Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54755
Total
4323
Critical
16270
High
16026
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93217 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/madvise: skip device-private PMDs in cold and pageout walks madvise_cold_or_pageout_pte_range() takes pmd_trans_huge_lock(), whose pmd_is_huge() check … | Sep 24, 2026 |
| CVE-2026-93216 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg() print_page_owner_memcg() reads page->memcg_data via READ_ONCE() at … | Sep 24, 2026 |
| CVE-2026-93215 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: cdx: Fix double free when sysfs file creation fails In cdx_create_res_attr(), if sysfs_create_bin_file() fails, the … | Sep 24, 2026 |
| CVE-2026-93214 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() usbg_make_tpg() held dep_lock while calling configfs_depend_item_unlocked(), which acquires … | Sep 24, 2026 |
| CVE-2026-93213 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: of: fix out-of-bounds read in of_alias_scan() stem parser The stem parser tests isdigit(*(end - 1)) … | Sep 24, 2026 |
| CVE-2026-93212 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: nfsd: guard nfsd_serv deref in nfsd_file_net_dispose nfsd_file_net_dispose() is the consumer side of l->freeme: the nfsd … | Sep 24, 2026 |
| CVE-2026-93211 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize DRC hash table before registering shrinker shrinker_register() precedes the INIT_LIST_HEAD loop and the … | Sep 24, 2026 |
| CVE-2026-93210 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: harden DFS cache against invalid target hints Currently, get_tgt_name() returns ERR_PTR(-ENOENT) when ce->tgthint … | Sep 24, 2026 |
| CVE-2026-93209 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb BT enable fails intermittently with -ETIMEDOUT … | Sep 24, 2026 |
| CVE-2026-93208 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: kasan: fix cache shrink race with CPU hotplug kasan_quarantine_remove_cache() first invokes per_cpu_remove_cache() on all online … | Sep 24, 2026 |
| CVE-2026-93207 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry svcauth_gss_decode_credbody() writes the caller's rpc_gss_wire_cred field by field and … | Sep 24, 2026 |
| CVE-2026-93206 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: PCI/proc: Use file_ns_capable() when checking config space read access proc_bus_pci_read() decides how much of the … | Sep 24, 2026 |
| CVE-2026-93205 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Manage teardown with devm arm_smmu_device_remove() manually frees the IOPF queue, destroys the vmid_map and … | Sep 24, 2026 |
| CVE-2026-92680 | MEDIUM | 5.5 | Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. … | Sep 24, 2026 |
| CVE-2026-88371 | UNKNOWN | — | ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code 128 decode6() function. When processing specially crafted Code 128 input, decode_e() can return -1 for … | Sep 24, 2026 |
| CVE-2026-88370 | UNKNOWN | — | libconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and strip_ini_cache(). The bundled utility allocates exactly ini_length bytes, while strip_ini_cache() unconditionally … | Sep 24, 2026 |
| CVE-2026-88369 | UNKNOWN | — | zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump(). | Sep 24, 2026 |
| CVE-2026-88368 | HIGH | 7.5 | NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() function. A specially crafted SVG document containing sufficiently large geometry coordinates can … | Sep 24, 2026 |
| CVE-2026-88366 | UNKNOWN | — | NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG arc commands. A specially crafted SVG document containing extreme arc radius … | Sep 24, 2026 |
| CVE-2026-88365 | UNKNOWN | — | minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-size field. | Sep 24, 2026 |
| CVE-2026-88362 | UNKNOWN | — | MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted JavaScript input containing an excessively large numeric array index can … | Sep 24, 2026 |
| CVE-2026-88361 | UNKNOWN | — | SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineMupdf::BuildPageLabelRec() when parsing PDF PageLabels /Nums entries. | Sep 24, 2026 |
| CVE-2026-88358 | UNKNOWN | — | simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafted truncated JSON document whose final structural token closes a nested array or … | Sep 24, 2026 |
| CVE-2026-88357 | HIGH | 7.5 | nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd … | Sep 24, 2026 |
| CVE-2026-88355 | UNKNOWN | — | An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression nodes, including constants, variables, and zero-argument functions, the function … | Sep 24, 2026 |