5.5

CVSS3.1

CVE-2026-22993 - idpf: Fix RSS LUT NULL ptr issue after soft reset

In the Linux kernel, the following vulnerability has been resolved: idpf: Fix RSS LUT NULL ptr issue after soft reset During soft reset, the RSS LUT is freed and not restored unless the interface is up. If an ethtool command that accesses the rss lut is attempted immediately after reset, it will …

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 5:19 p.m.

5.5

CVSS3.1

CVE-2025-71160 - netfilter: nf_tables: avoid chain re-validation if possible

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: avoid chain re-validation if possible Hamza Mahfooz reports cpu soft lock-ups in nft_chain_validate(): watchdog: BUG: soft lockup - CPU#1 stuck for 27s! [iptables-nft-re:37547] [..] RIP: 0010:nft_chain_va…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 8:19 p.m.

5.5

CVSS3.1

CVE-2026-22982 - net: mscc: ocelot: Fix crash when adding interface under a lag

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix crash when adding interface under a lag Commit 15faa1f67ab4 ("lan966x: Fix crash when adding interface under a lag") fixed a similar issue in the lan966x driver caused by a NULL pointer dereference. The oce…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 6:48 p.m.

9.4

CVSS3.1

CVE-2025-52025 -

An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulnerability arises because user input is directly inserted into a dynamic SQL query syntax without proper sanitization or parameterization. This allows an…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:24 p.m.

5.3

CVSS3.1

CVE-2025-52023 -

A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST requests are sent to public API…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:24 p.m.

7.8

CVSS3.1

CVE-2026-20613 -

The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an archive member. This means that a carelessly or maliciously constructed archive can extract a file into any user-writable location on the system using r…

πŸ“… Published: Jan. 22, 2026, 11:58 p.m. πŸ”„ Last Modified: Jan. 27, 2026, 8:17 p.m.

7.7

CVSS4.0

CVE-2026-24132 - Orval Mock Generation Code Injection via const

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19.0 and below and 8.0.0-rc.0 through 8.0.2 allow untrusted OpenAPI specifications to inject arbitrary TypeScript/JavaScript into generated mock files via the const keyword on schema…

πŸ“… Published: Jan. 22, 2026, 11:47 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 7 p.m.

6

CVSS4.0

CVE-2025-9290 - Authentication Weakness on Omada Controllers, Gateways and Access Points

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication th…

πŸ“… Published: Jan. 22, 2026, 11:14 p.m. πŸ”„ Last Modified: March 16, 2026, 6:07 p.m.

2.7

CVSS4.0

CVE-2026-24130 - Moonraker with LDAP Enabled Allows Malicious Search Filter Injection

Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, instances configured with the "ldap" component enabled are vulnerable to LDAP search filter injection techniques via the login endpoint. The 401 error response message can be used to …

πŸ“… Published: Jan. 22, 2026, 10:53 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 1:57 p.m.

9.3

CVSS3.1

CVE-2026-21264 - Microsoft Account Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.

πŸ“… Published: Jan. 22, 2026, 10:47 p.m. πŸ”„ Last Modified: April 1, 2026, 1:49 p.m.
Total resulsts: 343921
Page 1465 of 34,393
Β« previous page Β» next page
Filters