7.3

CVSS4.0

CVE-2025-23013 -

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue…

πŸ“… Published: Jan. 15, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-22976 -

SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering the content correctly at the "checkOrder.php" shopId module.

πŸ“… Published: Jan. 15, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-36476 - RDMA/rtrs: Ensure 'ib_sge list' is accessible

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Ensure 'ib_sge list' is accessible Move the declaration of the 'ib_sge list' variable outside the 'always_invalidate' block to ensure it remains accessible for use throughout the function. Previously, 'ib_sge list' wa…

πŸ“… Published: Jan. 15, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:16 p.m.

5.5

CVSS3.1

CVE-2024-57884 - mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim()

In the Linux kernel, the following vulnerability has been resolved: mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim() The task sometimes continues looping in throttle_direct_reclaim() because allow_direct_reclaim(pgdat) keeps returning false. #0 [ffff800…

πŸ“… Published: Jan. 15, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:18 p.m.

5.5

CVSS3.1

CVE-2024-57882 - mptcp: fix TCP options overflow.

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix TCP options overflow. Syzbot reported the following splat: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI KASAN: null-ptr-deref in range [0x00000…

πŸ“… Published: Jan. 15, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:18 p.m.

9.8

CVSS3.1

CVE-2024-48126 -

HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access.

πŸ“… Published: Jan. 15, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-57896 - btrfs: flush delalloc workers queue before stopping cleaner kthread during unmount

In the Linux kernel, the following vulnerability has been resolved: btrfs: flush delalloc workers queue before stopping cleaner kthread during unmount During the unmount path, at close_ctree(), we first stop the cleaner kthread, using kthread_stop() which frees the associated task_struct, and the…

πŸ“… Published: Jan. 15, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:56 a.m.

9.8

CVSS3.1

CVE-2025-22968 -

An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions

πŸ“… Published: Jan. 15, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 4:21 p.m.

8.1

CVSS3.1

CVE-2025-22964 -

DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries by directly incorporating user-supplied inp…

πŸ“… Published: Jan. 15, 2025, midnight πŸ”„ Last Modified: Oct. 3, 2025, 12:53 p.m.

6.5

CVSS3.1

CVE-2024-36751 -

An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL.

πŸ“… Published: Jan. 15, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346514
Page 6843 of 34,652
Β« previous page Β» next page
Filters