5.5

CVSS3.1

CVE-2026-23220 - ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths The problem occurs when a signed request fails smb2 signature verification check. In __process_request(), if check_sign_req() returns an error, set_smb…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

5.5

CVSS3.1

CVE-2025-71232 - scsi: qla2xxx: Free sp in error path to fix system crash

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Free sp in error path to fix system crash System crash seen during load/unload test in a loop, [61110.449331] qla2xxx [0000:27:00.0]-0042:0: Disabled MSI-X. [61110.467494] =========================================…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 5:30 p.m.

6.5

CVSS3.1

CVE-2025-65519 -

mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and XML file import processing. The application fails to validate nesting depth during parsing operations, allowing authenticated attackers to trigger denial of service conditions by uploading deeply nested m…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 20, 2026, 8:08 p.m.

9.8

CVSS3.1

CVE-2025-70150 -

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 4:13 p.m.

7.5

CVSS3.1

CVE-2025-70147 -

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session.

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 20, 2026, 8:07 p.m.

8.8

CVSS3.1

CVE-2026-23226 - ksmbd: add chann_lock to protect ksmbd_chann_list xarray

In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list xarray ksmbd_chann_list xarray lacks synchronization, allowing use-after-free in multi-channel sessions (between lookup_chann_list() and ksmbd_chann_del). Adds rw_semaphore chann…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 5:30 p.m.

7.8

CVSS3.1

CVE-2026-23222 - crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly

In the Linux kernel, the following vulnerability has been resolved: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly The existing allocation of scatterlists in omap_crypto_copy_sg_lists() was allocating an array of scatterlist pointers, not scatterlist objects, resulting in a…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 6:15 p.m.

5.5

CVSS3.1

CVE-2026-23215 - x86/vmware: Fix hypercall clobbers

In the Linux kernel, the following vulnerability has been resolved: x86/vmware: Fix hypercall clobbers Fedora QA reported the following panic: BUG: unable to handle page fault for address: 0000000040003e54 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not-present pa…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: April 18, 2026, noon

9.8

CVSS3.1

CVE-2025-70152 -

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname,…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 5:54 p.m.

7.8

CVSS3.1

CVE-2026-23225 - sched/mmcid: Don't assume CID is CPU owned on mode switch

In the Linux kernel, the following vulnerability has been resolved: sched/mmcid: Don't assume CID is CPU owned on mode switch Shinichiro reported a KASAN UAF, which is actually an out of bounds access in the MMCID management code. CPU0 CPU1 T1 runs in userspace T0: fork(T4) -…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 5:30 p.m.
Total resulsts: 349182
Page 1600 of 34,919
Β« previous page Β» next page
Filters