4.3

CVSS3.1

CVE-2025-44003 -

Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with physical access to the reader to perform a limited denial of service when 125 kHz Card Technology is enabled. This issue affects T-Series Readers: 9.20 prior to vCR9.20.250213a (โ€ฆ

๐Ÿ“… Published: July 10, 2025, 3:09 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-35983 -

Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited denial of service or perform privileged overrides during the initial configuration of the Controller, there is no risk for Controllers once they are connโ€ฆ

๐Ÿ“… Published: July 10, 2025, 3:09 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-5807 - Gwolle Guestbook <= 4.9.2 - Unauthenticated Stored Cross-Site Scripting via `gwolle_gb_content` Parโ€ฆ

The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜gwolle_gb_contentโ€™ parameter in all versions up to, and including, 4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitraโ€ฆ

๐Ÿ“… Published: July 10, 2025, 1:43 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 1:15 a.m.

5.4

CVSS3.1

CVE-2025-4406 - wpForo Forum <= 2.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above,โ€ฆ

๐Ÿ“… Published: July 10, 2025, 1:43 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 5:15 p.m.

4.7

CVSS3.1

CVE-2025-38306 - fs/fhandle.c: fix a race in call of has_locked_children()

In the Linux kernel, the following vulnerability has been resolved: fs/fhandle.c: fix a race in call of has_locked_children() may_decode_fh() is calling has_locked_children() while holding no locks. That's an oopsable race... The rest of the callers are safe since they are holding namespace_sem โ€ฆ

๐Ÿ“… Published: July 10, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 18, 2025, 8:41 p.m.

5.5

CVSS3.1

CVE-2025-38272 - net: dsa: b53: do not enable EEE on bcm63xx

In the Linux kernel, the following vulnerability has been resolved: net: dsa: b53: do not enable EEE on bcm63xx BCM63xx internal switches do not support EEE, but provide multiple RGMII ports where external PHYs may be connected. If one of these PHYs are EEE capable, we may try to enable EEE for tโ€ฆ

๐Ÿ“… Published: July 10, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 20, 2025, 4:56 p.m.

5.5

CVSS3.1

CVE-2025-38335 - Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT

In the Linux kernel, the following vulnerability has been resolved: Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT When enabling PREEMPT_RT, the gpio_keys_irq_timer() callback runs in hard irq context, but the input_event() takes a spin_lock, which isn't allowed there as it is converโ€ฆ

๐Ÿ“… Published: July 10, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 16, 2025, 5:51 p.m.

5.5

CVSS3.1

CVE-2025-38319 - drm/amd/pp: Fix potential NULL pointer dereference in atomctrl_initialize_mc_reg_table

In the Linux kernel, the following vulnerability has been resolved: drm/amd/pp: Fix potential NULL pointer dereference in atomctrl_initialize_mc_reg_table The function atomctrl_initialize_mc_reg_table() and atomctrl_initialize_mc_reg_table_v2_2() does not check the return value of smu_atom_get_daโ€ฆ

๐Ÿ“… Published: July 10, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 19, 2025, 4:44 p.m.

5.5

CVSS3.1

CVE-2025-38308 - ASoC: Intel: avs: Fix possible null-ptr-deref when initing hw

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Fix possible null-ptr-deref when initing hw Search result of avs_dai_find_path_template() shall be verified before being used. As 'template' is already known when avs_hw_constraints_init() is fired, drop the seaโ€ฆ

๐Ÿ“… Published: July 10, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 18, 2025, 12:55 p.m.

5.5

CVSS3.1

CVE-2025-38301 - nvmem: zynqmp_nvmem: unbreak driver after cleanup

In the Linux kernel, the following vulnerability has been resolved: nvmem: zynqmp_nvmem: unbreak driver after cleanup Commit 29be47fcd6a0 ("nvmem: zynqmp_nvmem: zynqmp_nvmem_probe cleanup") changed the driver to expect the device pointer to be passed as the "context", but in nvmem the context parโ€ฆ

๐Ÿ“… Published: July 10, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 19, 2025, 8:13 p.m.
Total resulsts: 349182
Page 4691 of 34,919
ยซ previous page ยป next page
Filters