6.4

CVSS3.1

CVE-2024-9017 - PeepSo Core: Groups <= 6.4.6.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Group …

The PeepSo Core: Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Group Description field in all versions up to, and including, 6.4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-lev…

πŸ“… Published: July 3, 2025, 6:44 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-5944 - Element Pack Addons for Elementor <= 8.0.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Si…

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜data-caption’ attribute in all versions up to, and including, 8.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with C…

πŸ“… Published: July 3, 2025, 4:25 a.m. πŸ”„ Last Modified: July 9, 2025, 5:52 p.m.

5.5

CVSS3.1

CVE-2025-38127 - ice: fix Tx scheduler error handling in XDP callback

In the Linux kernel, the following vulnerability has been resolved: ice: fix Tx scheduler error handling in XDP callback When the XDP program is loaded, the XDP callback adds new Tx queues. This means that the callback must update the Tx scheduler with the new queue number. In the event of a Tx s…

πŸ“… Published: July 3, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 9:32 p.m.

7.8

CVSS3.1

CVE-2025-38109 - net/mlx5: Fix ECVF vports unload on shutdown flow

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix ECVF vports unload on shutdown flow Fix shutdown flow UAF when a virtual function is created on the embedded chip (ECVF) of a BlueField device. In such case the vport acl ingress table is not properly destroyed. EC…

πŸ“… Published: July 3, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 9:36 p.m.

4.7

CVSS3.1

CVE-2025-38112 - net: Fix TOCTOU issue in sk_is_readable()

In the Linux kernel, the following vulnerability has been resolved: net: Fix TOCTOU issue in sk_is_readable() sk->sk_prot->sock_is_readable is a valid function pointer when sk resides in a sockmap. After the last sk_psock_put() (which usually happens when socket is removed from sockmap), sk->sk_p…

πŸ“… Published: July 3, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 6:13 p.m.

5.5

CVSS3.1

CVE-2025-38124 - net: fix udp gso skb_segment after pull from frag_list

In the Linux kernel, the following vulnerability has been resolved: net: fix udp gso skb_segment after pull from frag_list Commit a1e40ac5b5e9 ("net: gso: fix udp gso fraglist segmentation after pull from frag_list") detected invalid geometry in frag_list skbs and redirects them from skb_segment_…

πŸ“… Published: July 3, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 6:11 p.m.

5.5

CVSS3.1

CVE-2025-38099 - Bluetooth: Disable SCO support if READ_VOICE_SETTING is unsupported/broken

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Disable SCO support if READ_VOICE_SETTING is unsupported/broken A SCO connection without the proper voice_setting can cause the controller to lock up.

πŸ“… Published: July 3, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:30 p.m.

5.5

CVSS3.1

CVE-2025-38105 - ALSA: usb-audio: Kill timer properly at removal

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Kill timer properly at removal The USB-audio MIDI code initializes the timer, but in a rare case, the driver might be freed without the disconnect call. This leaves the timer in an active state while the assigne…

πŸ“… Published: July 3, 2025, midnight πŸ”„ Last Modified: March 25, 2026, 11:16 a.m.

7.8

CVSS3.1

CVE-2025-38129 - page_pool: Fix use-after-free in page_pool_recycle_in_ring

In the Linux kernel, the following vulnerability has been resolved: page_pool: Fix use-after-free in page_pool_recycle_in_ring syzbot reported a uaf in page_pool_recycle_in_ring: BUG: KASAN: slab-use-after-free in lock_release+0x151/0xa30 kernel/locking/lockdep.c:5862 Read of size 8 at addr ffff…

πŸ“… Published: July 3, 2025, midnight πŸ”„ Last Modified: Jan. 19, 2026, 1:16 p.m.

5.5

CVSS3.1

CVE-2025-38125 - net: stmmac: make sure that ptp_rate is not 0 before configuring EST

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: make sure that ptp_rate is not 0 before configuring EST If the ptp_rate recorded earlier in the driver happens to be 0, this bogus value will propagate up to EST configuration, where it will trigger a division by 0. …

πŸ“… Published: July 3, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 1:16 p.m.
Total resulsts: 349182
Page 4805 of 34,919
Β« previous page Β» next page
Filters