Aggregator
Use This Framework to Anticipate Impact of AI on Jobs
1 week ago
Trending Questions on Government Efficiency and Policy Change
1 week ago
CVE-2007-6301 | Open Newsletter up to 2.5 compose.php Type cross site scripting (EDB-30853 / XFDB-38902)
1 week ago
A vulnerability was found in Open Newsletter up to 2.5 and classified as problematic. This vulnerability affects unknown code of the file compose.php. Executing manipulation of the argument Type can lead to cross site scripting.
This vulnerability appears as CVE-2007-6301. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
CVE-2007-0649 | OpenEMR login_frame.php rootdir code injection (EDB-29556 / BID-22346)
1 week ago
A vulnerability was found in OpenEMR. It has been declared as problematic. Affected is an unknown function of the file interface/login/login_frame.php. Such manipulation of the argument rootdir leads to code injection.
This vulnerability is listed as CVE-2007-0649. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
CVE-2007-0649 | OpenEMR 2.8.2 import_xml.php rootdir code injection (EDB-29556 / BID-22348)
1 week ago
A vulnerability categorized as problematic has been discovered in OpenEMR 2.8.2. Affected is an unknown function of the file import_xml.php. The manipulation of the argument rootdir results in code injection.
This vulnerability is known as CVE-2007-0649. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The actual existence of this vulnerability is currently in question.
vuldb.com
CVE-2007-6608 | OpenBiblio up to 0.5.2 Pre4 staff_del_confirm.php themeName cross site scripting (EDB-30948 / XFDB-39297)
1 week ago
A vulnerability was found in OpenBiblio up to 0.5.2 Pre4. It has been declared as problematic. This affects an unknown function of the file staff_del_confirm.php. Executing manipulation of the argument themeName can lead to cross site scripting.
This vulnerability is tracked as CVE-2007-6608. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CVE-2007-4419 | Olate Olatedownload 3.4.1 admin.php improper authentication (EDB-30504 / XFDB-36088)
1 week ago
A vulnerability was found in Olate Olatedownload 3.4.1 and classified as critical. Impacted is an unknown function of the file admin.php. The manipulation results in improper authentication.
This vulnerability is identified as CVE-2007-4419. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2007-5724 | Omnistar Interactive Omnistar Live kb.php category_id cross site scripting (EDB-30717 / XFDB-38145)
1 week ago
A vulnerability, which was classified as problematic, has been found in Omnistar Interactive Omnistar Live. This affects an unknown part of the file kb.php. This manipulation of the argument category_id causes cross site scripting.
This vulnerability is handled as CVE-2007-5724. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
CVE-2025-38258 | Linux Kernel up to 6.6.95/6.12.35/6.15.4/6.16-rc3 memcg_path_store allocation of resources (EUVD-2025-20803 / Nessus ID 246875)
1 week ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.6.95/6.12.35/6.15.4/6.16-rc3. This impacts the function memcg_path_store. The manipulation results in allocation of resources.
This vulnerability is identified as CVE-2025-38258. The attack can only be performed from the local network. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-38256 | Linux Kernel up to 6.12.35/6.15.4/6.16-rc3 io_uring unpin_user_folio buffer overflow (EUVD-2025-20805 / Nessus ID 258053)
1 week ago
A vulnerability was found in Linux Kernel up to 6.12.35/6.15.4/6.16-rc3. It has been classified as critical. This impacts the function unpin_user_folio of the component io_uring. This manipulation causes buffer overflow.
This vulnerability is registered as CVE-2025-38256. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-38257 | Linux Kernel up to 6.1.142/6.6.95/6.12.35/6.15.4/6.16-rc3 s390 memdup_user nr_apqns allocation of resources (EUVD-2025-20804 / Nessus ID 243301)
1 week ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.1.142/6.6.95/6.12.35/6.15.4/6.16-rc3. This affects the function memdup_user of the component s390. The manipulation of the argument nr_apqns leads to allocation of resources.
