3.5

CVSS3.1

CVE-2024-58248 -

nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 5:14 p.m.

5.5

CVSS3.1

CVE-2025-22065 - idpf: fix adapter NULL pointer dereference on reboot

In the Linux kernel, the following vulnerability has been resolved: idpf: fix adapter NULL pointer dereference on reboot With SRIOV enabled, idpf ends up calling into idpf_remove() twice. First via idpf_shutdown() and then again when idpf_remove() calls into sriov_disable(), because the VF device…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:15 p.m.

5.5

CVSS3.1

CVE-2025-22032 - wifi: mt76: mt7921: fix kernel panic due to null pointer dereference

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix kernel panic due to null pointer dereference Address a kernel panic caused by a null pointer dereference in the `mt792x_rx_get_wcid` function. The issue arises because the `deflink` structure is not proper…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 5:15 p.m.

5.5

CVSS3.1

CVE-2025-22090 - x86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range()

In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range() If track_pfn_copy() fails, we already added the dst VMA to the maple tree. As fork() fails, we'll cleanup the maple tree, and stumble over the dst VMA for whi…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Jan. 11, 2026, 5:15 p.m.

9.8

CVSS3.1

CVE-2024-40073 -

Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 4:59 p.m.

4.8

CVSS3.1

CVE-2024-40074 -

Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 4:58 p.m.

5.5

CVSS3.1

CVE-2025-22099 - drm: xlnx: zynqmp_dpsub: Add NULL check in zynqmp_audio_init

In the Linux kernel, the following vulnerability has been resolved: drm: xlnx: zynqmp_dpsub: Add NULL check in zynqmp_audio_init devm_kasprintf() calls can return null pointers on failure. But some return values were not checked in zynqmp_audio_init(). Add NULL check in zynqmp_audio_init(), avoi…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 5:05 p.m.

5.4

CVSS3.1

CVE-2025-26153 -

A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

5.4

CVSS3.1

CVE-2024-40069 -

Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5 p.m.

5.5

CVSS3.1

CVE-2025-22053 - net: ibmveth: make veth_pool_store stop hanging

In the Linux kernel, the following vulnerability has been resolved: net: ibmveth: make veth_pool_store stop hanging v2: - Created a single error handling unlock and exit in veth_pool_store - Greatly expanded commit message with previous explanatory-only text Summary: Use rtnl_mutex to synchroniz…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 8:18 p.m.
Total resulsts: 344055
Page 5277 of 34,406
Β« previous page Β» next page
Filters