7.5

CVSS3.1

CVE-2025-70954 -

A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025.06. The issue is located in the execution logic of the INMSGPARAM instruction, where the program fails to validate if a specific pointer is null before accessing it. By sending a …

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-70955 -

A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10. The vulnerability stems from the improper handling of vmstate and continuation jump instructions, which allow for continuous dynamic tail calls. An attacker can exploit this by crafting a smart contract …

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-70122 -

A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. The issue occurs in the SDFFilterFields.UnmarshalBinary function (sdf-filter.go) when processing a declared length that e…

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: Feb. 18, 2026, 3:40 p.m.

7.5

CVSS3.1

CVE-2025-70121 -

An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted 5GS Mobile Identity in a NAS Registration Request message. The issue occurs in the GetSUCI method (NAS_MobileIdentity5GS.go) when accessing index 5 of…

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: Feb. 18, 2026, 3:45 p.m.

6.5

CVSS3.1

CVE-2025-70095 -

A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: Feb. 17, 2026, 2:59 p.m.

6.2

CVSS3.1

CVE-2025-66676 -

An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 9:36 p.m.

6.5

CVSS3.1

CVE-2025-70094 -

A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category parameter.

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: Feb. 17, 2026, 2:59 p.m.

7.5

CVSS3.1

CVE-2025-70123 -

An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts a malformed PFCP Association Setup Request, violating 3GPP TS 29.244. This places the UPF in an inconsistent state where a subsequen…

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: Feb. 18, 2026, 3:40 p.m.

9.8

CVSS3.1

CVE-2026-23112 - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg->length/offset values, leading to _copy_to_iter() …

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: May 4, 2026, 7:51 a.m.

7.8

CVSS3.1

CVE-2026-23111 - netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-catchall counterpart nft_mapelem_activate() and compared to wh…

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 8:45 p.m.
Total resulsts: 348551
Page 1587 of 34,856
Β« previous page Β» next page
Filters