Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56890
Total
4508
Critical
16896
High
16708
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-89799 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in bpf_get_stackid The get_perf_callchain call needs disabled preemption plus we need it … | Sep 16, 2026 |
| CVE-2026-89798 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: rpcrdma: arm rn_done before publishing the notification rpcrdma_rn_register() inserts @rn into rd_xa with xa_alloc() before … | Sep 16, 2026 |
| CVE-2026-89797 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: power: supply: ab8500_fg: fix use-after-free on remove ab8500_fg_remove() destroys the driver workqueue while the threaded … | Sep 16, 2026 |
| CVE-2026-89796 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: avoid infinite kdamond_merge_regions() internal loop Patch series "mm/damon: unurgent fixes for infinite loop, NULL … | Sep 16, 2026 |
| CVE-2026-89795 | HIGH | 8.4 | In the Linux kernel, the following vulnerability has been resolved: PCI: Allow per function PCI slots to fix slot reset on s390 On s390 systems, … | Sep 16, 2026 |
| CVE-2026-89794 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: zero pipe read compound padding Compound response handling extends the last response iov to … | Sep 16, 2026 |
| CVE-2026-86585 | UNKNOWN | — | The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls … | Sep 16, 2026 |
| CVE-2026-86107 | MEDIUM | 5.9 | The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP … | Sep 16, 2026 |
| CVE-2026-86106 | CRITICAL | 9.6 | An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command … | Sep 16, 2026 |
| CVE-2026-14916 | UNKNOWN | — | A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected … | Sep 16, 2026 |
| CVE-2026-89793 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: ublk: clear VM_MAYWRITE on read-only ublk char device mmap ublk_ch_mmap() rejects mmap requests with VM_WRITE … | Sep 16, 2026 |
| CVE-2026-86792 | UNKNOWN | — | Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with … | Sep 16, 2026 |
| CVE-2026-86474 | UNKNOWN | — | The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to … | Sep 16, 2026 |
| CVE-2026-86466 | UNKNOWN | — | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it … | Sep 16, 2026 |
| CVE-2026-86443 | UNKNOWN | — | Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device … | Sep 16, 2026 |
| CVE-2026-85628 | UNKNOWN | — | Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior … | Sep 16, 2026 |
| CVE-2026-84501 | MEDIUM | 5.3 | An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). … | Sep 16, 2026 |
| CVE-2026-84439 | UNKNOWN | — | When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with … | Sep 16, 2026 |
| CVE-2026-82310 | UNKNOWN | — | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, … | Sep 16, 2026 |
| CVE-2026-79993 | UNKNOWN | — | The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless … | Sep 16, 2026 |
| CVE-2026-77190 | MEDIUM | 6.5 | On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse … | Sep 16, 2026 |
| CVE-2026-76187 | UNKNOWN | — | Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client … | Sep 16, 2026 |
| CVE-2026-76186 | UNKNOWN | — | Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak … | Sep 16, 2026 |
| CVE-2026-76151 | UNKNOWN | — | Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through … | Sep 16, 2026 |
| CVE-2026-73469 | MEDIUM | 5.8 | When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended … | Sep 16, 2026 |