in draining guard

In the Linux kernel, the following vulnerability has been resolved: kernfs: Relax constraint in draining guard The active reference lifecycle provides the break/unbreak mechanism but the active reference is not truly active after unbreak -- callers don't use it afterwards but it's important for p…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 4:50 p.m.

7.8

CVSS3.1

CVE-2025-38338 - fs/nfs/read: fix double-unlock bug in nfs_return_empty_folio()

In the Linux kernel, the following vulnerability has been resolved: fs/nfs/read: fix double-unlock bug in nfs_return_empty_folio() Sometimes, when a file was read while it was being truncated by another NFS client, the kernel could deadlock because folio_unlock() was called twice, and the second …

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 12:52 p.m.

7.8

CVSS3.1

CVE-2025-38295 - perf/amlogic: Replace smp_processor_id() with raw_smp_processor_id() in meson_ddr_pmu_create()

In the Linux kernel, the following vulnerability has been resolved: perf/amlogic: Replace smp_processor_id() with raw_smp_processor_id() in meson_ddr_pmu_create() The Amlogic DDR PMU driver meson_ddr_pmu_create() function incorrectly uses smp_processor_id(), which assumes disabled preemption. Thi…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4 p.m.

4.1

CVSS3.1

CVE-2025-47811 -

In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default. The web application itself offers several legitimate ways to execute arbitrary system commands (i.e., through the web console or the task scheduler), and they ar…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: July 17, 2025, 1:18 p.m.
Total resulsts: 347056
Page 4480 of 34,706
Β« previous page Β» next page
Filters