9.8

CVSS3.1

CVE-2025-30133 -

An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app for authentication, but its HTTP server lacks this restriction. Once connected to the dashcam's Wi-Fi network via the default password ("…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 8:07 p.m.

5.5

CVSS3.1

CVE-2025-38491 - mptcp: make fallback action and fallback decision atomic

In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision atomic Syzkaller reported the following splat: WARNING: CPU: 1 PID: 7704 at net/mptcp/protocol.h:1223 __mptcp_do_fallback net/mptcp/protocol.h:1223 [inline] WARNING: CPU: 1 P…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 4:26 p.m.

7.1

CVSS3.1

CVE-2025-38483 - comedi: das16m1: Fix bit shift out of bounds

In the Linux kernel, the following vulnerability has been resolved: comedi: das16m1: Fix bit shift out of bounds When checking for a supported IRQ number, the following test is used: /* only irqs 2, 3, 4, 5, 6, 7, 10, 11, 12, 14, and 15 are valid */ if ((1 << it->options[1]) & 0xdcfc) { Howev…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 4:25 p.m.

7.8

CVSS3.1

CVE-2025-38490 - net: libwx: remove duplicate page_pool_put_full_page()

In the Linux kernel, the following vulnerability has been resolved: net: libwx: remove duplicate page_pool_put_full_page() page_pool_put_full_page() should only be invoked when freeing Rx buffers or building a skb if the size is too short. At other times, the pages need to be reused. So remove th…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 5:46 p.m.

5.5

CVSS3.1

CVE-2025-38468 - net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree

In the Linux kernel, the following vulnerability has been resolved: net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree htb_lookup_leaf has a BUG_ON that can trigger with the following: tc qdisc del dev lo root tc qdisc add dev lo root handle 1: htb default 1 tc class add dev …

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 7:36 p.m.

7.5

CVSS3.1

CVE-2025-50494 -

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: July 29, 2025, 9:15 p.m.

5.5

CVSS3.1

CVE-2025-38474 - usb: net: sierra: check for no status endpoint

In the Linux kernel, the following vulnerability has been resolved: usb: net: sierra: check for no status endpoint The driver checks for having three endpoints and having bulk in and out endpoints, but not that the third endpoint is interrupt input. Rectify the omission.

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 7:29 p.m.

4.1

CVSS3.1

CVE-2023-53158 - gix-transport: gix Command Execution Vulnerability

The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit.

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.9

CVSS3.1

CVE-2023-53161 - buffered-reader: Buffered-Reader Out-of-Bounds Access Vulnerability

The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Aug. 6, 2025, 9:16 p.m.

5.5

CVSS3.1

CVE-2025-38481 - comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large

In the Linux kernel, the following vulnerability has been resolved: comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large The handling of the `COMEDI_INSNLIST` ioctl allocates a kernel buffer to hold the array of `struct comedi_insn`, getting the length from the `n_insns` member of the `stru…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 4:24 p.m.
Total resulsts: 349182
Page 4493 of 34,919
Β« previous page Β» next page
Filters