Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54499
Total
4309
Critical
16193
High
15930
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97544 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfs: don't leak dqacct if rhashtable insertion fails LOLLM observes that xqcheck_mod_live_ino_dqtrx doesn't free the … | Sep 25, 2026 |
| CVE-2026-97543 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfs: destroy seen inode bitmap when we fail to add a dirpath LOLLM observes a … | Sep 25, 2026 |
| CVE-2026-97542 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfs: bail out on bitmap errors in xrep_agfl_fill LOLLM also points out that the xagb_bitmap_set … | Sep 25, 2026 |
| CVE-2026-97541 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k_htc: don't store usb_device_id usb_device_id is not guaranteed to live longer than probe due … | Sep 25, 2026 |
| CVE-2026-97540 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: don't rely on id table pointer arithmetic The current code is broken … | Sep 25, 2026 |
| CVE-2026-97539 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: xusbatm: don't rely on id table pointer arithmetic The current code is broken when … | Sep 25, 2026 |
| CVE-2026-97538 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: hwmon: (asus_rog_ryujin) Validate HID report lengths rog_ryujin_raw_event() parses response headers and payload fields without first … | Sep 25, 2026 |
| CVE-2026-97537 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking qla25xx_free_req_que() and qla25xx_free_rsp_que() have two … | Sep 25, 2026 |
| CVE-2026-97536 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix use-after-free of qpair work on queue teardown The response queue MSI-X handler … | Sep 25, 2026 |
| CVE-2026-97535 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size The VP control IOCB selects … | Sep 25, 2026 |
| CVE-2026-97534 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: f2fs: accurately adjust free_sections during free_segment_range In free_segment_range(), MAIN_SECS(sbi) is temporarily reduced by `secs` to … | Sep 25, 2026 |
| CVE-2026-97533 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Acquire init_mm read lock on attribute changes to avoid UAF A previous commit protected … | Sep 25, 2026 |
| CVE-2026-97532 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path When qla2x00_mem_alloc() fails, qla2x00_probe_one() jumps … | Sep 25, 2026 |
| CVE-2026-97531 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Skip vport under deletion in report ID acquisition qla24xx_report_id_acquisition() format-1 handling walks ha->vp_list … | Sep 25, 2026 |
| CVE-2026-97530 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature qla27xx_copy_multiple_pkt() and qla27xx_copy_fpin_pkt() poll rsp_q->ring_ptr->signature for … | Sep 25, 2026 |
| CVE-2026-97529 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[] The FC BSG transport allocates job->request via … | Sep 25, 2026 |
| CVE-2026-97528 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error qla_nvme_xmt_ls_rsp() obtains uctx, … | Sep 25, 2026 |
| CVE-2026-97527 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock The fcport->unsol_ctx_head list is … | Sep 25, 2026 |
| CVE-2026-97526 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: s390/pai: Support CPU hotplug for PMU PAI The command 'perf stat -e pai_crypto/CRYPTO_ALL/ -- <command>' … | Sep 25, 2026 |
| CVE-2026-97525 | HIGH | 8.2 | In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Allocate split page tables as kernel page tables A PTE is allocated directly without … | Sep 25, 2026 |
| CVE-2026-97524 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid unneeded actions on subflow reset Once in a blue moon, the mptcp receive … | Sep 25, 2026 |
| CVE-2026-97523 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: mptcp: close race between scheduler and state change The mptcp scheduler may race with subflow … | Sep 25, 2026 |
| CVE-2026-97522 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix bad accounting in __mptcp_subflow_push_pending() If __subflow_push_pending() errors out we should avoid updating the … | Sep 25, 2026 |
| CVE-2026-97228 | LOW | 2.7 | Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src/export_manager.py`), whereby the `export_id` … | Sep 25, 2026 |
| CVE-2026-27867 | UNKNOWN | — | An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action is required) who has the … | Sep 25, 2026 |