7.8

CVSS3.1

CVE-2025-37810 - usb: dwc3: gadget: check that event count does not exceed event buffer length

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: check that event count does not exceed event buffer length The event count is read from register DWC3_GEVNTCOUNT. There is a check for the count being zero, but not for exceeding the event buffer length. Check โ€ฆ

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 12, 2025, 9:40 p.m.

5.5

CVSS3.1

CVE-2025-37808 - crypto: null - Use spin lock instead of mutex

In the Linux kernel, the following vulnerability has been resolved: crypto: null - Use spin lock instead of mutex As the null algorithm may be freed in softirq context through af_alg, use spin locks instead of mutexes to protect the default null algorithm.

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 10, 2025, 5:31 p.m.

5.5

CVSS3.1

CVE-2025-37800 - driver core: fix potential NULL pointer dereference in dev_uevent()

In the Linux kernel, the following vulnerability has been resolved: driver core: fix potential NULL pointer dereference in dev_uevent() If userspace reads "uevent" device attribute at the same time as another threads unbinds the device from its driver, change to dev->driver from a valid pointer tโ€ฆ

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 3:29 p.m.

9.8

CVSS3.1

CVE-2025-26844 -

An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: June 12, 2025, 4:47 p.m.

5.5

CVSS3.1

CVE-2025-37828 - scsi: ufs: mcq: Add NULL check in ufshcd_mcq_abort()

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: mcq: Add NULL check in ufshcd_mcq_abort() A race can occur between the MCQ completion path and the abort handler: once a request completes, __blk_mq_free_request() sets rq->mq_hctx to NULL, meaning the subsequent ufshcโ€ฆ

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 14, 2025, 7:44 p.m.

5.5

CVSS3.1

CVE-2025-37805 - sound/virtio: Fix cancel_sync warnings on uninitialized work_structs

In the Linux kernel, the following vulnerability has been resolved: sound/virtio: Fix cancel_sync warnings on uninitialized work_structs Betty reported hitting the following warning: [ 8.709131][ T221] WARNING: CPU: 2 PID: 221 at kernel/workqueue.c:4182 ... [ 8.713282][ T221] Call trace:โ€ฆ

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

6.1

CVSS3.1

CVE-2025-28073 -

phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker can inject arbitrary JavaScript code by manipulating the id parameter, which is improperly sanitized.

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: June 16, 2025, 6:39 p.m.

8.8

CVSS3.1

CVE-2025-45843 -

TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: May 16, 2025, 3:39 p.m.

8.8

CVSS3.1

CVE-2025-45844 -

TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicCfg function.

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: May 16, 2025, 3:39 p.m.

6.5

CVSS3.1

CVE-2025-44023 -

An issue in dlink DNS-320 v.1.00 and DNS-320LW v.1.01.0914.20212 allows an attacker to execute arbitrary via the account_mgr.cgi->cgi_chg_admin_pw components.

๐Ÿ“… Published: May 8, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347806
Page 5359 of 34,781
ยซ previous page ยป next page
Filters