THREAT OPS › Threat News
Threat Intelligence News
12284 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- How GitHub’s agentic security principles make our AI agents as secure as possiblegithub_security_lab · 2025-11-25
- Antigravity Grounded! Security Vulnerabilities in Google's Latest IDEembracethered · 2025-11-25
- [Breach] Suno — 55,282,226 accounts exposedhibp_breaches · 2025-11-25
- [NVD] CVE-2025-11003 (MEDIUM 6.4) — The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_ui_template' function in all versions up to, and including, 3.5.09. This makes it posnvd · 2025-11-21
- [NVD] CVE-2025-10938 (MEDIUM 6.5) — The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with sunvd · 2025-11-21
- What organisations can learn from the record breaking fine over Capita’s ransomware incidentdoublepulsar · 2025-11-20
- Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharinggoogle_security · 2025-11-20
- [NVD] CVE-2025-61664 (MEDIUM 4.9) — A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking nvd · 2025-11-18
- [NVD] CVE-2025-61663 (MEDIUM 4.9) — A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the normal command is not properly unregistered when the module is unloaded. An attacker who can nvd · 2025-11-18
- [NVD] CVE-2025-61662 (HIGH 7.8) — A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condition by invoking the orphaned command, causnvd · 2025-11-18
- [NVD] CVE-2025-61661 (MEDIUM 4.8) — A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can nvd · 2025-11-18
- [NVD] CVE-2025-54771 (MEDIUM 4.9) — A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerabilnvd · 2025-11-18
- [NVD] CVE-2025-54770 (MEDIUM 4.9) — A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the net_set_vlan command is not properly unregistered when the network module is unloaded from menvd · 2025-11-18
- [NVD] CVE-2025-63994 — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2018-9206. Reason: This record is a duplicate of CVE-2018-9206. Notes: All CVE users should reference CVE-2018-9206 instead of this record. All references and descriptions in this record have been removed to prevent accnvd · 2025-11-18
- How an Old Bug in Lighttpd Gained New Life in AMI BMC, Including Lenovo and Intel productsbinarly · 2025-11-18
- YAMAGoya: A Real-time Client Monitoring Tool Using Sigma and YARA Rulesjpcert_blog · 2025-11-18
- Rust in Android: move fast and fix thingsgoogle_security · 2025-11-13
- [NVD] CVE-2025-40206 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_objref: validate objref and objrefmap expressions Referencing a synproxy stateful object from OUTPUT hook causes kernel crash due to infinite recursive calls: BUG: TASK stack guard page was hit nvd · 2025-11-12
- [NVD] CVE-2025-40196 — In the Linux kernel, the following vulnerability has been resolved: fs: quota: create dedicated workqueue for quota_release_work There is a kernel panic due to WARN_ONCE when panic_on_warn is set. This issue occurs when writeback is triggered due to sync call for an opened filnvd · 2025-11-12
- [NVD] CVE-2025-2843 (HIGH 8.8) — A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenvd · 2025-11-12
- [NVD] CVE-2025-40168 (HIGH 8.1) — In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). smc_clc_prfx_match() is called from smc_listen_work() and not under RCU nor RTNL. Using sk_dst_get(sk)->dev could trigger UAF. Let's use __sknvd · 2025-11-12
- [NVD] CVE-2025-40139 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set(). smc_clc_prfx_set() is called during connect() and not under RCU nor RTNL. Using sk_dst_get(sk)->dev could trigger UAF. Let's use __sk_dst_genvd · 2025-11-12
- [NVD] CVE-2025-40123 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Enforce expected_attach_type for tailcall compatibility Yinhao et al. recently reported: Our fuzzer tool discovered an uninitialized pointer issue in the bpf_prog_test_run_xdp() function within the Linvd · 2025-11-12
- VTPRACTITIONERS{ACRONIS}: Tracking FileFix, Shadow Vector, and SideWindervirustotal_blog · 2025-11-10
