CVE-2025-38480 – Comedi Uninitialized Data Exposure Vulnerability
In the Linux kernel, the following vulnerability has been resolved: comedi: Fix use of uninitialized data in insn_rw_emulate_bits() For Comedi `INSN_READ` and `INSN_WRITE` instructions on “digital” subdevices (subdevice types `COMEDI_SUBD_DI`, `COMEDI_SUBD_DO`, and `COMEDI_SUBD_DIO`), it is common for the subdevice driver not to have `insn_read` and `insn_write` handler functions, but to have an `insn_bits` handler function […]
CVE-2025-38478 – Linux Comedi Uninitialized Data Access Vulnerability
In the Linux kernel, the following vulnerability has been resolved: comedi: Fix initialization of data for instructions that write to subdevice Some Comedi subdevice instruction handlers are known to access instruction data elements beyond the first `insn->n` elements in some cases. The `do_insn_ioctl()` and `do_insnlist_ioctl()` functions allocate at least `MIN_SAMPLES` (16) data elements to deal […]
CVE-2025-38477 – Linux Kernel sch_qfq Race Condition Vulnerability
The following table lists the changes that have been made to the CVE-2025-38477 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Jul. 28, 2025 Action […]
CVE-2025-38476 – Linux kernel RPL Use-after-free Vulnerability
The following table lists the changes that have been made to the CVE-2025-38476 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Jul. 28, 2025 Action […]
CVE-2025-38474 – Sierra USB Net Interrupt Input Endpoint Validation Vulnerability
The following table lists the changes that have been made to the CVE-2025-38474 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Jul. 28, 2025 Action […]
CVE-2025-38475 – Android Linux SMC Socket Type Confusion Vulnerability
In the Linux kernel, the following vulnerability has been resolved: smc: Fix various oops due to inet_sock type confusion. syzbot reported weird splats [0][1] in cipso_v4_sock_setattr() while freeing inet_sk(sk)->inet_opt. The address was freed multiple times even though it was read-only memory. cipso_v4_sock_setattr() did nothing wrong, and the root cause was type confusion. The cited commit […]
CVE-2025-6918 – Ncvav Virtual PBX Software SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-6918 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 28, 2025 Action […]
Microsoft SharePoint Zero-Day
Microsoft SharePoint Zero-Day Chinese hackers are exploiting a high-severity vulnerability in Microsoft SharePoint to steal data worldwide: The vulnerability, tracked as CVE-2025-53770, carries a severity rating of 9.8 out of a po … Read more Published Date: Jul 28, 2025 (1 hour, 5 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-53770 CVE-2025-49706 CVE-2025-49704
New “ToolShell” Exploit Chain Attacking SharePoint Servers to Gain Complete Control
New “ToolShell” Exploit Chain Attacking SharePoint Servers to Gain Complete Control A critical new threat targeting Microsoft SharePoint servers through a sophisticated exploit chain dubbed “ToolShell.” This multi-stage attack combines previously patched vulnerabilities with fresh ze … Read more Published Date: Jul 28, 2025 (1 hour, 39 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-53771 […]
CVE-2025-8271 – Code-projects Exam Form Submission SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-8271 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 28, 2025 Action […]