Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54755
Total
4323
Critical
16270
High
16026
Medium
CVE ID Severity Score Description Published
CVE-2026-93217 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: mm/madvise: skip device-private PMDs in cold and pageout walks madvise_cold_or_pageout_pte_range() takes pmd_trans_huge_lock(), whose pmd_is_huge() check … Sep 24, 2026
CVE-2026-93216 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg() print_page_owner_memcg() reads page->memcg_data via READ_ONCE() at … Sep 24, 2026
CVE-2026-93215 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: cdx: Fix double free when sysfs file creation fails In cdx_create_res_attr(), if sysfs_create_bin_file() fails, the … Sep 24, 2026
CVE-2026-93214 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() usbg_make_tpg() held dep_lock while calling configfs_depend_item_unlocked(), which acquires … Sep 24, 2026
CVE-2026-93213 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: of: fix out-of-bounds read in of_alias_scan() stem parser The stem parser tests isdigit(*(end - 1)) … Sep 24, 2026
CVE-2026-93212 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: nfsd: guard nfsd_serv deref in nfsd_file_net_dispose nfsd_file_net_dispose() is the consumer side of l->freeme: the nfsd … Sep 24, 2026
CVE-2026-93211 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize DRC hash table before registering shrinker shrinker_register() precedes the INIT_LIST_HEAD loop and the … Sep 24, 2026
CVE-2026-93210 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: smb: client: harden DFS cache against invalid target hints Currently, get_tgt_name() returns ERR_PTR(-ENOENT) when ce->tgthint … Sep 24, 2026
CVE-2026-93209 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb BT enable fails intermittently with -ETIMEDOUT … Sep 24, 2026
CVE-2026-93208 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: kasan: fix cache shrink race with CPU hotplug kasan_quarantine_remove_cache() first invokes per_cpu_remove_cache() on all online … Sep 24, 2026
CVE-2026-93207 CRITICAL 9.8 In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry svcauth_gss_decode_credbody() writes the caller's rpc_gss_wire_cred field by field and … Sep 24, 2026
CVE-2026-93206 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: PCI/proc: Use file_ns_capable() when checking config space read access proc_bus_pci_read() decides how much of the … Sep 24, 2026
CVE-2026-93205 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Manage teardown with devm arm_smmu_device_remove() manually frees the IOPF queue, destroys the vmid_map and … Sep 24, 2026
CVE-2026-92680 MEDIUM 5.5 Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. … Sep 24, 2026
CVE-2026-88371 UNKNOWN — ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code 128 decode6() function. When processing specially crafted Code 128 input, decode_e() can return -1 for … Sep 24, 2026
CVE-2026-88370 UNKNOWN — libconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and strip_ini_cache(). The bundled utility allocates exactly ini_length bytes, while strip_ini_cache() unconditionally … Sep 24, 2026
CVE-2026-88369 UNKNOWN — zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump(). Sep 24, 2026
CVE-2026-88368 HIGH 7.5 NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() function. A specially crafted SVG document containing sufficiently large geometry coordinates can … Sep 24, 2026
CVE-2026-88366 UNKNOWN — NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG arc commands. A specially crafted SVG document containing extreme arc radius … Sep 24, 2026
CVE-2026-88365 UNKNOWN — minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-size field. Sep 24, 2026
CVE-2026-88362 UNKNOWN — MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted JavaScript input containing an excessively large numeric array index can … Sep 24, 2026
CVE-2026-88361 UNKNOWN — SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineMupdf::BuildPageLabelRec() when parsing PDF PageLabels /Nums entries. Sep 24, 2026
CVE-2026-88358 UNKNOWN — simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafted truncated JSON document whose final structural token closes a nested array or … Sep 24, 2026
CVE-2026-88357 HIGH 7.5 nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd … Sep 24, 2026
CVE-2026-88355 UNKNOWN — An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression nodes, including constants, variables, and zero-argument functions, the function … Sep 24, 2026