This vulnerability is referenced as CVE-2025-38257. The attack needs to be initiated within the local network. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-38255 | Linux Kernel up to 6.6.95/6.12.35/6.15.4/6.16-rc3 group_cpus_evenly null pointer dereference (EUVD-2025-20806 / Nessus ID 271193)
1 week ago
A vulnerability was found in Linux Kernel up to 6.6.95/6.12.35/6.15.4/6.16-rc3 and classified as critical. This affects the function group_cpus_evenly. The manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2025-38255. The attack must originate from the local network. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-38252 | Linux Kernel up to 6.15.4/6.16-rc3 ras cxl_cper_handle_prot_err denial of service (EUVD-2025-20809 / WID-SEC-2025-1517)
1 week ago
A vulnerability classified as critical was found in Linux Kernel up to 6.15.4/6.16-rc3. The impacted element is the function cxl_cper_handle_prot_err of the component ras. Executing manipulation can lead to denial of service.
The identification of this vulnerability is CVE-2025-38252. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-38253 | Linux Kernel up to 6.12.35/6.15.4/6.16-rc3 HID wacom_aes_battery_handler denial of service (EUVD-2025-20808 / Nessus ID 271193)
1 week ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.12.35/6.15.4/6.16-rc3. The affected element is the function wacom_aes_battery_handler of the component HID. Executing manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2025-38253. The attack is only possible within the local network. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2025-38254 | Linux Kernel up to 6.15.4/6.16-rc3 AMD Display drm_edid_raw memory corruption (EUVD-2025-20807 / Nessus ID 271193)
1 week ago
A vulnerability has been found in Linux Kernel up to 6.15.4/6.16-rc3 and classified as critical. The impacted element is the function drm_edid_raw of the component AMD Display. The manipulation leads to memory corruption.
This vulnerability is listed as CVE-2025-38254. The attack must be carried out from within the local network. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2025-38249 | Linux Kernel up to 6.1.142/6.6.95/6.12.35/6.15.4/6.16-rc3 ALSA snd_usb_get_audioformat_uac3 out-of-bounds (EUVD-2025-20812 / Nessus ID 265984)
1 week ago
A vulnerability described as problematic has been identified in Linux Kernel up to 6.1.142/6.6.95/6.12.35/6.15.4/6.16-rc3. Impacted is the function snd_usb_get_audioformat_uac3 of the component ALSA. Such manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-38249. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-38250 | Linux Kernel up to 6.12.35/6.15.4/6.16-rc3 Bluetooth include/linux/skbuff.h vhci_flush use after free (EUVD-2025-20811 / Nessus ID 253667)
1 week ago
A vulnerability labeled as critical has been found in Linux Kernel up to 6.12.35/6.15.4/6.16-rc3. Affected by this vulnerability is the function vhci_flush in the library include/linux/skbuff.h of the component Bluetooth. Executing manipulation can lead to use after free.
This vulnerability is handled as CVE-2025-38250. The attack can only be done within the local network. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-38251 | Linux Kernel up to 6.1.142/6.6.95/6.12.35/6.15.4/6.16-rc3 atm clip_push null pointer dereference (EUVD-2025-20810 / Nessus ID 265749)
1 week ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.142/6.6.95/6.12.35/6.15.4/6.16-rc3. Impacted is the function clip_push of the component atm. Performing manipulation results in null pointer dereference.
This vulnerability is identified as CVE-2025-38251. The attack can only be performed from the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-38246 | Linux Kernel up to 6.12.35/6.15.4/6.16-rc3 XDP_REDIRECT Feature privilege escalation (EUVD-2025-20815 / Nessus ID 247347)
1 week ago
A vulnerability described as problematic has been identified in Linux Kernel up to 6.12.35/6.15.4/6.16-rc3. This affects an unknown part of the component XDP_REDIRECT Feature. The manipulation results in privilege escalation.
This vulnerability was named CVE-2025-38246. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com