5.3

CVSS3.1

CVE-2025-51540 -

EzGED3 3.5.0 stores user passwords using an insecure hashing scheme: md5(md5(password)). This hashing method is cryptographically weak and allows attackers to perform efficient offline brute-force attacks if password hashes are disclosed. The lack of salting and use of a fast, outdated algorithm ma…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 2:40 p.m.

5.5

CVSS3.1

CVE-2025-38565 - perf/core: Exit early on perf_mmap() fail

In the Linux kernel, the following vulnerability has been resolved: perf/core: Exit early on perf_mmap() fail When perf_mmap() fails to allocate a buffer, it still invokes the event_mapped() callback of the related event. On X86 this might increase the perf_rdpmc_allowed reference counter. But no…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 2:40 p.m.

5.5

CVSS3.1

CVE-2025-38571 - sunrpc: fix client side handling of tls alerts

In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix client side handling of tls alerts A security exploit was discovered in NFS over TLS in tls_alert_recv due to its assumption that there is valid data in the msghdr's iterator's kvec. Instead, this patch proposes the …

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 2:40 p.m.

5.3

CVSS3.1

CVE-2025-50434 -

A security issue has been identified in Appian Enterprise Business Process Management version 25.3. The vulnerability is related to incorrect access control, which under certain conditions could allow unauthorized access to information.

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 2:40 p.m.

7.0

CVSS3.1

CVE-2025-38566 - sunrpc: fix handling of server side tls alerts

In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix handling of server side tls alerts Scott Mayhew discovered a security exploit in NFS over TLS in tls_alert_recv() due to its assumption it can read data from the msg iterator's kvec.. kTLS implementation splits TLS n…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 2:40 p.m.

7.0

CVSS3.1

CVE-2025-38584 - padata: Fix pd UAF once and for all

In the Linux kernel, the following vulnerability has been resolved: padata: Fix pd UAF once and for all There is a race condition/UAF in padata_reorder that goes back to the initial commit. A reference count is taken at the start of the process in padata_do_parallel, and released at the end in p…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 2:40 p.m.

5.5

CVSS3.1

CVE-2025-38586 - bpf, arm64: Fix fp initialization for exception boundary

In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Fix fp initialization for exception boundary In the ARM64 BPF JIT when prog->aux->exception_boundary is set for a BPF program, find_used_callee_regs() is not called because for a program acting as exception boundary, …

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 2:40 p.m.

5.3

CVSS3.1

CVE-2025-51529 -

Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unlimited database write operations to the wp_ajax_nopriv_cacsp_i…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 2:40 p.m.

9.8

CVSS3.1

CVE-2024-44373 -

A Path Traversal vulnerability in AllSky v2023.05.01_04 allows an unauthenticated attacker to create a webshell and remote code execution via the path, content parameter to /includes/save_file.php.

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Aug. 19, 2025, 8:15 p.m.

7.0

CVSS3.1

CVE-2025-38592 - Bluetooth: hci_devcd_dump: fix out-of-bounds via dev_coredumpv

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_devcd_dump: fix out-of-bounds via dev_coredumpv Currently both dev_coredumpv and skb_put_data in hci_devcd_dump use hdev->dump.head. However, dev_coredumpv can free the buffer. From dev_coredumpm_timeout documentat…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 2:40 p.m.
Total resulsts: 306438
Page 45 of 30,644
Β« previous page Β» next page
Filters