Latest CVE Feed
-
7.5
HIGHCVE-2024-8361
In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length triggers a software assertion, which subsequently causes a Denial of Service (DoS). If a watchdog is implemented, device will restart aft... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Denial of Service
-
5.8
MEDIUMCVE-2024-7322
A ZigBee coordinator, router, or end device may change their node ID when an unsolicited encrypted rejoin response is received, this change in node ID causes Denial of Service (DoS). To recover from this DoS, the network must be re-established... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2022-48633
In the Linux kernel, the following vulnerability has been resolved: drm/gma500: Fix WARN_ON(lock->magic != lock) error psb_gem_unpin() calls dma_resv_lock() but the underlying ww_mutex gets destroyed by drm_gem_object_release() move the drm_gem_object_r... Read more
Affected Products : linux_kernel- Published: Apr. 28, 2024
- Modified: Sep. 16, 2025
-
5.5
MEDIUMCVE-2022-48631
In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug in extents parsing when eh_entries == 0 and eh_depth > 0 When walking through an inode extents, the ext4_ext_binsearch_idx() function assumes that the extent header has be... Read more
Affected Products : linux_kernel- Published: Apr. 28, 2024
- Modified: Sep. 16, 2025
-
5.5
MEDIUMCVE-2024-26921
In the Linux kernel, the following vulnerability has been resolved: inet: inet_defrag: prevent sk release while still in use ip_local_out() and other functions can pass skb->sk as function argument. If the skb is a fragment and reassembly happens befor... Read more
Affected Products : linux_kernel- Published: Apr. 18, 2024
- Modified: Sep. 16, 2025
-
5.5
MEDIUMCVE-2024-26920
In the Linux kernel, the following vulnerability has been resolved: tracing/trigger: Fix to return error if failed to alloc snapshot Fix register_snapshot_trigger() to return error code if it failed to allocate a snapshot instead of 0 (success). Unless ... Read more
Affected Products : linux_kernel- Published: Apr. 17, 2024
- Modified: Sep. 16, 2025
-
8.0
HIGHCVE-2024-47770
Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. This vulnerability occurs when the system has... Read more
Affected Products : wazuh- Published: Feb. 03, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2024-26919
In the Linux kernel, the following vulnerability has been resolved: usb: ulpi: Fix debugfs directory leak The ULPI per-device debugfs root is named after the ulpi device's parent, but ulpi_unregister_interface tries to remove a debugfs directory named a... Read more
Affected Products : linux_kernel- Published: Apr. 17, 2024
- Modified: Sep. 16, 2025
-
8.4
HIGHCVE-2023-39943
In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to e... Read more
- Published: Feb. 04, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Memory Corruption
-
8.4
HIGHCVE-2023-40222
In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerabilit... Read more
- Published: Feb. 04, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2024-26906
In the Linux kernel, the following vulnerability has been resolved: x86/mm: Disallow vsyscall page read for copy_from_kernel_nofault() When trying to use copy_from_kernel_nofault() to read vsyscall page through a bpf program, the following oops was repo... Read more
- Published: Apr. 17, 2024
- Modified: Sep. 16, 2025
-
7.5
HIGHCVE-2025-36003
IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.... Read more
Affected Products : security_verify_governance- Published: Aug. 28, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2024-26914
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix incorrect mpc_combine array size [why] MAX_SURFACES is per stream, while MAX_PLANES is per asic. The mpc_combine is an array that records all the planes per asic. T... Read more
Affected Products : linux_kernel- Published: Apr. 17, 2024
- Modified: Sep. 16, 2025
-
5.4
MEDIUMCVE-2025-9646
A security flaw has been discovered in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_organization_assemble_personal/jaxrs/definition/calendarConfig. The manipulation of the argument toMonthViewName results in cross site scrip... Read more
Affected Products : o2oa- Published: Aug. 29, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-9655
A weakness has been identified in O2OA up to 10.0-410. This affects an unknown part of the file /x_organization_assemble_control/jaxrs/person/ of the component Personal Profile Page. Executing manipulation of the argument Description can lead to cross sit... Read more
Affected Products : o2oa- Published: Aug. 29, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2024-26916
In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amd: flush any delayed gfxoff on suspend entry" commit ab4750332dbe ("drm/amdgpu/sdma5.2: add begin/end_use ring callbacks") caused GFXOFF control to be used more heavily an... Read more
Affected Products : linux_kernel- Published: Apr. 17, 2024
- Modified: Sep. 16, 2025
-
5.4
MEDIUMCVE-2025-9657
A vulnerability was detected in O2OA up to 10.0-410. This issue affects some unknown processing of the file /x_program_center/jaxrs/script of the component Personal Profile Page. The manipulation of the argument name/alias/description results in cross sit... Read more
Affected Products : o2oa- Published: Aug. 29, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Cross-Site Scripting
-
6.2
MEDIUMCVE-2024-26918
In the Linux kernel, the following vulnerability has been resolved: PCI: Fix active state requirement in PME polling The commit noted in fixes added a bogus requirement that runtime PM managed devices need to be in the RPM_ACTIVE state for PME polling. ... Read more
Affected Products : linux_kernel- Published: Apr. 17, 2024
- Modified: Sep. 16, 2025
-
5.4
MEDIUMCVE-2025-9658
A flaw has been found in O2OA up to 10.0-410. Impacted is an unknown function of the file /x_portal_assemble_designer/jaxrs/dict/ of the component Personal Profile Page. This manipulation of the argument name/alias/description causes cross site scripting.... Read more
Affected Products : o2oa- Published: Aug. 29, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2023-52522
In the Linux kernel, the following vulnerability has been resolved: net: fix possible store tearing in neigh_periodic_work() While looking at a related syzbot report involving neigh_periodic_work(), I found that I forgot to add an annotation when deleti... Read more
Affected Products : linux_kernel- Published: Mar. 02, 2024
- Modified: Sep. 16, 2025