Aggregator
The Gentleman
4 months ago
You must login to view this content
cohenido
CVE-2025-68725 | Linux Kernel up to 6.18.1 skb_warn_bad_offload privilege escalation (Nessus ID 279716 / WID-SEC-2025-2920)
4 months ago
A vulnerability has been found in Linux Kernel up to 6.18.1 and classified as problematic. The affected element is the function skb_warn_bad_offload. The manipulation leads to privilege escalation.
This vulnerability is documented as CVE-2025-68725. The attack requires being on the local network. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-68365 | Linux Kernel up to 6.18.1 ntfs3 __getname uninitialized pointer (Nessus ID 279758 / WID-SEC-2025-2920)
4 months ago
A vulnerability was found in Linux Kernel up to 6.18.1 and classified as critical. This affects the function __getname of the component ntfs3. Executing a manipulation can lead to uninitialized pointer.
This vulnerability is registered as CVE-2025-68365. The attack requires access to the local network. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2023-54207 | Linux Kernel up to 6.1.52/6.4.15/6.5.2 HID use after free (Nessus ID 298924 / WID-SEC-2025-2941)
4 months ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.52/6.4.15/6.5.2. Affected by this issue is some unknown functionality of the component HID. Such manipulation leads to use after free.
This vulnerability is documented as CVE-2023-54207. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-71089 | Linux Kernel up to 6.6.119/6.12.63/6.18.3 IOMMU Driver use after free (Nessus ID 298928)
4 months ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.6.119/6.12.63/6.18.3. The affected element is an unknown function of the component IOMMU Driver. The manipulation results in use after free.
This vulnerability was named CVE-2025-71089. The attack needs to be approached within the local network. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-68817 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 ksmbd ksmbd_tree_connect_put use after free (Nessus ID 298659)
4 months ago
A vulnerability was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. It has been classified as critical. Impacted is the function ksmbd_tree_connect_put of the component ksmbd. Performing a manipulation results in use after free.
This vulnerability was named CVE-2025-68817. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-71144 | Linux Kernel up to 6.6.119/6.12.64/6.18.4/6.19-rc3 net/mptcp/subflow.c mptcp_disconnect state issue (WID-SEC-2026-0119)
4 months ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.6.119/6.12.64/6.18.4/6.19-rc3. The impacted element is the function mptcp_disconnect of the file net/mptcp/subflow.c. This manipulation causes state issue.
This vulnerability is registered as CVE-2025-71144. The attack requires access to the local network. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-68823 | Linux Kernel up to 6.18.2/6.19-rc1 bdev_open file descriptor consumption (Nessus ID 283661)
4 months ago
A vulnerability was found in Linux Kernel up to 6.18.2/6.19-rc1. It has been declared as critical. The affected element is the function bdev_open. Executing a manipulation can lead to uncontrolled file descriptor consumption.
The identification of this vulnerability is CVE-2025-68823. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-68749 | Linux Kernel up to 6.17.12/6.18.1 ivpu ivpu_gem_bo_free race condition (Nessus ID 279749 / WID-SEC-2025-2929)
4 months ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.17.12/6.18.1. This affects the function ivpu_gem_bo_free of the component ivpu. The manipulation results in race condition.
This vulnerability is known as CVE-2025-68749. Access to the local network is required for this attack. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2023-54285 | Linux Kernel up to 6.5.4 iomap folio_next_index buffer overflow (Nessus ID 298404 / WID-SEC-2025-2941)
4 months ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.5.4. This vulnerability affects the function folio_next_index of the component iomap. Executing a manipulation can lead to buffer overflow.
This vulnerability is handled as CVE-2023-54285. The attack can only be done within the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2023-54321 | Linux Kernel up to 5.15.98/6.1.15/6.2.2 device_add null pointer dereference (Nessus ID 280731 / WID-SEC-2025-2941)
4 months ago
A vulnerability described as critical has been identified in Linux Kernel up to 5.15.98/6.1.15/6.2.2. This affects the function device_add. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2023-54321. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-68358 | Linux Kernel up to 6.17.12/6.18.1 btrfs_clear_space_info_full allocation of resources (Nessus ID 279768 / WID-SEC-2025-2920)
4 months ago
A vulnerability was found in Linux Kernel up to 6.17.12/6.18.1. It has been declared as critical. Affected by this vulnerability is the function btrfs_clear_space_info_full. Such manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2025-68358. The attack can only be initiated within the local network. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-43281 | Apple macOS up to 15.5 improper authentication (EUVD-2025-34695)
4 months ago
A vulnerability was found in Apple macOS up to 15.5. It has been declared as critical. This affects an unknown function. Such manipulation leads to improper authentication.
This vulnerability is traded as CVE-2025-43281. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
「好用又便宜」的 Nano Banana 2 来了,这次能改变你的出图工作流吗?
4 months ago
比起模型本身的升级,这次更像一次「产品化收口」。
Drupal security advisory (AV26-175)
4 months ago
Canadian Centre for Cyber Security
CVE-2026-3293 | snowflakedb snowflake-jdbc up to 4.0.1 JDBC URL SdkProxyRoutePlanner.java SdkProxyRoutePlanner nonProxyHosts redos (Issue 2505)
4 months ago
A vulnerability categorized as problematic has been discovered in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net/snowflake/client/internal/core/SdkProxyRoutePlanner.java of the component JDBC URL Handler. Executing a manipulation of the argument nonProxyHosts can lead to inefficient regular expression complexity.
The identification of this vulnerability is CVE-2026-3293. The attack can only be executed locally. Furthermore, there is an exploit available.
A patch should be applied to remediate this issue.
vuldb.com
New Zealand Police Dismantle Dark Web Drug Syndicate in Operation Solana
4 months ago
New Zealand Police Dismantle Dark Web Drug Syndicate in Operation Solana
Dark Web Informer
Preventing Breaches – MFA on Remote Access to Linux, Unix, and Infrastructure Systems
4 months ago
Most breaches don’t start with malware or zero-day exploits. They start with a login. An attacker gets hold of a password, maybe through phishing, reuse, or a leaked credential dump. They test it against a remote system. An SSH prompt appears. The credentials work. From there, everything unfolds quietly – privilege escalation, lateral movement, persistence. By the time anyone notices, the damage is already done. […]
The post Preventing Breaches – MFA on Remote Access to Linux, Unix, and Infrastructure Systems appeared first on 12Port.
The post Preventing Breaches – MFA on Remote Access to Linux, Unix, and Infrastructure Systems appeared first on Security Boulevard.
Peter Senescu
CVE-2025-12981 | Listee Plugin up to 1.1.6 on WordPress user_role Remote Code Execution
4 months ago
A vulnerability was found in Listee Plugin up to 1.1.6 on WordPress. It has been rated as critical. This issue affects some unknown processing. Performing a manipulation of the argument user_role results in Remote Code Execution.
This vulnerability was named CVE-2025-12981. The attack may be initiated remotely. There is no available exploit.
vuldb.com