Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54755
Total
4323
Critical
16270
High
16026
Medium
CVE ID Severity Score Description Published
CVE-2026-97226 MEDIUM 6.3 A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The … Sep 24, 2026
CVE-2026-97225 MEDIUM 6.3 A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON Runner. Executing … Sep 24, 2026
CVE-2026-96873 UNKNOWN — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch … Sep 24, 2026
CVE-2026-96750 HIGH 7.1 MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from … Sep 24, 2026
CVE-2026-96746 MEDIUM 6.5 An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of … Sep 24, 2026
CVE-2026-96745 MEDIUM 5.6 Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored … Sep 24, 2026
CVE-2026-96744 HIGH 7.1 Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock … Sep 24, 2026
CVE-2026-93541 MEDIUM 6.5 An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a Sep 24, 2026
CVE-2026-93425 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into … Sep 24, 2026
CVE-2026-93283 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When device_register() fails in i3c_master_register_new_i3c_devs(), put_device() is called to … Sep 24, 2026
CVE-2026-93282 HIGH 8.1 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE matching … Sep 24, 2026
CVE-2026-93281 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix HE extended capability length check rtw89_mac_check_he_obss_narrow_bw_ru_iter() reads extended capability byte 10, but … Sep 24, 2026
CVE-2026-93280 HIGH 8.8 In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes against the fetched size gb_audio_gb_get_topology() fetches a topology … Sep 24, 2026
CVE-2026-93279 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown The TX cleanup tasklet can be scheduled by … Sep 24, 2026
CVE-2026-93278 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown cvm_oct_rx_shutdown calls free_irq and netif_napi_del without disabling the … Sep 24, 2026
CVE-2026-93277 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Validate udata before executing commands The destroy callbacks currently zero the udata output after … Sep 24, 2026
CVE-2026-93276 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator devm_regulator_get_exclusive() initialises the regulator … Sep 24, 2026
CVE-2026-93275 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/pt: Fix stop/start with no update If pt_event_stop() is called without PERF_EF_UPDATE flag, then perf_aux_output_end() … Sep 24, 2026
CVE-2026-93274 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: pinctrl: bcm2835: Don't remove an unregistered GPIO chip If the devm_pinctrl_register() function fails, bcm2835_pinctrl_probe() calls … Sep 24, 2026
CVE-2026-93273 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: regulator: tps6594: Fix device node reference leaks in multiphase loop In tps6594_regulator_probe(), the multi-phase configuration … Sep 24, 2026
CVE-2026-93272 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3 The changes introduced to … Sep 24, 2026
CVE-2026-93271 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate ath11k can receive HT/VHT/HE … Sep 24, 2026
CVE-2026-93270 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn The BPF_MOV64_PERCPU_REG insn requires JIT to emit native … Sep 24, 2026
CVE-2026-93269 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: ext4: fix circular lock dependency in ext4_ext_migrate Move iput(tmp_inode) after ext4_writepages_up_write() to avoid a circular … Sep 24, 2026
CVE-2026-93268 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: ext4: skip extra isize expansion during mount to prevent deadlock ext4_try_to_expand_extra_isize() is called from __ext4_mark_inode_dirty() … Sep 24, 2026