Aggregator
CVE-2025-40258 | Linux Kernel up to 6.6.117/6.12.59/6.17.9 mptcp lib/refcount.c mptcp_schedule_work use after free
1 month 2 weeks ago
A vulnerability has been found in Linux Kernel up to 6.6.117/6.12.59/6.17.9 and classified as critical. Affected by this vulnerability is the function mptcp_schedule_work in the library lib/refcount.c of the component mptcp. Performing manipulation results in use after free.
This vulnerability was named CVE-2025-40258. The attack needs to be approached within the local network. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2025-40255 | Linux Kernel up to 6.17.9 generic_hwtstamp_ioctl_lower null pointer dereference
1 month 2 weeks ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.17.9. Affected is the function generic_hwtstamp_ioctl_lower. Such manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2025-40255. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2025-40264 | Linux Kernel up to 5.4.301/6.6.117/6.12.59/6.17.9 be_insert_vlan_in_pkt wrb_params null pointer dereference
1 month 2 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.4.301/6.6.117/6.12.59/6.17.9. This impacts the function be_insert_vlan_in_pkt. This manipulation of the argument wrb_params causes null pointer dereference.
This vulnerability is handled as CVE-2025-40264. The attack can only be done within the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-40261 | Linux Kernel up to 6.6.117/6.12.59/6.17.9 nvme_fc_delete_ctrl information disclosure
1 month 2 weeks ago
A vulnerability classified as critical was found in Linux Kernel up to 6.6.117/6.12.59/6.17.9. This affects the function nvme_fc_delete_ctrl. The manipulation results in information disclosure.
This vulnerability is known as CVE-2025-40261. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-40256 | Linux Kernel up to 6.17.9 xfrm_state_delete_tunnel initialization
1 month 2 weeks ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.17.9. The impacted element is the function xfrm_state_delete_tunnel. The manipulation leads to improper initialization.
This vulnerability is traded as CVE-2025-40256. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26810 | Linux Kernel up to 6.1.83/6.6.23/6.7.11/6.8.2 is_intx privilege escalation (Nessus ID 209060 / WID-SEC-2025-1293)
1 month 2 weeks ago
A vulnerability was found in Linux Kernel up to 6.1.83/6.6.23/6.7.11/6.8.2. It has been rated as problematic. This issue affects the function is_intx. This manipulation causes privilege escalation.
This vulnerability appears as CVE-2024-26810. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-26646 | Linux Kernel up to 6.1.75/6.6.14/6.7.2 thermal memory corruption (Nessus ID 210815 / WID-SEC-2025-1293)
1 month 2 weeks ago
A vulnerability classified as critical was found in Linux Kernel up to 6.1.75/6.6.14/6.7.2. Affected is an unknown function of the component thermal. The manipulation results in memory corruption.
This vulnerability was named CVE-2024-26646. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-26668 | Linux Kernel up to 5.15.148/6.1.75/6.6.14/6.7.2 nft_limit integer overflow (Nessus ID 207884 / WID-SEC-2025-1293)
1 month 2 weeks ago
A vulnerability classified as problematic was found in Linux Kernel up to 5.15.148/6.1.75/6.6.14/6.7.2. Affected is an unknown function of the component nft_limit. The manipulation results in integer overflow.
This vulnerability is reported as CVE-2024-26668. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-26669 | Linux Kernel up to 6.6.14/6.7.2 tcf_block_offload_unbind memory leak (9ed46144cff3/c04709b2cc99/32f2a0afa95f / Nessus ID 207884)
1 month 2 weeks ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.6.14/6.7.2. This issue affects the function tcf_block_offload_unbind. The manipulation results in memory leak.
This vulnerability is identified as CVE-2024-26669. The attack can only be performed from the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2024-26641 | Linux Kernel up to 5.10.209/5.15.148/6.1.76/6.6.15/6.7.3 ip6_tunnel include/net/inet_ecn.h __ip6_tnl_rcv initialization (Nessus ID 209060 / WID-SEC-2025-1293)
1 month 2 weeks ago
A vulnerability has been found in Linux Kernel up to 5.10.209/5.15.148/6.1.76/6.6.15/6.7.3 and classified as problematic. Affected is the function __ip6_tnl_rcv in the library include/net/inet_ecn.h of the component ip6_tunnel. This manipulation causes improper initialization.
