9.8

CVSS3.1

CVE-2025-4322 - Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover

The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change…

πŸ“… Published: May 20, 2025, 5:30 a.m. πŸ”„ Last Modified: April 22, 2026, 7:15 a.m.

0.0

CVE-2025-4974 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: May 20, 2025, 12:30 a.m. πŸ”„ Last Modified: Sept. 11, 2025, 10:19 p.m.

7.8

CVSS3.1

CVE-2025-37979 - ASoC: qcom: Fix sc7280 lpass potential buffer overflow

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix sc7280 lpass potential buffer overflow Case values introduced in commit 5f78e1fb7a3e ("ASoC: qcom: Add driver support for audioreach solution") cause out of bounds access in arrays of sc7280 driver data (e.g. in c…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 8:31 p.m.

5.5

CVSS3.1

CVE-2025-37967 - usb: typec: ucsi: displayport: Fix deadlock

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix deadlock This patch introduces the ucsi_con_mutex_lock / ucsi_con_mutex_unlock functions to the UCSI driver. ucsi_con_mutex_lock ensures the connector mutex is only locked if a connection is est…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 8:30 p.m.

7.8

CVSS3.1

CVE-2025-5914 - Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, en…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: April 20, 2026, 4:30 p.m.

5.5

CVSS3.1

CVE-2025-37937 - objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds()

In the Linux kernel, the following vulnerability has been resolved: objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds() If dib8000_set_dds()'s call to dib8000_read32() returns zero, the result is a divide-by-zero. Prevent that from happening. Fixes the following warning with an…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 5:41 p.m.

7.8

CVSS3.1

CVE-2025-37947 - ksmbd: prevent out-of-bounds stream writes by validating *pos

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds stream writes by validating *pos ksmbd_vfs_stream_write() did not validate whether the write offset (*pos) was within the bounds of the existing stream data length (v_len). If *pos was greater than or…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 3:56 p.m.

7.8

CVSS3.1

CVE-2025-37899 - ksmbd: fix use-after-free in session logoff

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in session logoff The sess->user object can currently be in use by another thread, for example if another connection has sent a session setup request to bind to the session being free'd. The handler for …

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

6.6

CVSS3.1

CVE-2025-5915 - Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 4:15 a.m.

5.5

CVSS3.1

CVE-2025-37945 - net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY

In the Linux kernel, the following vulnerability has been resolved: net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY DSA has 2 kinds of drivers: 1. Those who call dsa_switch_suspend() and dsa_switch_resume() from their device PM ops: qca8k-8xxx, bcm_sf2, …

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: April 20, 2026, 6:15 p.m.
Total resulsts: 347061
Page 5101 of 34,707
Β« previous page Β» next page
Filters