Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56890
Total
4508
Critical
16896
High
16708
Medium
CVE ID Severity Score Description Published
CVE-2026-89799 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in bpf_get_stackid The get_perf_callchain call needs disabled preemption plus we need it … Sep 16, 2026
CVE-2026-89798 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: rpcrdma: arm rn_done before publishing the notification rpcrdma_rn_register() inserts @rn into rd_xa with xa_alloc() before … Sep 16, 2026
CVE-2026-89797 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: power: supply: ab8500_fg: fix use-after-free on remove ab8500_fg_remove() destroys the driver workqueue while the threaded … Sep 16, 2026
CVE-2026-89796 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: avoid infinite kdamond_merge_regions() internal loop Patch series "mm/damon: unurgent fixes for infinite loop, NULL … Sep 16, 2026
CVE-2026-89795 HIGH 8.4 In the Linux kernel, the following vulnerability has been resolved: PCI: Allow per function PCI slots to fix slot reset on s390 On s390 systems, … Sep 16, 2026
CVE-2026-89794 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: ksmbd: zero pipe read compound padding Compound response handling extends the last response iov to … Sep 16, 2026
CVE-2026-86585 UNKNOWN — The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls … Sep 16, 2026
CVE-2026-86107 MEDIUM 5.9 The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP … Sep 16, 2026
CVE-2026-86106 CRITICAL 9.6 An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command … Sep 16, 2026
CVE-2026-14916 UNKNOWN — A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected … Sep 16, 2026
CVE-2026-89793 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: ublk: clear VM_MAYWRITE on read-only ublk char device mmap ublk_ch_mmap() rejects mmap requests with VM_WRITE … Sep 16, 2026
CVE-2026-86792 UNKNOWN — Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with … Sep 16, 2026
CVE-2026-86474 UNKNOWN — The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to … Sep 16, 2026
CVE-2026-86466 UNKNOWN — Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it … Sep 16, 2026
CVE-2026-86443 UNKNOWN — Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device … Sep 16, 2026
CVE-2026-85628 UNKNOWN — Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior … Sep 16, 2026
CVE-2026-84501 MEDIUM 5.3 An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). … Sep 16, 2026
CVE-2026-84439 UNKNOWN — When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with … Sep 16, 2026
CVE-2026-82310 UNKNOWN — Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, … Sep 16, 2026
CVE-2026-79993 UNKNOWN — The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless … Sep 16, 2026
CVE-2026-77190 MEDIUM 6.5 On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse … Sep 16, 2026
CVE-2026-76187 UNKNOWN — Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client … Sep 16, 2026
CVE-2026-76186 UNKNOWN — Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak … Sep 16, 2026
CVE-2026-76151 UNKNOWN — Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through … Sep 16, 2026
CVE-2026-73469 MEDIUM 5.8 When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended … Sep 16, 2026