This vulnerability appears as CVE-2024-26641. The attacker needs to be present on the local network. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2025-54305 | Thermo Fisher Torrent Suite Django Application 5.18.1 LocalhostAuthMiddleware REMOTE_ADDR improper authentication
1 month 2 weeks ago
A vulnerability described as critical has been identified in Thermo Fisher Torrent Suite Django Application 5.18.1. The affected element is an unknown function of the component LocalhostAuthMiddleware. Executing manipulation of the argument REMOTE_ADDR can lead to improper authentication.
This vulnerability appears as CVE-2025-54305. The attack requires local access. There is no available exploit.
vuldb.com
CVE-2025-61148 | EduplusCampus 3.0.1 Student Payment API /student/get-receipt rec_no resource injection
1 month 2 weeks ago
A vulnerability marked as critical has been reported in EduplusCampus 3.0.1. Impacted is an unknown function of the file /student/get-receipt of the component Student Payment API. Performing manipulation of the argument rec_no results in improper control of resource identifiers.
This vulnerability is reported as CVE-2025-61148. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-63681 | open-webui 0.6.33 /api/tasks/stop/ access control
1 month 2 weeks ago
A vulnerability labeled as critical has been found in open-webui 0.6.33. This issue affects some unknown processing of the file /api/tasks/stop/. Such manipulation leads to improper access controls.
This vulnerability is documented as CVE-2025-63681. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2025-66516 | Apache Tika Core/Tika Parsers/Tika PDF Parser Module XFA File Parser xml external entity reference
1 month 2 weeks ago
A vulnerability identified as problematic has been detected in Apache Tika Core, Tika Parsers and Tika PDF Parser Module. This vulnerability affects unknown code of the component XFA File Parser. This manipulation causes xml external entity reference.
This vulnerability is registered as CVE-2025-66516. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2025-54303 | Thermo Fisher Torrent Suite Django Application 5.18.1 Django ORM API default credentials
1 month 2 weeks ago
A vulnerability categorized as problematic has been discovered in Thermo Fisher Torrent Suite Django Application 5.18.1. This affects an unknown part of the component Django ORM API. The manipulation results in use of default credentials.
This vulnerability is cataloged as CVE-2025-54303. The attack must originate from the local network. There is no exploit available.
vuldb.com
CVE-2025-40217 | Linux Kernel up to 6.17.3 pidfs privilege escalation
1 month 2 weeks ago
A vulnerability was found in Linux Kernel up to 6.17.3. It has been rated as critical. Affected by this issue is some unknown functionality of the component pidfs. The manipulation leads to privilege escalation.
This vulnerability is listed as CVE-2025-40217. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-40246 | Linux Kernel up to 6.12.59/6.17.9 xfs min out-of-bounds
1 month 2 weeks ago
A vulnerability was found in Linux Kernel up to 6.12.59/6.17.9. It has been declared as critical. Affected by this vulnerability is the function min of the component xfs. Executing manipulation can lead to out-of-bounds read.
This vulnerability is tracked as CVE-2025-40246. The attack is only possible within the local network. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-40254 | Linux Kernel up to 5.4.301/6.6.117/6.12.59/6.17.9 nsh_key_put_from_nlattr null pointer dereference
1 month 2 weeks ago
A vulnerability was found in Linux Kernel up to 5.4.301/6.6.117/6.12.59/6.17.9. It has been classified as critical. Affected is the function nsh_key_put_from_nlattr. Performing manipulation results in null pointer dereference.
This vulnerability is identified as CVE-2025-40254. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-40253 | Linux Kernel up to 5.4.301/6.6.117/6.12.59/6.17.9 s390 ctcmpc_unpack_skb double free
1 month 2 weeks ago
A vulnerability was found in Linux Kernel up to 5.4.301/6.6.117/6.12.59/6.17.9 and classified as critical. This impacts the function ctcmpc_unpack_skb of the component s390. Such manipulation leads to double free.
This vulnerability is referenced as CVE-2025-40253. The attack needs to be initiated within the local network. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com