8.1
CVE-2025-1290 -
A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before a worker thread accesses it resulting in a โฆ
3.3
CVE-2021-47671 - can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path
In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path In es58x_rx_err_msg(), if can->do_set_mode() fails, the function directly returns without calling netif_rx(skb). This means that the skb previously allocated by aโฆ
7.8
CVE-2021-47669 - can: vxcan: vxcan_xmit: fix use after free bug
In the Linux kernel, the following vulnerability has been resolved: can: vxcan: vxcan_xmit: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the canfd_frame cfd which aliases skb memory is accessed after the netif_rx_ni().
7.8
CVE-2021-47668 - can: dev: can_restart: fix use after free bug
In the Linux kernel, the following vulnerability has been resolved: can: dev: can_restart: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the netif_rx_ni() in: stats->rx_bytes += cf-โฆ
6.1
CVE-2025-29015 -
Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.
6.5
CVE-2025-29455 -
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.
7.6
CVE-2025-29457 -
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function.
9.8
CVE-2025-29043 -
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234
9.8
CVE-2025-29040 -
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c
7.6
CVE-2025-29451 -
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.