Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56890
Total
4508
Critical
16896
High
16708
Medium
CVE ID Severity Score Description Published
CVE-2026-90023 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() Previously fsg_num_buffers_validate() was removed as it … Sep 16, 2026
CVE-2026-90022 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi2: fix use-after-free in string attribute show path f_midi2_opts_str_show() takes the string lock … Sep 16, 2026
CVE-2026-90021 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: initialize work in f_midi_alloc() f_midi_alloc initializes free_ref to 1 and it can … Sep 16, 2026
CVE-2026-90020 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() gadget_dev_ioctl() reads dev->gadget before acquiring dev->lock, but … Sep 16, 2026
CVE-2026-90019 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: usb: gadget: fix null pointer dereference in usb_put_function_instance() usb_put_function_instance() attempts to dereference fd inside fi … Sep 16, 2026
CVE-2026-90018 HIGH 8.8 In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() rtw_get_wps_attr() walks WPS attributes inside … Sep 16, 2026
CVE-2026-90017 HIGH 7.1 In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() rtw_action_frame_parse() takes a frame_len parameter but never actually … Sep 16, 2026
CVE-2026-90016 HIGH 7.1 In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() rtw_restruct_wmm_ie() scans in_ie for a WMM IE with: … Sep 16, 2026
CVE-2026-90015 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: xhci: fix lost bounce buffers on TDs spanning several ring segments When a TD reaches … Sep 16, 2026
CVE-2026-90014 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: tracing: Have show_event_filters/triggers files take trace array ref The newly added files show_event_filters and show_event_triggers … Sep 16, 2026
CVE-2026-90013 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: tracing: Take trace_array reference when opening options file The options files do not take the … Sep 16, 2026
CVE-2026-90012 CRITICAL 9.8 In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership on partial map failure If RX mapping fails after TX … Sep 16, 2026
CVE-2026-90011 CRITICAL 9.1 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a terminator byte for the login payload iscsi_target_check_login_request() rejects a login … Sep 16, 2026
CVE-2026-90010 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Cap io_uring sense copy to max_response_len Completion copied scmd->sense_len to the user response … Sep 16, 2026
CVE-2026-90009 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Fix TOCTOU in io_uring passthrough command setup scsi_bsg_uring_cmd() reads bsg_uring_cmd from the shared … Sep 16, 2026
CVE-2026-90008 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame megasas_make_prp_nvme() builds a command's … Sep 16, 2026
CVE-2026-90007 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Use rollback index when freeing MSI-X vectors pm8001_request_msix() unwinds previously registered handlers with … Sep 16, 2026
CVE-2026-90006 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: samples/damon/mtier: handle damon_stop() failure damon_sample_mtier_stop() assumes its damon_stop() call will always successfully stops the two … Sep 16, 2026
CVE-2026-90005 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: samples/damon/wsse: handle damon_start() failure Patch series "samples/damon: handle damon_{start,stop}() failures". All DAMON sample modules are … Sep 16, 2026
CVE-2026-90004 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: handle region split failure in apply_min_nr_regions() damon_apply_min_nr_regions() repeatedly split each region until its size … Sep 16, 2026
CVE-2026-90003 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: futex: Prevent rcuwait use-after-free during requeue PI On PREEMPT_RT, FUTEX_CMP_REQUEUE_PI can trigger a KASAN report … Sep 16, 2026
CVE-2026-90002 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: ftrace: Take trace_array reference before accessing its ftrace_ops The trace instance files set_ftrace_filter and set_ftrace_notrace … Sep 16, 2026
CVE-2026-90001 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: HID: bpf: serialize device reference release in struct_ops destroy path __hid_bpf_ops_destroy_device() and hid_bpf_unreg() can race … Sep 16, 2026
CVE-2026-90000 HIGH 8.8 In the Linux kernel, the following vulnerability has been resolved: HID: rmi: fix OOB access with undersized RMI reports The hid-rmi driver sizes its writeReport/readReport … Sep 16, 2026
CVE-2026-8462 UNKNOWN — SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event … Sep 16, 2026