Latest CVE Feed
- 
                                
                                
8.8
HIGHCVE-2025-57457
An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the "IP Addr" parameter.... Read more
Affected Products :- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-11490
A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file src/command-manager.ts of the component Absolute Path Handler. Such manipulation leads to os command injec... Read more
Affected Products :- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
0.0
NACVE-2023-53627
In the Linux kernel, the following vulnerability has been resolved: scsi: hisi_sas: Grab sas_dev lock when traversing the members of sas_dev.list When freeing slots in function slot_complete_v3_hw(), it is possible that sas_dev.list is being traversed e... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Race Condition
 
 - 
                                
                                
0.0
NACVE-2023-53638
In the Linux kernel, the following vulnerability has been resolved: octeon_ep: cancel queued works in probe error path If it fails to get the devices's MAC address, octep_probe exits while leaving the delayed work intr_poll_task queued. When the work la... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2023-53635
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: fix wrong ct->timeout value (struct nf_conn)->timeout is an interval before the conntrack confirmed. After confirmed, it becomes a timestamp. It is observed that... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 
 - 
                                
                                
0.0
NACVE-2023-53631
In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-sysman: Fix reference leak If a duplicate attribute is found using kset_find_obj(), a reference to that attribute is returned. This means that we need to dispose it a... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2023-53624
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_fq: fix integer overflow of "credit" if sch_fq is configured with "initial quantum" having values greater than INT_MAX, the first assignment of "credit" does signed integ... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
0.0
NACVE-2023-53622
In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix possible data races in gfs2_show_options() Some fields such as gt_logd_secs of the struct gfs2_tune are accessed without holding the lock gt_spin in gfs2_show_options(): va... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Race Condition
 
 - 
                                
                                
0.0
NACVE-2023-53619
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: Avoid nf_ct_helper_hash uses after free If nf_conntrack_init_start() fails (for example due to a register_nf_conntrack_bpf() failure), the nf_conntrack_helper_fini... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2022-50555
In the Linux kernel, the following vulnerability has been resolved: tipc: fix a null-ptr-deref in tipc_topsrv_accept syzbot found a crash in tipc_topsrv_accept: KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] Workqueue: tipc_... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2022-50554
In the Linux kernel, the following vulnerability has been resolved: blk-mq: avoid double ->queue_rq() because of early timeout David Jeffery found one double ->queue_rq() issue, so far it can be triggered in VM use case because of long vmexit latency or... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Race Condition
 
 - 
                                
                                
0.0
NACVE-2022-50553
In the Linux kernel, the following vulnerability has been resolved: tracing/hist: Fix out-of-bound write on 'action_data.var_ref_idx' When generate a synthetic event with many params and then create a trace action for it [1], kernel panic happened [2]. ... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2022-50550
In the Linux kernel, the following vulnerability has been resolved: blk-iolatency: Fix memory leak on add_disk() failures When a gendisk is successfully initialized but add_disk() fails such as when a loop device has invalid number of minor device numbe... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2022-50547
In the Linux kernel, the following vulnerability has been resolved: media: solo6x10: fix possible memory leak in solo_sysfs_init() If device_register() returns error in solo_sysfs_init(), the name allocated by dev_set_name() need be freed. As comment of... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2022-50544
In the Linux kernel, the following vulnerability has been resolved: usb: host: xhci: Fix potential memory leak in xhci_alloc_stream_info() xhci_alloc_stream_info() allocates stream context array for stream_info ->stream_ctx_array with xhci_alloc_stream_... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2022-50542
In the Linux kernel, the following vulnerability has been resolved: media: si470x: Fix use-after-free in si470x_int_in_callback() syzbot reported use-after-free in si470x_int_in_callback() [1]. This indicates that urb->context, which contains struct si... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2022-50538
In the Linux kernel, the following vulnerability has been resolved: vme: Fix error not catched in fake_init() In fake_init(), __root_device_register() is possible to fail but it's ignored, which can cause unregistering vme_root fail when exit. general... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 
 - 
                                
                                
0.0
NACVE-2022-50537
In the Linux kernel, the following vulnerability has been resolved: firmware: raspberrypi: fix possible memory leak in rpi_firmware_probe() In rpi_firmware_probe(), if mbox_request_channel() fails, the 'fw' will not be freed through rpi_firmware_delete(... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2022-50536
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix repeated calls to sock_put() when msg has more_data In tcp_bpf_send_verdict() redirection, the eval variable is assigned to __SK_REDIRECT after the apply_bytes data is... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2022-50535
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential null-deref in dm_resume [Why] Fixing smatch error: dm_resume() error: we previously assumed 'aconnector->dc_link' could be null [How] Check if dc_link nu... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025