Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54449
Total
4308
Critical
16178
High
15893
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100072 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ACPI: platform: Use acpi_bus_get_primary_device() The acpi_get_first_physical_node() usage in acpi_platform_fill_resource() and acpi_create_platform_device() is generally unsafe because … | Sep 25, 2026 |
| CVE-2026-100071 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: hsr: free learned nodes on device setup failure hsr_dev_finalize() can fail after a lower-device … | Sep 25, 2026 |
| CVE-2026-100070 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet sashiko says: If map_addr() changes the … | Sep 25, 2026 |
| CVE-2026-95832 | UNKNOWN | — | Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 … | Sep 25, 2026 |
| CVE-2026-88421 | HIGH | 7.5 | Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, … | Sep 25, 2026 |
| CVE-2026-88420 | UNKNOWN | — | A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.save() component of APSL puput v1.2.1 through v2.2.0 allows authenticated attackers with Wagtail Editor privileges to execute … | Sep 25, 2026 |
| CVE-2026-79153 | HIGH | 7.8 | Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated … | Sep 25, 2026 |
| CVE-2026-78902 | MEDIUM | 6.1 | Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package | Sep 25, 2026 |
| CVE-2026-52622 | HIGH | 7.5 | An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain … | Sep 25, 2026 |
| CVE-2026-51773 | HIGH | 8.1 | An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external … | Sep 25, 2026 |
| CVE-2026-51772 | UNKNOWN | — | A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an … | Sep 25, 2026 |
| CVE-2025-51457 | HIGH | 8.8 | D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint. An attacker with authenticated access can … | Sep 25, 2026 |
| CVE-2026-97622 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-62062. Reason: This candidate is a reservation duplicate of CVE-2026-62062. Notes: All CVE … | Sep 25, 2026 |
| CVE-2026-98159 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: validate CLC firmware records The CLC region is supplied by firmware, but … | Sep 25, 2026 |
| CVE-2026-98158 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ppp_async: drop the errored frame instead of resetting its headroom ppp_receive_nonmp_frame() prepends a two-byte direction … | Sep 25, 2026 |
| CVE-2026-98157 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation The poll_msec sysfs store file uses simple_strtoul() … | Sep 25, 2026 |
| CVE-2026-98156 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: drm/virtio: use the DMA API for resource backing on Xen On a Xen PV domain … | Sep 25, 2026 |
| CVE-2026-98155 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Address potential out-of-bounds read in resp_worker() Although 'commit 2feec5ae5df7 ("accel/qaic: Handle DBC deactivation if … | Sep 25, 2026 |
| CVE-2026-98154 | HIGH | 7.0 | In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix -EIO cleanup order in queue_rq On -EIO, the RDMA queue_rq path reports a … | Sep 25, 2026 |
| CVE-2026-98153 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: nvme: fix racy access to FDP placement id array nvme_query_fdp_info() is called per-path and therefore … | Sep 25, 2026 |
| CVE-2026-98152 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: fix queue leak when connect backlog is exceeded When pending disconnecting queues exceed the … | Sep 25, 2026 |
| CVE-2026-98151 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic Take the following unprivileged program as … | Sep 25, 2026 |
| CVE-2026-98150 | HIGH | 7.0 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix BPF_F_CPU validation for sparse CPU IDs BPF_F_CPU stores the target CPU ID in … | Sep 25, 2026 |
| CVE-2026-98149 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix percpu map update indexing with sparse CPU IDs Per-CPU array, hash, and cgroup … | Sep 25, 2026 |
| CVE-2026-98148 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/gud: validate GUD_ROTATION_0 is present in supported rotations The rotation argument to drm_plane_create_rotation_property() is set … | Sep 25, 2026 |