4.8

CVSS3.1

CVE-2024-40074 -

Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 4:58 p.m.

5.5

CVSS3.1

CVE-2025-22099 - drm: xlnx: zynqmp_dpsub: Add NULL check in zynqmp_audio_init

In the Linux kernel, the following vulnerability has been resolved: drm: xlnx: zynqmp_dpsub: Add NULL check in zynqmp_audio_init devm_kasprintf() calls can return null pointers on failure. But some return values were not checked in zynqmp_audio_init(). Add NULL check in zynqmp_audio_init(), avoi…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 5:05 p.m.

5.4

CVSS3.1

CVE-2025-26153 -

A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

5.4

CVSS3.1

CVE-2024-40069 -

Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5 p.m.

5.5

CVSS3.1

CVE-2025-22053 - net: ibmveth: make veth_pool_store stop hanging

In the Linux kernel, the following vulnerability has been resolved: net: ibmveth: make veth_pool_store stop hanging v2: - Created a single error handling unlock and exit in veth_pool_store - Greatly expanded commit message with previous explanatory-only text Summary: Use rtnl_mutex to synchroniz…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2025-22103 - net: fix NULL pointer dereference in l3mdev_l3_rcv

In the Linux kernel, the following vulnerability has been resolved: net: fix NULL pointer dereference in l3mdev_l3_rcv When delete l3s ipvlan: ip link del link eth0 ipvlan1 type ipvlan mode l3s This may cause a null pointer dereference: Call trace: ip_rcv_finish+0x48/0xd0 ip_…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 10:15 a.m.

5.5

CVSS3.1

CVE-2025-22037 - ksmbd: fix null pointer dereference in alloc_preauth_hash()

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can send smb2 session setup even thought conn->preauth_info is no…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Sept. 19, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2025-22072 - spufs: fix gang directory lifetimes

In the Linux kernel, the following vulnerability has been resolved: spufs: fix gang directory lifetimes prior to "[POWERPC] spufs: Fix gang destroy leaks" we used to have a problem with gang lifetimes - creation of a gang returns opened gang directory, which normally gets removed when that gets c…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.5

CVSS3.1

CVE-2025-22033 - arm64: Don't call NULL in do_compat_alignment_fixup()

In the Linux kernel, the following vulnerability has been resolved: arm64: Don't call NULL in do_compat_alignment_fixup() do_alignment_t32_to_handler() only fixes up alignment faults for specific instructions; it returns NULL otherwise (e.g. LDREX). When that's the case, signal to the caller that…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.5

CVSS3.1

CVE-2024-58092 - nfsd: fix legacy client tracking initialization

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix legacy client tracking initialization Get rid of the nfsd4_legacy_tracking_ops->init() call in check_for_legacy_methods(). That will be handled in the caller (nfsd4_client_tracking_init()). Otherwise, we'll wind up ca…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 7:11 p.m.
Total resulsts: 343970
Page 5269 of 34,397
Β« previous page Β» next page
Filters