- [NVD] CVE-2025-10230 (CRITICAL 10.0) — A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the nvd · 2025-11-07
- Reversing at Scale: AI-Powered Malware Detection for Apple’s Binariesvirustotal_blog · 2025-11-06
- [NVD] CVE-2023-43000 (HIGH 8.8) — A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.nvd · 2025-11-05
- Update on Attacks by Threat Group APT-C-60jpcert_blog · 2025-11-05
- [NVD] CVE-2025-43441 (MEDIUM 4.3) — The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.nvd · 2025-11-04
- [NVD] CVE-2025-43438 (MEDIUM 4.3) — A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Sanvd · 2025-11-04
- [NVD] CVE-2025-43433 (HIGH 8.8) — The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption.nvd · 2025-11-04
- CyberSlop — meet the new threat actor, MIT and Safe Securitydoublepulsar · 2025-11-03
- November is the Month of Searches: Explore, Learn, and Share with #MonthOfVTSearchvirustotal_blog · 2025-11-03
- [NVD] CVE-2025-12464 (MEDIUM 6.2) — A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to process a short frame in loopnvd · 2025-10-31
- [NVD] CVE-2023-7314 (MEDIUM 5.4) — Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.nvd · 2025-10-30
- [NVD] CVE-2023-7313 (MEDIUM 5.4) — Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.nvd · 2025-10-30
- How Android provides the most effective protection to keep you safe from mobile scamsgoogle_security · 2025-10-30
- [NVD] CVE-2025-40102 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Prevent access to vCPU events before init Another day, another syzkaller bug. KVM erroneously allows userspace to pend vCPU events for a vCPU that hasn't been initialized yet, leading to KVM interprnvd · 2025-10-30
- [NVD] CVE-2025-40098 — In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state() Return value of a function acpi_evaluate_dsm() is dereferenced without checking for NULL, but it is usually checked for this funvd · 2025-10-30
- Evolving Product Security: Scaling YARA Detections with the Binarly Transparency Platform v3.5binarly · 2025-10-30
- HTTPS by defaultgoogle_security · 2025-10-28
- Claude Pirate: Abusing Anthropic's File API For Data Exfiltrationembracethered · 2025-10-28
- [NVD] CVE-2025-40074 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF. Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(), ipv4_neigh_lookup() to use lockdep enabled dnvd · 2025-10-28
- [NVD] CVE-2025-40064 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: smc: Fix use-after-free in __pnet_find_base_ndev(). syzbot reported use-after-free of net_device in __pnet_find_base_ndev(), which was called during connect(). [0] smc_pnet_find_ism_resource() fetches sk_dst_gnvd · 2025-10-28
- [NVD] CVE-2025-40054 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: f2fs: fix UAF issue in f2fs_merge_page_bio() As JY reported in bugzilla [1], Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 pc : [0xffffffe51d249484] f2fs_is_cp_guaranteednvd · 2025-10-28
- TSUBAME Report Overflow (Apr-Jun 2025)jpcert_blog · 2025-10-28
- [NVD] CVE-2025-10939 (LOW 3.7) — A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application patnvd · 2025-10-28
- [NVD] CVE-2025-4106 — An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.nvd · 2025-10-24
- [NVD] CVE-2025-57848 (MEDIUM 6.4) — A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affnvd · 2025-10-23
- Microsoft builds on Recall with Gaming Copilot — fails basic privacy testsdoublepulsar · 2025-10-23
- Hugging Face and VirusTotal: Building Trust in AI Modelsvirustotal_blog · 2025-10-23
- Cryptographic Algorithms Identification in Java Bytecodebinarly · 2025-10-23
- [NVD] CVE-2023-53706 — In the Linux kernel, the following vulnerability has been resolved: mm/vmemmap/devdax: fix kernel crash when probing devdax devices commit 4917f55b4ef9 ("mm/sparse-vmemmap: improve memory savings for compound devmaps") added support for using optimized vmmemap for devdax devicenvd · 2025-10-22
