Aggregator
CVE-2025-38063 | Linux Kernel up to 6.1.140/6.6.92/6.12.30/6.14.8 dm __send_empty_flush state issue (Nessus ID 241773 / WID-SEC-2025-1350)
1 month 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.1.140/6.6.92/6.12.30/6.14.8. This affects the function __send_empty_flush of the component dm. This manipulation causes state issue.
The identification of this vulnerability is CVE-2025-38063. The attack needs to be done within the local network. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-38060 | Linux Kernel up to 6.12.30/6.14.8 bpf copy_verifier_state state issue (EUVD-2025-18593 / Nessus ID 241605)
1 month 3 weeks ago
A vulnerability described as problematic has been identified in Linux Kernel up to 6.12.30/6.14.8. Impacted is the function copy_verifier_state of the component bpf. Executing a manipulation can lead to state issue.
This vulnerability is handled as CVE-2025-38060. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-38062 | Linux Kernel up to 6.1.140/6.6.92/6.12.30/6.14.8 MSI iommu_dma_prepare_msi allocation of resources (Nessus ID 241773 / WID-SEC-2025-1350)
1 month 3 weeks ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.1.140/6.6.92/6.12.30/6.14.8. This impacts the function iommu_dma_prepare_msi of the component MSI. Such manipulation leads to allocation of resources.
This vulnerability is referenced as CVE-2025-38062. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2025-38061 | Linux Kernel up to 6.14.8 net pktgen_thread_write buffer overflow (Nessus ID 242218 / WID-SEC-2025-1350)
1 month 3 weeks ago
A vulnerability classified as critical was found in Linux Kernel up to 6.14.8. This affects the function pktgen_thread_write of the component net. Executing a manipulation can lead to buffer overflow.
This vulnerability is handled as CVE-2025-38061. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-38059 | Linux Kernel up to 6.6.92/6.12.30/6.14.8 btrfs_search_slot null pointer dereference (EUVD-2025-18594 / Nessus ID 242347)
1 month 3 weeks ago
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.92/6.12.30/6.14.8. Impacted is the function btrfs_search_slot. Performing a manipulation results in null pointer dereference.
This vulnerability is reported as CVE-2025-38059. The attacker must have access to the local network to execute the attack. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2025-38058 | Linux Kernel up to 6.14.8 __legitimize_mnt locking (Nessus ID 241773 / WID-SEC-2025-1350)
1 month 3 weeks ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.14.8. This issue affects the function __legitimize_mnt. The manipulation results in improper locking.
This vulnerability was named CVE-2025-38058. The attack needs to be approached within the local network. There is no available exploit.
You should upgrade the affected component.
vuldb.com
AI-Native SOC Data Fitness: From Telemetry Flood to Decision-Quality Signals
1 month 3 weeks ago
'Promptware' Attacks Await an Unprepared AI Industry
1 month 3 weeks ago
Researchers Say AI Prompt Injection Has Emerged As a Dangerous New Class of Attacks
The large language model industry has mostly treated prompt injection attacks as a risk analogous to traditional web server prompt injection attacks. Researchers now say feeding rogue instructions to an artificial intelligence system merits its own classification as "promptware."
The large language model industry has mostly treated prompt injection attacks as a risk analogous to traditional web server prompt injection attacks. Researchers now say feeding rogue instructions to an artificial intelligence system merits its own classification as "promptware."
Hackers Increasingly Prefer Fast and Low-Complexity Attacks
1 month 3 weeks ago
Incident Responders Detail Top Ransomware and Business Email Compromise Tactics
There's no need to invest into sophisticated hacking operations when moving fast and exploiting well-trod techniques gives threat actors all the access they want. Threat actors are prioritizing "low-complexity entry points, rather than investing in sophisticated exploits," say incident responders.
There's no need to invest into sophisticated hacking operations when moving fast and exploiting well-trod techniques gives threat actors all the access they want. Threat actors are prioritizing "low-complexity entry points, rather than investing in sophisticated exploits," say incident responders.
CVE-2023-46930 | GPAC 2.3-DEV-rev605-gfc9e29089-master MP4Box media_odf.c gf_isom_find_od_id_for_track memory corruption (EUVD-2023-51093)
1 month 3 weeks ago
A vulnerability classified as critical has been found in GPAC 2.3-DEV-rev605-gfc9e29089-master. This issue affects the function gf_isom_find_od_id_for_track of the file /afltest/gpac/src/isomedia/media_odf.c of the component MP4Box. Performing a manipulation results in memory corruption.
