Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56576
Total
4483
Critical
16766
High
16609
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-90060 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Don't add invalid kcontrols to LED layer The kcontrol LED state layer tries … | Sep 17, 2026 |
| CVE-2026-90059 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: restore NET_IP_ALIGN in the RX DMA offset Since the RX path was converted … | Sep 17, 2026 |
| CVE-2026-90058 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup qdisc_get_stab() accepts a user-supplied size table, and … | Sep 17, 2026 |
| CVE-2026-90057 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: slip: remove slip_hangup() to fix use-after-free in slip_receive_buf() Jaeyoung Chung and Eulgyu Kim reported a … | Sep 17, 2026 |
| CVE-2026-90056 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: fec: only stop PTP if it was initialized fec_ptp_init() is only called when fep->bufdesc_ex … | Sep 17, 2026 |
| CVE-2026-90055 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: atm: usbatm: fix invalid ci_range initialization syzbot reported a shift-out-of-bounds in __vcc_connect(): UBSAN: shift-out-of-bounds … | Sep 17, 2026 |
| CVE-2026-90054 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tcp: fix corruption of urgent data on multi-segment retransmit On the normal xmit path, while … | Sep 17, 2026 |
| CVE-2026-90053 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_htb: limit htb_classify inner-class filter hops htb_classify() follows each filter-selected inner class by switching … | Sep 17, 2026 |
| CVE-2026-90052 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix buffer overflow with keyed discard Since commit 68c5c42567bc ("dm-integrity: replace forgeable discard filler … | Sep 17, 2026 |
| CVE-2026-90051 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tcp: reject non zerocopy devmem tx Devmem tcp tx doesn't work without zero-copy, however it's … | Sep 17, 2026 |
| CVE-2026-90050 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net/sched: fq: clamp quantum and initial_quantum in change path The fq change path accepts TCA_FQ_QUANTUM … | Sep 17, 2026 |
| CVE-2026-8674 | MEDIUM | 5.3 | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or … | Sep 17, 2026 |
| CVE-2026-85720 | MEDIUM | 5.9 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request … | Sep 17, 2026 |
| CVE-2026-85716 | LOW | 3.7 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute … | Sep 17, 2026 |
| CVE-2026-54587 | UNKNOWN | — | mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. … | Sep 17, 2026 |
| CVE-2026-54586 | UNKNOWN | — | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without … | Sep 17, 2026 |
| CVE-2026-54585 | UNKNOWN | — | mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive … | Sep 17, 2026 |
| CVE-2026-54583 | UNKNOWN | — | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download … | Sep 17, 2026 |
| CVE-2026-54582 | UNKNOWN | — | mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The … | Sep 17, 2026 |
| CVE-2026-54581 | UNKNOWN | — | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing … | Sep 17, 2026 |
| CVE-2026-54580 | UNKNOWN | — | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c … | Sep 17, 2026 |
| CVE-2026-54579 | UNKNOWN | — | mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using … | Sep 17, 2026 |
| CVE-2026-54578 | UNKNOWN | — | mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with … | Sep 17, 2026 |
| CVE-2026-54577 | UNKNOWN | — | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument … | Sep 17, 2026 |
| CVE-2026-54576 | UNKNOWN | — | mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A … | Sep 17, 2026 |