Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54704
Total
4321
Critical
16261
High
15994
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97408 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate connectionless PSM length Connectionless L2CAP frames carry a two-byte PSM at the … | Sep 24, 2026 |
| CVE-2026-97407 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt rockchip_pdm_set_fmt() calls pm_runtime_get_sync() before accessing … | Sep 24, 2026 |
| CVE-2026-97231 | HIGH | 7.3 | A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the component Socket.IO Connect Interface. … | Sep 24, 2026 |
| CVE-2026-94613 | HIGH | 7.5 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment … | Sep 24, 2026 |
| CVE-2026-94612 | HIGH | 7.4 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does … | Sep 24, 2026 |
| CVE-2026-94611 | HIGH | 8.1 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on … | Sep 24, 2026 |
| CVE-2026-94609 | HIGH | 8.8 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a … | Sep 24, 2026 |
| CVE-2026-94606 | HIGH | 8.9 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient … | Sep 24, 2026 |
| CVE-2026-94604 | UNKNOWN | — | Rejected reason: This CVE is a duplicate of another CVE. | Sep 24, 2026 |
| CVE-2026-94281 | MEDIUM | 6.5 | An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. | Sep 24, 2026 |
| CVE-2026-93830 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: xgmac2: disable RBUE in default RX interrupt mask Enabling the RX Buffer Unavailable … | Sep 24, 2026 |
| CVE-2026-93829 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix races in cifsd thread creation The cifsd demultiplex thread can run and … | Sep 24, 2026 |
| CVE-2026-93828 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: exfat: fix handling of damaged volume in exfat_create_upcase_table() When the size of the upcase table … | Sep 24, 2026 |
| CVE-2026-93827 | HIGH | 8.4 | In the Linux kernel, the following vulnerability has been resolved: virtio-fs: avoid double-free on failed queue setup virtio_fs_setup_vqs() allocates fs->vqs and fs->mq_map before calling virtio_find_vqs(). … | Sep 24, 2026 |
| CVE-2026-93826 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: HID: hidpp: fix potential UAF in hidpp_connect_event() If input_register_device() fails, we call input_free_device(), but keep … | Sep 24, 2026 |
| CVE-2026-93825 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data() Prevent NULL pointer dereference when spi_get_device_id() returns … | Sep 24, 2026 |
| CVE-2026-93824 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tls: reject the combination of TLS and sockmap TLS and sockmap (BPF psock) integration hides … | Sep 24, 2026 |
| CVE-2026-93823 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Let driver decide buffer size at AMDKFD_IOC_GET_DMABUF_INFO ioctl amdkfd driver needs allocate buffer to … | Sep 24, 2026 |
| CVE-2026-93822 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: PCI: iproc: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock lock while stopping … | Sep 24, 2026 |
| CVE-2026-93821 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: PCI: altera: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock lock while stopping … | Sep 24, 2026 |
| CVE-2026-93820 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: PCI: rockchip: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock lock while stopping … | Sep 24, 2026 |
| CVE-2026-93819 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: PCI: mediatek: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock lock while stopping … | Sep 24, 2026 |
| CVE-2026-93818 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock lock while stopping … | Sep 24, 2026 |
| CVE-2026-93817 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: perf: Fix addr_filter_ranges lifetime Lee Jia Jie reported that since event::addr_filter_ranges is used under RCU, … | Sep 24, 2026 |
| CVE-2026-93816 | HIGH | 7.1 | In the Linux kernel, the following vulnerability has been resolved: f2fs: validate inline dentry name lengths before conversion Inline dentry conversion copies names out of … | Sep 24, 2026 |