7.8

CVSS3.1

CVE-2025-40364 - io_uring: fix io_req_prep_async with provided buffers

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if needed.

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 2:06 p.m.

9.1

CVSS3.1

CVE-2024-29643 -

An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 3:51 p.m.

5.5

CVSS3.1

CVE-2025-38575 - ksmbd: use aead_request_free to match aead_request_alloc

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_alloc Use aead_request_free() instead of kfree() to properly free memory allocated by aead_request_alloc(). This ensures sensitive crypto data is zeroed before being freed.

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 2:31 p.m.

9.8

CVSS3.1

CVE-2024-53591 -

An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 7:41 p.m.

6.3

CVSS3.1

CVE-2024-46089 -

74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 5:39 p.m.

7.5

CVSS3.1

CVE-2025-28228 -

A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 2:08 p.m.

5.5

CVSS3.1

CVE-2025-39930 - ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai()

In the Linux kernel, the following vulnerability has been resolved: ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai() commit 419d1918105e ("ASoC: simple-card-utils: use __free(device_node) for device node") uses __free(device_node) for dlc->of_node, but we need to k…

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: March 25, 2026, 10:19 a.m.

5.5

CVSS3.1

CVE-2025-38637 - net_sched: skbprio: Remove overly strict queue assertions

In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue assertions In the current implementation, skbprio enqueue/dequeue contains an assertion that fails under certain conditions when SKBPRIO is used as a child qdisc under TBF with speci…

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 9:35 p.m.

4.7

CVSS3.1

CVE-2025-38104 - drm/amdgpu: Replace Mutex with Spinlock for RLCG register access to avoid Priority Inversion in SRI…

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Replace Mutex with Spinlock for RLCG register access to avoid Priority Inversion in SRIOV RLCG Register Access is a way for virtual functions to safely access GPU registers in a virtualized environment., including TLB…

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 2:34 p.m.

7.1

CVSS3.1

CVE-2025-39735 - jfs: fix slab-out-of-bounds read in ea_get()

In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds read in ea_get() During the "size_check" label in ea_get(), the code checks if the extended attribute list (xattr) size matches ea_size. If not, it logs "ea_get: invalid extended attribute" and calls p…

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.
Total resulsts: 343887
Page 5193 of 34,389
Β« previous page Β» next page
Filters