5.3

CVSS3.1

CVE-2025-6786 - DocCheck Login <= 1.1.5 - Unauthorized Post Access

The DocCheck Login plugin for WordPress is vulnerable to unauthorized post access in all versions up to, and including, 1.1.5. This is due to plugin redirecting a user to login on a password protected post after the page has loaded. This makes it possible for unauthenticated attackers to read posts…

πŸ“… Published: July 4, 2025, 1:43 a.m. πŸ”„ Last Modified: April 22, 2026, 2:45 p.m.

7.8

CVSS3.1

CVE-2025-38227 - media: vidtv: Terminating the subsequent process of initialization failure

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the subsequent process of initialization failure syzbot reported a slab-use-after-free Read in vidtv_mux_init. [1] After PSI initialization fails, the si member is accessed again, resulting in this uaf.…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:38 p.m.

5.5

CVSS3.1

CVE-2025-38208 - smb: client: add NULL check in automount_fullpath

In the Linux kernel, the following vulnerability has been resolved: smb: client: add NULL check in automount_fullpath page is checked for null in __build_path_from_dentry_optional_prefix when tcon->origin_fullpath is not set. However, the check is missing when it is set. Add a check to prevent a …

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:30 p.m.

5.5

CVSS3.1

CVE-2025-38205 - drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1 [Why] If the dummy values in `populate_dummy_dml_surface_cfg()` aren't updated then they can lead to a divide by zero in downstream callers like CalculateVMAn…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:08 p.m.

5.5

CVSS3.1

CVE-2025-38185 - atm: atmtcp: Free invalid length skb in atmtcp_c_send().

In the Linux kernel, the following vulnerability has been resolved: atm: atmtcp: Free invalid length skb in atmtcp_c_send(). syzbot reported the splat below. [0] vcc_sendmsg() copies data passed from userspace to skb and passes it to vcc->dev->ops->send(). atmtcp_c_send() accesses skb->data as …

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 4:53 p.m.

7.8

CVSS3.1

CVE-2025-38176 - binder: fix use-after-free in binderfs_evict_inode()

In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in binderfs_evict_inode() Running 'stress-ng --binderfs 16 --timeout 300' under KASAN-enabled kernel, I've noticed the following: BUG: KASAN: slab-use-after-free in binderfs_evict_inode+0x1de/0x2d0 Wri…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 9:03 p.m.

5.5

CVSS3.1

CVE-2025-38196 - io_uring/rsrc: validate buffer count with offset for cloning

In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: validate buffer count with offset for cloning syzbot reports that it can trigger a WARN_ON() for kmalloc() attempt that's too big: WARNING: CPU: 0 PID: 6488 at mm/slub.c:5024 __kvmalloc_node_noprof+0x520/0x640 mm/…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:24 p.m.

7.8

CVSS3.1

CVE-2025-38180 - net: atm: fix /proc/net/atm/lec handling

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix /proc/net/atm/lec handling /proc/net/atm/lec must ensure safety against dev_lec[] changes. It appears it had dev_put() calls without prior dev_hold(), leading to imbalance and UAF.

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:36 p.m.

8.1

CVSS3.1

CVE-2025-43711 -

Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upon the next boot) by dragging a crafted Tunnelblick.app file into /Applications.

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-38217 - hwmon: (ftsteutates) Fix TOCTOU race in fts_read()

In the Linux kernel, the following vulnerability has been resolved: hwmon: (ftsteutates) Fix TOCTOU race in fts_read() In the fts_read() function, when handling hwmon_pwm_auto_channels_temp, the code accesses the shared variable data->fan_source[channel] twice without holding any locks. It is fir…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 3:21 p.m.
Total resulsts: 349182
Page 4792 of 34,919
Β« previous page Β» next page
Filters