8.7

CVSS4.0

CVE-2025-4148 - Netgear EX6200 sub_503FC buffer overflow

A vulnerability was found in Netgear EX6200 1.0.3.94 and classified as critical. Affected by this issue is the function sub_503FC. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not reโ€ฆ

๐Ÿ“… Published: May 1, 2025, 3 a.m. ๐Ÿ”„ Last Modified: May 12, 2025, 7:38 p.m.

8.1

CVSS3.1

CVE-2025-2816 - Page View Count 2.8.0 - 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Limited Optionโ€ฆ

The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the yellow_message_dontshow() function in versions 2.8.0 to 2.8.4. This makes it possible for authenticated attackers, with Subscribeโ€ฆ

๐Ÿ“… Published: May 1, 2025, 2:23 a.m. ๐Ÿ”„ Last Modified: May 12, 2025, 7:38 p.m.

8.7

CVSS4.0

CVE-2025-4147 - Netgear EX6200 sub_47F7C buffer overflow

A vulnerability has been found in Netgear EX6200 1.0.3.94 and classified as critical. Affected by this vulnerability is the function sub_47F7C. The manipulation of the argument host leads to buffer overflow. The attack can be launched remotely. The vendor was contacted early about this disclosure bโ€ฆ

๐Ÿ“… Published: May 1, 2025, 2 a.m. ๐Ÿ”„ Last Modified: May 12, 2025, 7:38 p.m.

8.7

CVSS4.0

CVE-2025-4146 - Netgear EX6200 sub_41940 buffer overflow

A vulnerability, which was classified as critical, was found in Netgear EX6200 1.0.3.94. Affected is the function sub_41940. The manipulation of the argument host leads to buffer overflow. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did notโ€ฆ

๐Ÿ“… Published: May 1, 2025, 1 a.m. ๐Ÿ”„ Last Modified: May 12, 2025, 7:38 p.m.

5.3

CVSS4.0

CVE-2025-4144 - PKCE bypass via downgrade attack

PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, itย was found that an attacker could cause the check to be skipped. Fixed in: https://github.com/cloudflare/workers-oauth-provider/pulโ€ฆ

๐Ÿ“… Published: May 1, 2025, 12:50 a.m. ๐Ÿ”„ Last Modified: May 12, 2025, 7:39 p.m.

6

CVSS4.0

CVE-2025-4143 - Missing validation of redirect_uri on authorize endpoint

The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on the allowed list of redirect URIs for the given client registration. Fixed in:ย  https://github.com/cloudflare/workers-oaโ€ฆ

๐Ÿ“… Published: May 1, 2025, 12:19 a.m. ๐Ÿ”„ Last Modified: May 12, 2025, 7:39 p.m.

8.7

CVSS4.0

CVE-2025-4145 - Netgear EX6200 sub_3D0BC buffer overflow

A vulnerability, which was classified as critical, has been found in Netgear EX6200 1.0.3.94. This issue affects the function sub_3D0BC. The manipulation of the argument host leads to buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure but didโ€ฆ

๐Ÿ“… Published: May 1, 2025, midnight ๐Ÿ”„ Last Modified: May 12, 2025, 7:39 p.m.

5.5

CVSS3.1

CVE-2022-49861 - dmaengine: mv_xor_v2: Fix a resource leak in mv_xor_v2_remove()

In the Linux kernel, the following vulnerability has been resolved: dmaengine: mv_xor_v2: Fix a resource leak in mv_xor_v2_remove() A clk_prepare_enable() call in the probe is not balanced by a corresponding clk_disable_unprepare() in the remove function. Add the missing call.

๐Ÿ“… Published: May 1, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 4:15 p.m.

5.5

CVSS3.1

CVE-2022-49783 - x86/fpu: Drop fpregs lock before inheriting FPU permissions

In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Drop fpregs lock before inheriting FPU permissions Mike Galbraith reported the following against an old fork of preempt-rt but the same issue also applies to the current preempt-rt tree. BUG: sleeping function calledโ€ฆ

๐Ÿ“… Published: May 1, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 7, 2025, 5:48 p.m.

5.5

CVSS3.1

CVE-2022-49822 - cifs: Fix connections leak when tlink setup failed

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix connections leak when tlink setup failed If the tlink setup failed, lost to put the connections, then the module refcnt leak since the cifsd kthread not exit. Also leak the fscache info, and for next mount with fsc, itโ€ฆ

๐Ÿ“… Published: May 1, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 10, 2025, 8:17 p.m.
Total resulsts: 347814
Page 5453 of 34,782
ยซ previous page ยป next page
Filters