This vulnerability is known as CVE-2023-46930. Access to the local network is required for this attack. No exploit is available.
vuldb.com
CVE-2023-46927 | GPAC 2.3-DEV-rev605-gfc9e29089-master isom_write.c gf_isom_use_compact_size heap-based overflow (Issue 2657 / EUVD-2023-51090)
1 month 3 weeks ago
A vulnerability was found in GPAC 2.3-DEV-rev605-gfc9e29089-master and classified as critical. This impacts the function gf_isom_use_compact_size of the file gpac/src/isomedia/isom_write.c. Such manipulation leads to heap-based buffer overflow.
This vulnerability is referenced as CVE-2023-46927. It is possible to launch the attack remotely. No exploit is available.
It is advisable to implement a patch to correct this issue.
vuldb.com
CVE-2023-46928 | GPAC 2.3-DEV-rev605-gfc9e29089-master MP4Box isom_tools.c gf_media_change_pl memory corruption (Issue 2661 / EUVD-2023-51091)
1 month 3 weeks ago
A vulnerability, which was classified as critical, was found in GPAC 2.3-DEV-rev605-gfc9e29089-master. The impacted element is the function gf_media_change_pl of the file /afltest/gpac/src/media_tools/isom_tools.c of the component MP4Box. The manipulation results in memory corruption.
This vulnerability was named CVE-2023-46928. The attack may be performed from remote. There is no available exploit.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2023-46916 | Maxima Max Pro Power 1.0 486A BLE authentication replay (ID 175660 / EUVD-2023-51080)
1 month 3 weeks ago
A vulnerability categorized as critical has been discovered in Maxima Max Pro Power 1.0 486A. This issue affects some unknown processing of the component BLE. Executing a manipulation can lead to authentication bypass by capture-replay.
This vulnerability appears as CVE-2023-46916. The attack requires local access. There is no available exploit.
vuldb.com
Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in The Wild Targeting Corporate Networks
1 month 3 weeks ago
Two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) have emerged as a major threat to enterprise networks, with active exploitation campaigns targeting corporate infrastructure across multiple countries. The vulnerabilities, identified as CVE-2026-1281 and CVE-2026-1340, enable unauthenticated attackers to execute arbitrary code remotely on target servers without requiring any user interaction or credentials. These […]
The post Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in The Wild Targeting Corporate Networks appeared first on Cyber Security News.
Tushar Subhra Dutta
CVE-2026-2641 | universal-ctags up to 6.2.1 V Language Parser parsers/v.c parseExpression/parseExprList recursion (Issue 4369 / Nessus ID 299393)
1 month 3 weeks ago
A vulnerability categorized as problematic has been discovered in universal-ctags ctags up to 6.2.1. The affected element is the function parseExpression/parseExprList of the file parsers/v.c of the component V Language Parser. Executing a manipulation can lead to uncontrolled recursion.
This vulnerability is handled as CVE-2026-2641. It is possible to launch the attack on the local host. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
Firebase Misconfiguration Exposes 300M Messages From Chat & Ask AI Users
1 month 3 weeks ago
A technical mistake in the popular Chat & Ask AI app has left 300 million private messages from 25 million users exposed online. Discover what happened and how you can protect your personal data when using AI chatbots.
Deeba Ahmed
CVE-2021-22175 | GitLab 10.5 Webhook server-side request forgery
1 month 3 weeks ago
A vulnerability was found in GitLab 10.5. It has been rated as critical. This affects an unknown function of the component Webhook Handler. Performing a manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2021-22175. The attack must originate from the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-31342 | oretnom23 Online Car Wash Booking System 1.0 Master.php?f=delete_img denial of service
1 month 3 weeks ago
A vulnerability categorized as problematic has been discovered in oretnom23 Online Car Wash Booking System 1.0. This vulnerability affects unknown code of the file /ocwbs/classes/Master.php?f=delete_img. The manipulation results in denial of service.
This vulnerability is identified as CVE-2022-31342. The attack can only be performed from the local network. There is not any exploit available.
vuldb.com
CVE-2022-31344 | oretnom23 Online Car Wash Booking System 1.0 Master.php?f=delete_booking sql injection
1 month 3 weeks ago
A vulnerability identified as critical has been detected in oretnom23 Online Car Wash Booking System 1.0. This issue affects some unknown processing of the file /ocwbs/classes/Master.php?f=delete_booking. This manipulation causes sql injection.
This vulnerability is tracked as CVE-2022-31344. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com