Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54755
Total
4323
Critical
16270
High
16026
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97226 | MEDIUM | 6.3 | A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The … | Sep 24, 2026 |
| CVE-2026-97225 | MEDIUM | 6.3 | A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON Runner. Executing … | Sep 24, 2026 |
| CVE-2026-96873 | UNKNOWN | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch … | Sep 24, 2026 |
| CVE-2026-96750 | HIGH | 7.1 | MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from … | Sep 24, 2026 |
| CVE-2026-96746 | MEDIUM | 6.5 | An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of … | Sep 24, 2026 |
| CVE-2026-96745 | MEDIUM | 5.6 | Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored … | Sep 24, 2026 |
| CVE-2026-96744 | HIGH | 7.1 | Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock … | Sep 24, 2026 |
| CVE-2026-93541 | MEDIUM | 6.5 | An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a | Sep 24, 2026 |
| CVE-2026-93425 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into … | Sep 24, 2026 |
| CVE-2026-93283 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When device_register() fails in i3c_master_register_new_i3c_devs(), put_device() is called to … | Sep 24, 2026 |
| CVE-2026-93282 | HIGH | 8.1 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE matching … | Sep 24, 2026 |
| CVE-2026-93281 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix HE extended capability length check rtw89_mac_check_he_obss_narrow_bw_ru_iter() reads extended capability byte 10, but … | Sep 24, 2026 |
| CVE-2026-93280 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes against the fetched size gb_audio_gb_get_topology() fetches a topology … | Sep 24, 2026 |
| CVE-2026-93279 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown The TX cleanup tasklet can be scheduled by … | Sep 24, 2026 |
| CVE-2026-93278 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown cvm_oct_rx_shutdown calls free_irq and netif_napi_del without disabling the … | Sep 24, 2026 |
| CVE-2026-93277 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Validate udata before executing commands The destroy callbacks currently zero the udata output after … | Sep 24, 2026 |
| CVE-2026-93276 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator devm_regulator_get_exclusive() initialises the regulator … | Sep 24, 2026 |
| CVE-2026-93275 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/pt: Fix stop/start with no update If pt_event_stop() is called without PERF_EF_UPDATE flag, then perf_aux_output_end() … | Sep 24, 2026 |
| CVE-2026-93274 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: pinctrl: bcm2835: Don't remove an unregistered GPIO chip If the devm_pinctrl_register() function fails, bcm2835_pinctrl_probe() calls … | Sep 24, 2026 |
| CVE-2026-93273 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: regulator: tps6594: Fix device node reference leaks in multiphase loop In tps6594_regulator_probe(), the multi-phase configuration … | Sep 24, 2026 |
| CVE-2026-93272 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3 The changes introduced to … | Sep 24, 2026 |
| CVE-2026-93271 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate ath11k can receive HT/VHT/HE … | Sep 24, 2026 |
| CVE-2026-93270 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn The BPF_MOV64_PERCPU_REG insn requires JIT to emit native … | Sep 24, 2026 |
| CVE-2026-93269 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ext4: fix circular lock dependency in ext4_ext_migrate Move iput(tmp_inode) after ext4_writepages_up_write() to avoid a circular … | Sep 24, 2026 |
| CVE-2026-93268 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ext4: skip extra isize expansion during mount to prevent deadlock ext4_try_to_expand_extra_isize() is called from __ext4_mark_inode_dirty() … | Sep 24, 2026 |