9.8

CVSS3.1

CVE-2024-42733 -

An issue in Docmosis Tornado v.2.9.7 and before allows a remote attacker to execute arbitrary code via a crafted script to the UNC path input

πŸ“… Published: March 7, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 7:40 p.m.

5.5

CVSS3.1

CVE-2025-21838 - usb: gadget: core: flush gadget workqueue after device removal

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: flush gadget workqueue after device removal device_del() can lead to new work being scheduled in gadget->work workqueue. This is observed, for example, with the dwc3 driver with the following call stack: devi…

πŸ“… Published: March 7, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.5

CVSS3.1

CVE-2025-21840 - thermal/netlink: Prevent userspace segmentation fault by adjusting UAPI header

In the Linux kernel, the following vulnerability has been resolved: thermal/netlink: Prevent userspace segmentation fault by adjusting UAPI header The intel-lpmd tool [1], which uses the THERMAL_GENL_ATTR_CPU_CAPABILITY attribute to receive HFI events from kernel space, encounters a segmentation …

πŸ“… Published: March 7, 2025, midnight πŸ”„ Last Modified: Oct. 29, 2025, 9:09 p.m.

5.5

CVSS3.1

CVE-2025-21835 - usb: gadget: f_midi: fix MIDI Streaming descriptor lengths

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: fix MIDI Streaming descriptor lengths While the MIDI jacks are configured correctly, and the MIDIStreaming endpoint descriptors are filled with the correct information, bNumEmbMIDIJack and bLength are set inc…

πŸ“… Published: March 7, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:19 p.m.

6.4

CVSS3.1

CVE-2025-27825 -

An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.

πŸ“… Published: March 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-27822 -

An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop CMS. It allows people to temporarily switch to another user account. The module provides a "Masquerade as admin" permission to restrict people (who can masquerade) from switching to an account with administrative privile…

πŸ“… Published: March 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-21836 - io_uring/kbuf: reallocate buf lists on upgrade

In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: reallocate buf lists on upgrade IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it was created for legacy selected buffer and has been emptied. It violates the requirement that most of the field…

πŸ“… Published: March 7, 2025, midnight πŸ”„ Last Modified: March 7, 2026, 12:15 p.m.

6.4

CVSS3.1

CVE-2025-27823 -

An issue was discovered in the Mail Disguise module before 1.x-1.0.5 for Backdrop CMS. It enables a website to obfuscate email addresses, and should prevent spambots from collecting them. The module doesn't sufficiently validate the data attribute value on links, potentially leading to a Cross Site…

πŸ“… Published: March 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.2

CVSS3.1

CVE-2025-27839 -

operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification results to be disregarded during the first scan of a card. Exploitation may not have been possible.

πŸ“… Published: March 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-21837 - kernel: io_uring/uring_cmd: unconditionally copy SQEs at prep time

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: March 7, 2025, midnight πŸ”„ Last Modified: May 20, 2025, 2:15 p.m.
Total resulsts: 349182
Page 6424 of 34,919
Β« previous page Β» next page
Filters