Aggregator
Microsoft security advisory – February 2026 monthly rollup (AV26-111) - Update 1
1 day 2 hours ago
Canadian Centre for Cyber Security
CVE-2022-50881 | Linux Kernel up to 5.10.172/5.15.98/6.1.15/6.2.2 ath9k_hif_usb_disconnect use after free (Nessus ID 298924 / WID-SEC-2025-2941)
1 day 2 hours ago
A vulnerability was found in Linux Kernel up to 5.10.172/5.15.98/6.1.15/6.2.2. It has been classified as critical. This affects the function ath9k_hif_usb_disconnect. This manipulation causes use after free.
This vulnerability is handled as CVE-2022-50881. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2022-50884 | Linux Kernel up to 6.0.2 drm_copy_field drm_driver null pointer dereference (Nessus ID 298924 / WID-SEC-2025-2941)
1 day 2 hours ago
A vulnerability was found in Linux Kernel up to 6.0.2. It has been rated as critical. This issue affects the function drm_copy_field. Performing a manipulation of the argument drm_driver results in null pointer dereference.
This vulnerability was named CVE-2022-50884. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2022-50816 | Linux Kernel up to 6.0.6 ipv6 net/core/skbuff.c ip6gre_tnl_link_config_route mtu state issue (Nessus ID 298924)
1 day 2 hours ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.0.6. Affected by this issue is the function ip6gre_tnl_link_config_route of the file net/core/skbuff.c of the component ipv6. Performing a manipulation of the argument mtu results in state issue.
This vulnerability is reported as CVE-2022-50816. The attacker must have access to the local network to execute the attack. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-50580 | Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2 tg_with_in_bps_limit privilege escalation (Nessus ID 298924 / WID-SEC-2025-2394)
1 day 2 hours ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2. The affected element is the function tg_with_in_bps_limit. Such manipulation leads to privilege escalation.
This vulnerability is traded as CVE-2022-50580. Access to the local network is required for this attack to succeed. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-71120 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc2 SUNRPC svcauth_gss null pointer dereference (EUVD-2026-2494 / Nessus ID 298928)
1 day 2 hours ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc2. The impacted element is the function svcauth_gss of the component SUNRPC. Such manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2025-71120. Access to the local network is required for this attack to succeed. There is no exploit available.
You should upgrade the affected component.
vuldb.com
The Human Element: Turning Threat Actor OPSEC Fails into Investigative Breakthroughs
1 day 3 hours ago
In this post, we explore how the psychological traps of operational security can unmask even the most sophisticated actors.
The post The Human Element: Turning Threat Actor OPSEC Fails into Investigative Breakthroughs appeared first on Flashpoint.
The post The Human Element: Turning Threat Actor OPSEC Fails into Investigative Breakthroughs appeared first on Security Boulevard.
Flashpoint
CVE-2025-38628 | Linux Kernel up to 6.12.41/6.15.9/6.16.0 vdpa mlx5_vdpa_free uninitialized resource (Nessus ID 270575 / WID-SEC-2025-1898)
1 day 3 hours ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.12.41/6.15.9/6.16.0. This affects the function mlx5_vdpa_free of the component vdpa. Executing a manipulation can lead to uninitialized resource.
This vulnerability is handled as CVE-2025-38628. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-38630 | Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0 fbdev fb_add_videomode return null pointer dereference (Nessus ID 276629 / WID-SEC-2025-1898)
1 day 3 hours ago
A vulnerability was found in Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0. It has been classified as critical. This affects the function fb_add_videomode of the component fbdev. Performing a manipulation of the argument return results in null pointer dereference.
This vulnerability is identified as CVE-2025-38630. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-38629 | Linux Kernel up to 6.15.9/6.16.0 ALSA scarlett2_input_select_ctl_info null pointer dereference (Nessus ID 260284 / WID-SEC-2025-1898)
1 day 3 hours ago
A vulnerability has been found in Linux Kernel up to 6.15.9/6.16.0 and classified as critical. This vulnerability affects the function scarlett2_input_select_ctl_info of the component ALSA. Performing a manipulation results in null pointer dereference.
This vulnerability was named CVE-2025-38629. The attack needs to be approached within the local network. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2025-38625 | Linux Kernel up to 6.6.101/6.12.41/6.15.9/6.16.0 privilege escalation (Nessus ID 270575 / WID-SEC-2025-1898)
1 day 3 hours ago
A vulnerability was found in Linux Kernel up to 6.6.101/6.12.41/6.15.9/6.16.0. It has been classified as critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in privilege escalation.
This vulnerability was named CVE-2025-38625. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-38627 | Linux Kernel up to 6.16.0 f2fs f2fs_inode_info use after free (WID-SEC-2025-1898)
1 day 3 hours ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.16.0. This affects the function f2fs_inode_info of the component f2fs. Such manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2025-38627. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2025-38626 | Linux Kernel up to 6.6.101/6.12.41/6.15.9/6.16.0 f2fs f2fs_map_blocks allocation of resources (Nessus ID 260275 / WID-SEC-2025-1898)
1 day 3 hours ago
A vulnerability marked as critical has been reported in Linux Kernel up to 6.6.101/6.12.41/6.15.9/6.16.0. This vulnerability affects the function f2fs_map_blocks of the component f2fs. This manipulation causes allocation of resources.
This vulnerability is registered as CVE-2025-38626. The attack requires access to the local network. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-38623 | Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0 pci_bus_to_OF_node denial of service (Nessus ID 270738 / WID-SEC-2025-1898)
1 day 3 hours ago
A vulnerability was found in Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0. It has been rated as critical. Affected by this issue is the function pci_bus_to_OF_node. Performing a manipulation results in denial of service.
This vulnerability is cataloged as CVE-2025-38623. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-38624 | Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0 kernel/irq/msi.c pci_hp_remove_devices denial of service (Nessus ID 260280 / WID-SEC-2025-1898)
1 day 3 hours ago
A vulnerability was found in Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0 and classified as critical. This impacts the function pci_hp_remove_devices of the file kernel/irq/msi.c. The manipulation results in denial of service.
This vulnerability is identified as CVE-2025-38624. The attack can only be performed from the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-38622 | Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0 net net/core/skbuff.c udp_rcv_segment denial of service (Nessus ID 266176 / WID-SEC-2025-1898)
1 day 3 hours ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0. This issue affects the function udp_rcv_segment of the file net/core/skbuff.c of the component net. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2025-38622. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
Go语言逆向工程实战 - 从数据结构到CTF解题
1 day 3 hours ago
Go 语言作为一门新兴的编译型语言,近年来在云计算、微服务、区块链等领域得到了广泛应用。随着 Go 语言的普及,越来越多的程序开始使用 Go 语言编写,这也使得 Go 语言逆向成为了一个新的研究方向。Go 语言类似于 C 语言,编译后的目标文件是一个二进制文件,逆向的也是 native 代码,但是 Go 语言有一些独特的特性使得它的逆向分析既有挑战性又有一定的便利性
CVE-2023-46005 | SourceCodester Best Courier Management System 1.0 /edit_branch.php ID sql injection (EUVD-2023-50267)
1 day 3 hours ago
A vulnerability has been found in SourceCodester Best Courier Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit_branch.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is documented as CVE-2023-46005. The attack requires being on the local network. There is not any exploit available.
vuldb.com
CVE-2023-46004 | SourceCodester Best Courier Management System 1.0 update_user unrestricted upload (EUVD-2023-50266)
1 day 3 hours ago
A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been declared as problematic. The affected element is the function update_user. Such manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2023-46004. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com