Currently trending CVE - Hype Score: 2 - A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
Currently trending CVE - Hype Score: 3 - A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges.
This issue requires administrative ...
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.18.3. This affects the function gmap_helper_zap_one_page of the component KVM. This manipulation causes memory corruption.
This vulnerability appears as CVE-2025-71155. The attacker needs to be present on the local network. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.18.5. It has been classified as critical. Affected by this issue is some unknown functionality of the component gpio. Performing a manipulation results in denial of service.
This vulnerability is known as CVE-2025-71158. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Linux Kernel up to 6.6.119/6.12.63/6.18.2/6.19-rc2. Affected by this vulnerability is the function smb3_reconfigure of the component cifs. The manipulation leads to memory leak.
This vulnerability is documented as CVE-2025-71151. The attack requires being on the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.3/6.19-rc3. This vulnerability affects the function of_find_net_device_by_node of the component Conduit Driver. Such manipulation leads to improper update of reference count.
This vulnerability is traded as CVE-2025-71152. Access to the local network is required for this attack to succeed. There is no exploit available.
You should upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc1. Affected by this issue is some unknown functionality of the component ksmbd. The manipulation results in improper update of reference count.
This vulnerability is reported as CVE-2025-71150. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is advised.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.6.119/6.12.63/6.18.3/6.19-rc3. This impacts the function get_file_all_info of the component ksmbd. Performing a manipulation results in memory leak.
This vulnerability is cataloged as CVE-2025-71153. The attack must originate from the local network. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.19-rc3. It has been rated as critical. Impacted is the function usb_submit_urb. The manipulation leads to memory leak.
This vulnerability is referenced as CVE-2025-71154. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in Linux Kernel up to 6.18.5/6.19-rc4 and classified as critical. Affected by this vulnerability is the function btrfs_get_or_create_delayed_node. Such manipulation leads to use after free.
This vulnerability is traded as CVE-2025-71159. Access to the local network is required for this attack to succeed. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.63/6.18.3/6.19-rc3. This affects the function ib_del_sub_device_and_put of the component RDMA. The manipulation leads to improper update of reference count.
This vulnerability is documented as CVE-2025-71157. The attack requires being on the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.12.63/6.18.3/6.19-rc3. This affects the function __napi_poll of the component gve. The manipulation leads to improper initialization.
This vulnerability is referenced as CVE-2025-71156. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
A vulnerability classified as critical was found in Supermicro MBD-X13SEM-F 01.05.02. This affects an unknown function of the component Image Handler. Such manipulation leads to improper verification of cryptographic signature.
This vulnerability is listed as CVE-2025-12007. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in Altium AES up to 7.0.5 and classified as critical. This vulnerability affects unknown code. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2025-27378. It is possible to launch the attack remotely. No exploit is available.
A vulnerability marked as problematic has been reported in Altium AES up to 7.0.5. Affected is an unknown function of the component BOM Viewer. Performing a manipulation of the argument Description results in cross site scripting.
This vulnerability is reported as CVE-2025-27379. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability categorized as critical has been discovered in dragonflyoss dragonfly up to 2.4.0. Impacted is an unknown function of the file /api/v1/jobs of the component Job API Endpoint. Executing a manipulation can lead to missing authentication.
This vulnerability is registered as CVE-2026-24124. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical has been found in Runtipi up to 4.6.x. This affects an unknown part of the component BackupManager. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2026-24129. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.19-rc4. Affected is the function qdisc_get. The manipulation leads to null pointer dereference.
This vulnerability is listed as CVE-2026-22976. The attack must be carried out from within the local network. There is no available exploit.
It is suggested to upgrade the affected component.