Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54449
Total
4308
Critical
16178
High
15893
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93834 | HIGH | 8.8 | A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and … | Sep 25, 2026 |
| CVE-2026-93647 | CRITICAL | 9.3 | An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing … | Sep 25, 2026 |
| CVE-2026-93643 | CRITICAL | 9.8 | When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform … | Sep 25, 2026 |
| CVE-2026-93642 | CRITICAL | 9.3 | An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to … | Sep 25, 2026 |
| CVE-2026-93641 | CRITICAL | 9.3 | An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to … | Sep 25, 2026 |
| CVE-2026-85750 | HIGH | 7.2 | Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient … | Sep 25, 2026 |
| CVE-2026-85542 | HIGH | 8.8 | IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted … | Sep 25, 2026 |
| CVE-2026-85029 | HIGH | 7.5 | IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation … | Sep 25, 2026 |
| CVE-2026-84893 | HIGH | 7.6 | IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information … | Sep 25, 2026 |
| CVE-2026-84884 | HIGH | 7.5 | IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential … | Sep 25, 2026 |
| CVE-2026-80431 | UNKNOWN | — | Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal … | Sep 25, 2026 |
| CVE-2026-80430 | UNKNOWN | — | Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows … | Sep 25, 2026 |
| CVE-2026-100190 | UNKNOWN | — | The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically item IDs, … | Sep 25, 2026 |
| CVE-2026-100187 | UNKNOWN | — | The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on … | Sep 25, 2026 |
| CVE-2026-100177 | UNKNOWN | — | The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot … | Sep 25, 2026 |
| CVE-2026-100176 | UNKNOWN | — | The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported from chats and crawled forums are stored without character restrictions. … | Sep 25, 2026 |
| CVE-2026-100174 | UNKNOWN | — | The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS). A user with the ability to create a custom tag could … | Sep 25, 2026 |
| CVE-2026-100172 | UNKNOWN | — | The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/templates/chats_explorer/block_message.html … | Sep 25, 2026 |
| CVE-2026-100079 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: unregister debugfs entries on teardown ucsi_register() creates per-instance debugfs entries, but ucsi_unregister() … | Sep 25, 2026 |
| CVE-2026-100078 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: pass correct argument to function The first argument to iwl_mei_write_cyclic_buf() should be … | Sep 25, 2026 |
| CVE-2026-100077 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Recover HW before retire hung submit During recovery, it is not safe to retire … | Sep 25, 2026 |
| CVE-2026-100076 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths issue_beacon(), issue_probersp() and issue_asocrsp() obtain a … | Sep 25, 2026 |
| CVE-2026-100075 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the … | Sep 25, 2026 |
| CVE-2026-100074 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Mark bpf_refcount field as unique BPF_REFCOUNT is not marked as a unique field, while … | Sep 25, 2026 |
| CVE-2026-100073 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ext4: fix transaction overflow during writeback Commit 95ad8ee45cdb ("ext4: correct the reserved credits for extent … | Sep 25, 2026 |