5.5

CVSS3.1

CVE-2025-71237 - nilfs2: Fix potential block overflow that cause system hang

In the Linux kernel, the following vulnerability has been resolved: nilfs2: Fix potential block overflow that cause system hang When a user executes the FITRIM command, an underflow can occur when calculating nblocks if end_block is too small. Since nblocks is of type sector_t, which is u64, a ne…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 9 p.m.

5.5

CVSS3.1

CVE-2025-71235 - scsi: qla2xxx: Delay module unload while fabric scan in progress

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Delay module unload while fabric scan in progress System crash seen during load/unload test in a loop. [105954.384919] RBP: ffff914589838dc0 R08: 0000000000000000 R09: 0000000000000086 [105954.384920] R10: 0000000…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 9 p.m.

5.5

CVSS3.1

CVE-2025-71233 - PCI: endpoint: Avoid creating sub-groups asynchronously

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Avoid creating sub-groups asynchronously The asynchronous creation of sub-groups by a delayed work could lead to a NULL pointer dereference when the driver directory is removed before the work completes. The crash…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 5:30 p.m.

5.5

CVSS3.1

CVE-2025-71227 - wifi: mac80211: don't WARN for connections on invalid channels

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't WARN for connections on invalid channels It's not clear (to me) how exactly syzbot managed to hit this, but it seems conceivable that e.g. regulatory changed and has disabled a channel between scanning (chan…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: March 18, 2026, 8:40 p.m.

7.5

CVSS3.1

CVE-2025-70148 -

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 20, 2026, 1:55 p.m.

9.4

CVSS3.1

CVE-2025-70141 -

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 3:44 p.m.

8.8

CVSS3.1

CVE-2025-70064 -

PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after authentication. This…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 9:03 p.m.

6.5

CVSS3.1

CVE-2025-70063 -

The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewid' parameter belongs to the currently authenticated patient. This allows a user to access the confid…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 10:33 p.m.

8.8

CVSS3.1

CVE-2026-2648 - chromium-browser: Heap buffer overflow in PDFium

Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file. (Chromium security severity: High)

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 6:30 p.m.

8.8

CVSS3.1

CVE-2026-23230 - smb: client: split cached_fid bitfields to avoid shared-byte RMW races

In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid shared-byte RMW races is_open, has_lease and on_list are stored in the same bitfield byte in struct cached_fid but are updated in different code paths that may run concurrently. Bi…

πŸ“… Published: Feb. 18, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 5:15 p.m.
Total resulsts: 349182
Page 1602 of 34,919
Β« previous page Β» next page
Filters