5.5

CVSS3.1

CVE-2025-22106 - vmxnet3: unregister xdp rxq info in the reset path

In the Linux kernel, the following vulnerability has been resolved: vmxnet3: unregister xdp rxq info in the reset path vmxnet3 does not unregister xdp rxq info in the vmxnet3_reset_work() code path as vmxnet3_rq_destroy() is not invoked in this code path. So, we get below message with a backtrace…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 6:42 p.m.

5.5

CVSS3.1

CVE-2025-22105 - bonding: check xdp prog when set bond mode

In the Linux kernel, the following vulnerability has been resolved: bonding: check xdp prog when set bond mode Following operations can trigger a warning[1]: ip netns add ns1 ip netns exec ns1 ip link add bond0 type bond mode balance-rr ip netns exec ns1 ip link set dev bond0 xdp obj…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

5.5

CVSS3.1

CVE-2025-22103 - net: fix NULL pointer dereference in l3mdev_l3_rcv

In the Linux kernel, the following vulnerability has been resolved: net: fix NULL pointer dereference in l3mdev_l3_rcv When delete l3s ipvlan: ip link del link eth0 ipvlan1 type ipvlan mode l3s This may cause a null pointer dereference: Call trace: ip_rcv_finish+0x48/0xd0 ip_…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 10:15 a.m.

9.8

CVSS3.1

CVE-2025-29708 -

SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 4:33 p.m.

6.1

CVSS3.1

CVE-2025-43703 -

An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access to the internal API (even though the attacker has no knowledge of an API key) through approaches such as scripts or the SRC attribute of an IMG element. NOTE: this issue exists be…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 2:56 p.m.

4.7

CVSS3.1

CVE-2025-43704 -

Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-22070 - fs/9p: fix NULL pointer dereference on mkdir

In the Linux kernel, the following vulnerability has been resolved: fs/9p: fix NULL pointer dereference on mkdir When a 9p tree was mounted with option 'posixacl', parent directory had a default ACL set for its subdirectories, e.g.: setfacl -m default:group:simpsons:rwx parentdir then creatin…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 5:15 p.m.

5.5

CVSS3.1

CVE-2025-22028 - media: vimc: skip .s_stream() for stopped entities

In the Linux kernel, the following vulnerability has been resolved: media: vimc: skip .s_stream() for stopped entities Syzbot reported [1] a warning prompted by a check in call_s_stream() that checks whether .s_stream() operation is warranted for unstarted or stopped subdevs. Add a simple fix in…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 7:05 p.m.

9.8

CVSS3.1

CVE-2024-40072 -

Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 4:59 p.m.

5.5

CVSS3.1

CVE-2025-22034 - mm/gup: reject FOLL_SPLIT_PMD with hugetlb VMAs

In the Linux kernel, the following vulnerability has been resolved: mm/gup: reject FOLL_SPLIT_PMD with hugetlb VMAs Patch series "mm: fixes for device-exclusive entries (hmm)", v2. Discussing the PageTail() call in make_device_exclusive_range() with Willy, I recently discovered [1] that device-e…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 8:07 p.m.
Total resulsts: 349182
Page 5797 of 34,919
Β« previous page Β» next page
Filters