- [NVD] CVE-2022-50560 — In the Linux kernel, the following vulnerability has been resolved: drm/meson: explicitly remove aggregate driver at module unload time Because component_master_del wasn't being called when unloading the meson_drm module, the aggregate device would linger forever in the global nvd · 2025-10-22
- VTPRACTITIONERS{SEQRITE}: Tracking UNG0002, Silent Lynx and DragonClonevirustotal_blog · 2025-10-21
- Inside the breach that broke the internet: The untold story of Log4Shellgithub_security_lab · 2025-10-20
- Missing Mitigations: Inside The Security Gap in UEFI Firmwarebinarly · 2025-10-17
- [NVD] CVE-2025-11568 (MEDIUM 4.4) — A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption format. An attacker with the necessary permissions can exploit this flaw by writing a large amount of metadata to an encrypted device. The utility fails to correctnvd · 2025-10-15
- [NVD] CVE-2025-20359 (MEDIUM 6.5) — Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensitive data or cause the Snort 3 Detection Engine to crash. This vulnerability is due to an error in nvd · 2025-10-15
- [NVD] CVE-2025-9640 (MEDIUM 4.3) — A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnnvd · 2025-10-15
- [NVD] CVE-2025-39991 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load() If ab->fw.m3_data points to data, then fw pointer remains null. Further, if m3_mem is not allocated, then fw is dereferenced to be passed to ath11k_errnvd · 2025-10-15
- [NVD] CVE-2023-7305 — SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can send specially crafted requests that cause the application to perform sensitive operations or executenvd · 2025-10-15
- [NVD] CVE-2025-25252 (MEDIUM 4.8) — An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was tenvd · 2025-10-14
- [NVD] CVE-2025-11731 (LOW 3.1) — A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This cnvd · 2025-10-14
- [NVD] CVE-2025-39964 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes mnvd · 2025-10-13
- [NVD] CVE-2025-61884 (HIGH 7.5) — Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Confignvd · 2025-10-12
- [NVD] CVE-2025-11561 (HIGH 8.8) — A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. Thnvd · 2025-10-09
- Simpler Access for a Stronger VirusTotalvirustotal_blog · 2025-10-08
- APT Meets GPT: Targeted Operations with Untamed LLMsvolexity · 2025-10-08
- [NVD] CVE-2025-8291 (MEDIUM 4.3) — The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could benvd · 2025-10-07
- [NVD] CVE-2022-50535 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential null-deref in dm_resume [Why] Fixing smatch error: dm_resume() error: we previously assumed 'aconnector->dc_link' could be null [How] Check if dc_link null at the beginning of thnvd · 2025-10-07
- [NVD] CVE-2022-50527 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix size validation for non-exclusive domains (v4) Fix amdgpu_bo_validate_size() to check whether the TTM domain manager for the requested memory exists, else we get a kernel oops when dereferencingnvd · 2025-10-07
- [NVD] CVE-2025-11362 (HIGH 7.5) — Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafnvd · 2025-10-07
- [NVD] CVE-2025-61882 (CRITICAL 9.8) — Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to cnvd · 2025-10-05
- [NVD] CVE-2022-50507 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate data run offset This adds sanity checks for data run offset. We should make sure data run offset is legit before trying to unpack them, otherwise we may encounter use-after-free or some unexpnvd · 2025-10-04
- [NVD] CVE-2025-11234 (HIGH 7.5) — A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client wnvd · 2025-10-03
- [NVD] CVE-2022-50451 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix memory leak on ntfs_fill_super() error path syzbot reported kmemleak as below: BUG: memory leak unreferenced object 0xffff8880122f1540 (size 32): comm "a.out", pid 6664, jiffies 4294939771 (agenvd · 2025-10-01
