5.3

CVSS3.1

CVE-2025-15525 - Ajax Load More – Infinite Scroll, Lazy Load & Load More <= 7.8.1 - Incorrect Authorization to Unaut…

The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for unauthenticated attackers to expo…

📅 Published: Jan. 31, 2026, 4:35 a.m. 🔄 Last Modified: April 21, 2026, 12:30 a.m.

5.3

CVSS3.1

CVE-2026-1431 - Booking Calendar <= 10.14.13 - Missing Authorization to Unauthenticated Booking Details Exposure

The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpbc_ajax_WPBC_FLEXTIMELINE_NAV() function in all versions up to, and including, 10.14.13. This makes it possible for unauthenticated attackers to retrieve booking informa…

📅 Published: Jan. 31, 2026, 4:35 a.m. 🔄 Last Modified: April 16, 2026, 1:30 a.m.

5.3

CVSS3.1

CVE-2025-15510 - NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated…

The NEX-Forms – Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the NF5_Export_Forms class constructor in all versions up to, and including, 9.1.8. This makes it possible for unauthenticated attackers to export form configuration…

📅 Published: Jan. 31, 2026, 1:23 a.m. 🔄 Last Modified: April 20, 2026, 9 p.m.

5.5

CVSS3.1

CVE-2026-23015 - gpio: mpsse: fix reference leak in gpio_mpsse_probe() error paths

In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: fix reference leak in gpio_mpsse_probe() error paths The reference obtained by calling usb_get_dev() is not released in the gpio_mpsse_probe() error paths. Fix that by using device managed helper functions. Also remo…

📅 Published: Jan. 31, 2026, midnight 🔄 Last Modified: April 18, 2026, 2:30 p.m.

0.0

CVE-2026-23030 - phy: rockchip: inno-usb2: Fix a double free bug in rockchip_usb2phy_probe()

In the Linux kernel, the following vulnerability has been resolved: phy: rockchip: inno-usb2: Fix a double free bug in rockchip_usb2phy_probe() The for_each_available_child_of_node() calls of_node_put() to release child_np in each success loop. After breaking from the loop with the child_np has b…

📅 Published: Jan. 31, 2026, midnight 🔄 Last Modified: April 18, 2026, 8 p.m.

5.5

CVSS3.1

CVE-2026-23023 - idpf: fix memory leak in idpf_vport_rel()

In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leak in idpf_vport_rel() Free vport->rx_ptype_lkup in idpf_vport_rel() to avoid leaking memory during a reset. Reported by kmemleak: unreferenced object 0xff450acac838a000 (size 4096): comm "kworker/u258:5", p…

📅 Published: Jan. 31, 2026, midnight 🔄 Last Modified: April 18, 2026, 1 a.m.

0.0

CVE-2026-23037 - can: etas_es58x: allow partial RX URB allocation to succeed

In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: allow partial RX URB allocation to succeed When es58x_alloc_rx_urbs() fails to allocate the requested number of URBs but succeeds in allocating some, it returns an error code. This causes es58x_open() to return e…

📅 Published: Jan. 31, 2026, midnight 🔄 Last Modified: April 18, 2026, 2:30 p.m.

5.5

CVSS3.1

CVE-2026-23017 - idpf: fix error handling in the init_task on load

In the Linux kernel, the following vulnerability has been resolved: idpf: fix error handling in the init_task on load If the init_task fails during a driver load, we end up without vports and netdevs, effectively failing the entire process. In that state a subsequent reset will result in a crash …

📅 Published: Jan. 31, 2026, midnight 🔄 Last Modified: April 18, 2026, 1 a.m.

5.5

CVSS3.1

CVE-2025-71181 - rust_binder: remove spin_lock() in rust_shrink_free_page()

In the Linux kernel, the following vulnerability has been resolved: rust_binder: remove spin_lock() in rust_shrink_free_page() When forward-porting Rust Binder to 6.18, I neglected to take commit fb56fdf8b9a2 ("mm/list_lru: split the lock to per-cgroup scope") into account, and apparently I did n…

📅 Published: Jan. 31, 2026, midnight 🔄 Last Modified: March 25, 2026, 7:43 p.m.

5.5

CVSS3.1

CVE-2025-71180 - counter: interrupt-cnt: Drop IRQF_NO_THREAD flag

In the Linux kernel, the following vulnerability has been resolved: counter: interrupt-cnt: Drop IRQF_NO_THREAD flag An IRQ handler can either be IRQF_NO_THREAD or acquire spinlock_t, as CONFIG_PROVE_RAW_LOCK_NESTING warns: ============================= [ BUG: Invalid wait context ] 6.18.0-rc1+gi…

📅 Published: Jan. 31, 2026, midnight 🔄 Last Modified: March 25, 2026, 7:45 p.m.
Total resulsts: 349182
Page 1872 of 34,919
« previous page » next page
Filters