Aggregator
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
1 hour 55 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
Pennsylvania AG confirms data breach after INC Ransom attack
1 hour 59 minutes ago
The office of Pennsylvania's attorney general has confirmed that the ransomware gang behind an August 2025 cyberattack stole files containing personal and medical information. [...]
Sergiu Gatlan
Cyber Readiness Stalls Despite Confidence in Incident Response
2 hours 57 minutes ago
New Immersive report finds cyber resilience and decision making are flatlining
Microsoft: Windows bug blocks Microsoft 365 desktop app installs
3 hours 2 minutes ago
Microsoft is working to resolve a known issue preventing users from installing the Microsoft 365 desktop apps on Windows devices. [...]
Sergiu Gatlan
CVE-2025-40364 | Linux Kernel up to 6.1.128/6.6.77 io_uring io_req_prep_async buffer overflow (EUVD-2025-11841 / Nessus ID 240812)
3 hours 22 minutes ago
A vulnerability was found in Linux Kernel up to 6.1.128/6.6.77. It has been classified as critical. The impacted element is the function io_req_prep_async of the component io_uring. This manipulation causes buffer overflow.
This vulnerability appears as CVE-2025-40364. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-37946 | Linux Kernel up to 6.12.28/6.14.6/6.15-rc5 pci_dev_put use after free (Nessus ID 242283 / WID-SEC-2025-1114)
3 hours 22 minutes ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.12.28/6.14.6/6.15-rc5. This affects the function pci_dev_put. Performing manipulation results in use after free.
This vulnerability is known as CVE-2025-37946. Access to the local network is required for this attack. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-37945 | Linux Kernel up to 47ac7b2f6a1ffef76e55a9ec146881a36673284b dsa_switch_suspend denial of service (Nessus ID 240657 / WID-SEC-2025-1114)
3 hours 22 minutes ago
A vulnerability categorized as critical has been discovered in Linux Kernel. This vulnerability affects the function dsa_switch_suspend. Executing manipulation can lead to denial of service.
This vulnerability is registered as CVE-2025-37945. The attack requires access to the local network. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-37944 | Linux Kernel up to 6.6.87/6.12.24/6.13.11/6.14.3 wifi ath12k_dp_mon_srng_process denial of service (Nessus ID 240657 / WID-SEC-2025-1114)
3 hours 22 minutes ago
A vulnerability labeled as critical has been found in Linux Kernel up to 6.6.87/6.12.24/6.13.11/6.14.3. Impacted is the function ath12k_dp_mon_srng_process of the component wifi. The manipulation results in denial of service.
This vulnerability is reported as CVE-2025-37944. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2025-37942 | Linux Kernel up to 6.12.23/6.13.11/6.14.2 HID infinite loop (Nessus ID 240657 / WID-SEC-2025-1114)
3 hours 22 minutes ago
A vulnerability was found in Linux Kernel up to 6.12.23/6.13.11/6.14.2. It has been rated as critical. This affects an unknown part of the component HID. Performing manipulation results in infinite loop.
This vulnerability is cataloged as CVE-2025-37942. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-37941 | Linux Kernel up to 6.12.23/6.13.11/6.14.2 ASoC wcd937x_soc_codec_probe memory leak (Nessus ID 240657 / WID-SEC-2025-1114)
3 hours 22 minutes ago
A vulnerability marked as critical has been reported in Linux Kernel up to 6.12.23/6.13.11/6.14.2. The affected element is the function wcd937x_soc_codec_probe of the component ASoC. This manipulation causes memory leak.
This vulnerability appears as CVE-2025-37941. The attacker needs to be present on the local network. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-37855 | Linux Kernel up to 6.14.2 res_pool null pointer dereference (EUVD-2025-14137 / Nessus ID 240657)
3 hours 22 minutes ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.14.2. The impacted element is the function res_pool. The manipulation leads to null pointer dereference.
This vulnerability is listed as CVE-2025-37855. The attack must be carried out from within the local network. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-37943 | Linux Kernel up to 6.6.87/6.12.23/6.13.11/6.14.2 wifi ath12k_dp_rx_h_undecap_nwifi memory corruption (Nessus ID 237977 / WID-SEC-2025-1114)
3 hours 22 minutes ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.6.87/6.12.23/6.13.11/6.14.2. The impacted element is the function ath12k_dp_rx_h_undecap_nwifi of the component wifi. Such manipulation leads to memory corruption.
This vulnerability is traded as CVE-2025-37943. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-37854 | Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2 reset_domain use after free (Nessus ID 237504)
3 hours 22 minutes ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2. Impacted is the function reset_domain. Performing manipulation results in use after free.
This vulnerability is identified as CVE-2025-37854. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10445 | Synology DiskStation Manager certificate validation (SA_24_20)
3 hours 22 minutes ago
A vulnerability was found in Synology DiskStation Manager, Unified Controller and BeeStation Manager and classified as critical. Impacted is an unknown function. Executing manipulation can lead to improper certificate validation.
This vulnerability is tracked as CVE-2024-10445. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-10441 | Synology DiskStation Manager System Plugin Daemon escape output (SA_24_20)
3 hours 22 minutes ago
A vulnerability was found in Synology DiskStation Manager, Unified Controller and BeeStation Manager. It has been declared as very critical. The impacted element is an unknown function of the component System Plugin Daemon. The manipulation results in escaping of output.
This vulnerability is cataloged as CVE-2024-10441. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-13305 | D-Link DWR-M920/DWR-M921/DWR-M960/DIR-822K/DIR-825M 1.01.07 formTracerouteDiagnosticRun host buffer overflow
3 hours 34 minutes ago
A vulnerability was found in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07 and classified as critical. This issue affects some unknown processing of the file /boafrm/formTracerouteDiagnosticRun. Executing manipulation of the argument host can lead to buffer overflow.
The identification of this vulnerability is CVE-2025-13305. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-13304 | D-Link DWR-M920/DWR-M921/DWR-M960/DWR-M961/DIR-825M 1.01.07/1.1.47 formPingDiagnosticRun host buffer overflow
3 hours 35 minutes ago
A vulnerability has been found in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formPingDiagnosticRun. Performing manipulation of the argument host results in buffer overflow.
This vulnerability was named CVE-2025-13304. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
CVE-2025-3572 | INTUMIT SmartRobot up to 7.x server-side request forgery
4 hours 12 minutes ago
A vulnerability was found in INTUMIT SmartRobot up to 7.x and classified as critical. This issue affects some unknown processing. Such manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2025-3572. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-37846 | Linux Kernel up to 6.12.23/6.13.11/6.14.2 arm64 do_el0_mops null pointer dereference (Nessus ID 240657 / WID-SEC-2025-1114)
4 hours 12 minutes ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.23/6.13.11/6.14.2. Impacted is the function do_el0_mops of the component arm64. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2025-37846. The attack needs to be approached within the local network. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com