0.0

CVE-2025-38523 - cifs: Fix the smbd_response slab to allow usercopy

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix the smbd_response slab to allow usercopy The handling of received data in the smbdirect client code involves using copy_to_iter() to copy data from the smbd_reponse struct's packet trailer to a folioq buffer provided byโ€ฆ

๐Ÿ“… Published: Aug. 16, 2025, 11:12 a.m. ๐Ÿ”„ Last Modified: Aug. 16, 2025, 11:12 a.m.

0.0

CVE-2025-38522 - sched/ext: Prevent update_locked_rq() calls with NULL rq

In the Linux kernel, the following vulnerability has been resolved: sched/ext: Prevent update_locked_rq() calls with NULL rq Avoid invoking update_locked_rq() when the runqueue (rq) pointer is NULL in the SCX_CALL_OP and SCX_CALL_OP_RET macros. Previously, calling update_locked_rq(NULL) with preโ€ฆ

๐Ÿ“… Published: Aug. 16, 2025, 11:12 a.m. ๐Ÿ”„ Last Modified: Aug. 16, 2025, 11:12 a.m.

6.4

CVSS3.1

CVE-2025-8143 - Soledad <= 8.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pcsml_smartlists_h'

The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜pcsml_smartlists_hโ€™ parameter in all versions up to, and including, 8.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acceโ€ฆ

๐Ÿ“… Published: Aug. 16, 2025, 11:11 a.m. ๐Ÿ”„ Last Modified: Aug. 16, 2025, 12:15 p.m.

7.3

CVSS3.1

CVE-2025-8105 - Soledad <= 8.6.7 - Unauthenticated Arbitrary Shortcode Execution

The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticโ€ฆ

๐Ÿ“… Published: Aug. 16, 2025, 11:11 a.m. ๐Ÿ”„ Last Modified: Aug. 16, 2025, 12:15 p.m.

6.5

CVSS3.1

CVE-2025-8878 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Contโ€ฆ

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content โ€“ ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.4. This is due to the software allowing users to execute an acโ€ฆ

๐Ÿ“… Published: Aug. 16, 2025, 11:11 a.m. ๐Ÿ”„ Last Modified: Aug. 16, 2025, 12:15 p.m.

8.8

CVSS3.1

CVE-2025-8142 - Soledad <= 8.6.7 - Authenticated (Contributor+) Local File Inclusion via 'header_layout'

The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via the 'header_layout' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the serverโ€ฆ

๐Ÿ“… Published: Aug. 16, 2025, 11:11 a.m. ๐Ÿ”„ Last Modified: Aug. 16, 2025, 11:11 a.m.

0.0

CVE-2025-38521 - drm/imagination: Fix kernel crash when hard resetting the GPU

In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix kernel crash when hard resetting the GPU The GPU hard reset sequence calls pm_runtime_force_suspend() and pm_runtime_force_resume(), which according to their documentation should only be used during system-wiโ€ฆ

๐Ÿ“… Published: Aug. 16, 2025, 10:55 a.m. ๐Ÿ”„ Last Modified: Aug. 16, 2025, 10:55 a.m.

0.0

CVE-2025-38520 - drm/amdkfd: Don't call mmput from MMU notifier callback

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Don't call mmput from MMU notifier callback If the process is exiting, the mmput inside mmu notifier callback from compactd or fork or numa balancing could release the last reference of mm struct to call exit_mmap andโ€ฆ

๐Ÿ“… Published: Aug. 16, 2025, 10:55 a.m. ๐Ÿ”„ Last Modified: Aug. 16, 2025, 10:55 a.m.

0.0

CVE-2025-38519 - mm/damon: fix divide by zero in damon_get_intervals_score()

In the Linux kernel, the following vulnerability has been resolved: mm/damon: fix divide by zero in damon_get_intervals_score() The current implementation allows having zero size regions with no special reasons, but damon_get_intervals_score() gets crashed by divide by zero when the region size iโ€ฆ

๐Ÿ“… Published: Aug. 16, 2025, 10:55 a.m. ๐Ÿ”„ Last Modified: Aug. 16, 2025, 10:55 a.m.

0.0

CVE-2025-38518 - x86/CPU/AMD: Disable INVLPGB on Zen2

In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Disable INVLPGB on Zen2 AMD Cyan Skillfish (Family 17h, Model 47h, Stepping 0h) has an issue that causes system oopses and panics when performing TLB flush using INVLPGB. However, the problem is that that machine haโ€ฆ

๐Ÿ“… Published: Aug. 16, 2025, 10:55 a.m. ๐Ÿ”„ Last Modified: Aug. 16, 2025, 10:55 a.m.
Total resulsts: 305889
Page 8 of 30,589
ยซ previous page ยป next page
Filters