7.8

CVSS3.1

CVE-2025-38350 - net/sched: Always pass notifications when child class becomes empty

In the Linux kernel, the following vulnerability has been resolved: net/sched: Always pass notifications when child class becomes empty Certain classful qdiscs may invoke their classes' dequeue handler on an enqueue operation. This may unexpectedly empty the child qdisc and thus make an in-flight…

πŸ“… Published: July 19, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 5:34 p.m.

4

CVSS3.1

CVE-2025-52924 -

In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.

πŸ“… Published: July 19, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-54313 - eslint-config-prettier: Eslint-config-prettier Supply Chain Compromise

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

πŸ“… Published: July 19, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

7.5

CVSS3.0

CVE-2025-27210 -

An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.

πŸ“… Published: July 18, 2025, 10:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.0

CVE-2025-27209 - nodejs: Node.js Rapidhash HashDoS Vulnerability

The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an attacker can generate collisions even without…

πŸ“… Published: July 18, 2025, 10:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.6

CVSS4.0

CVE-2025-7396 - Curve25519 Blinding

In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding configure option is only for the base C implementation of Curve25519. It is not needed, or available with; ARM assembly builds, Intel assembly builds, and the small Curve25519 feature…

πŸ“… Published: July 18, 2025, 10:51 p.m. πŸ”„ Last Modified: Dec. 3, 2025, 3:25 p.m.

7

CVSS4.0

CVE-2025-7394 -

In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both…

πŸ“… Published: July 18, 2025, 10:34 p.m. πŸ”„ Last Modified: Dec. 3, 2025, 3:21 p.m.

9.2

CVSS4.0

CVE-2025-7395 - Domain Name Validation Bypass with Apple Native Certificate Validation

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted re…

πŸ“… Published: July 18, 2025, 10:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-7814 - code-projects Food Ordering Review System signup_function.php sql injection

A vulnerability classified as critical was found in code-projects Food Ordering Review System 1.0. This vulnerability affects unknown code of the file /pages/signup_function.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has bee…

πŸ“… Published: July 18, 2025, 9:44 p.m. πŸ”„ Last Modified: July 29, 2025, 8:45 p.m.

8.7

CVSS4.0

CVE-2025-7807 - Tenda FH451 SafeUrlFilter fromSafeUrlFilter stack-based overflow

A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. This issue affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. The manipulation of the argument Go/page leads to stack-based buffer overflow. The attack may be initiated remotely. The exp…

πŸ“… Published: July 18, 2025, 8:44 p.m. πŸ”„ Last Modified: July 23, 2025, 4:40 p.m.
Total resulsts: 349182
Page 4592 of 34,919
Β« previous page Β» next page
Filters