- [NVD] CVE-2022-50442 (HIGH 8.4) — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate buffer length while parsing index indx_read is called when we have some NTFS directory operations that need more information from the index buffers. This adds a sanity check to make sure the nvd · 2025-10-01
- [NVD] CVE-2022-50420 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/hpre - fix resource leak in remove process In hpre_remove(), when the disable operation of qm sriov failed, the following logic should continue to be executed to release the remaining resourcenvd · 2025-10-01
- [NVD] CVE-2021-4460 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix UBSAN shift-out-of-bounds warning If get_num_sdma_queues or get_num_xgmi_sdma_queues is 0, we end up doing a shift operation where the number of bits shifted equals number of bits in the operandnvd · 2025-10-01
- Crowdsourced AI += Exodia Labsvirustotal_blog · 2025-10-01
- [NVD] CVE-2025-39925 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: can: j1939: implement NETDEV_UNREGISTER notification handler syzbot is reporting unregister_netdevice: waiting for vcan0 to become free. Usage count = 2 problem, for j1939 protocol did not have NETDEV_UNREGnvd · 2025-10-01
- [NVD] CVE-2025-39901 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: i40e: remove read access to debugfs files The 'command' and 'netdev_ops' debugfs files are a legacy debugging interface supported by the i40e driver since its early days by commit 02e9c290814c ("i40e: debugfs invd · 2025-10-01
- Advanced Threat Hunting: Automating Large-Scale Operations with LLMsvirustotal_blog · 2025-09-30
- From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusiondfirreport · 2025-09-29
- Cross-Agent Privilege Escalation: When Agents Free Each Otherembracethered · 2025-09-24
- Accelerating adoption of AI for cybersecurity at DEF CON 33google_security · 2025-09-24
- [NVD] CVE-2025-20327 (HIGH 7.7) — A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation. An attacker could exploit this vulnnvd · 2025-09-24
- [NVD] CVE-2025-20313 (MEDIUM 6.7) — Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. These vulnerabilitnvd · 2025-09-24
- [NVD] CVE-2025-20312 (HIGH 7.7) — A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when parsinvd · 2025-09-24
- [NVD] CVE-2025-20311 (HIGH 7.4) — A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic. This vulnerability is due to impropenvd · 2025-09-24
- [NVD] CVE-2025-20160 (HIGH 8.1) — A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists because the system does not properly check nvd · 2025-09-24
- [NVD] CVE-2025-20149 (MEDIUM 6.5) — A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a buffer overflow. An attanvd · 2025-09-24
- Broken Trust: Fixed Supermicro BMC Bug Gains a New Life in Two New Vulnerabilitiesbinarly · 2025-09-24
- [NVD] CVE-2025-4993 (CRITICAL 9.1) — Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.10, from 6.1.0 before 6.1.2.27, from 6.0.0 before 6.0.1.43, from 5.3.0 bnvd · 2025-09-23
- [NVD] CVE-2025-4582 (HIGH 7.1) — Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.8, from 6.1.0 before 6.1.2.26, from 6.0.0 before 6.0nvd · 2025-09-23
- [NVD] CVE-2025-39862 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix list corruption after hardware restart Since stations are recreated from scratch, all lists that wcids are added to must be cleared before calling ieee80211_restart_hw. Set wcid->sta = 0nvd · 2025-09-19
- [NVD] CVE-2025-10035 (CRITICAL 10.0) — A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.nvd · 2025-09-18
- [NVD] CVE-2022-50418 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: mhi: fix potential memory leak in ath11k_mhi_register() mhi_alloc_controller() allocates a memory space for mhi_ctrl. When gets some error, mhi_ctrl should be freed with mhi_free_controller(). Butnvd · 2025-09-18
- [NVD] CVE-2022-50407 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - increase the memory of local variables Increase the buffer to prevent stack overflow by fuzz test. The maximum length of the qos configuration buffer is 256 bytes. Currently, the value ofnvd · 2025-09-18