9.8

CVSS3.1

CVE-2025-26325 -

ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: April 10, 2025, 5:28 p.m.

7.1

CVSS3.1

CVE-2025-21717 - net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq kvzalloc_node is not doing a runtime check on the node argument (__alloc_pages_node_noprof does have a VM_BUG_ON, but it expands to nothing on !CONF…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 1:06 p.m.

5.5

CVSS3.1

CVE-2025-21805 - RDMA/rtrs: Add missing deinit() call

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Add missing deinit() call A warning is triggered when repeatedly connecting and disconnecting the rnbd: list_add corruption. prev->next should be next (ffff88800b13e480), but was ffff88801ecd1338. (prev=ffff88801ecd13…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 2:58 a.m.

5.5

CVSS3.1

CVE-2025-21799 - net: ethernet: ti: am65-cpsw: fix freeing IRQ in am65_cpsw_nuss_remove_tx_chns()

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: fix freeing IRQ in am65_cpsw_nuss_remove_tx_chns() When getting the IRQ we use k3_udma_glue_tx_get_irq() which returns negative error value on error. So not NULL check is not sufficient to deteremine…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:19 p.m.

7.1

CVSS3.1

CVE-2025-21794 - HID: hid-thrustmaster: fix stack-out-of-bounds read in usb_check_int_endpoints()

In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: fix stack-out-of-bounds read in usb_check_int_endpoints() Syzbot[1] has detected a stack-out-of-bounds read of the ep_addr array from hid-thrustmaster driver. This array is passed to usb_check_int_endpoints…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:19 p.m.

5.5

CVSS3.1

CVE-2025-21783 - gpiolib: Fix crash on error in gpiochip_get_ngpios()

In the Linux kernel, the following vulnerability has been resolved: gpiolib: Fix crash on error in gpiochip_get_ngpios() The gpiochip_get_ngpios() uses chip_*() macros to print messages. However these macros rely on gpiodev to be initialised and set, which is not the case when called via bgpio_in…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2025-21777 - ring-buffer: Validate the persistent meta data subbuf array

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Validate the persistent meta data subbuf array The meta data for a mapped ring buffer contains an array of indexes of all the subbuffers. The first entry is the reader page, and the rest of the entries lay out the or…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 8:36 p.m.

5.5

CVSS3.1

CVE-2025-21771 - sched_ext: Fix incorrect autogroup migration detection

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix incorrect autogroup migration detection scx_move_task() is called from sched_move_task() and tells the BPF scheduler that cgroup migration is being committed. sched_move_task() is used by both cgroup and autogroup …

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 8:30 p.m.

5.5

CVSS3.1

CVE-2025-21768 - net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels Some lwtunnels have a dst cache for post-transformation dst. If the packet destination did not change we may end up recording a reference to the lwtunnel in its own ca…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 8:28 p.m.

5.5

CVSS3.1

CVE-2025-21765 - ipv6: use RCU protection in ip6_default_advmss()

In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU protection in ip6_default_advmss() ip6_default_advmss() needs rcu protection to make sure the net structure it reads does not disappear.

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.
Total resulsts: 345134
Page 6140 of 34,514
Β« previous page Β» next page
Filters