Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
27385
Total
2080
Critical
8289
High
8496
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-43297 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rga: Fix possible ERR_PTR dereference in rga_buf_init() rga_get_frame() can return ERR_PTR(-EINVAL) when buffer … | May 08, 2026 |
| CVE-2026-43296 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Workaround SQM/PSE stalls by disabling sticky NIX SQ manager sticky mode is known to … | May 08, 2026 |
| CVE-2026-43295 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: rapidio: replace rio_free_net() with kfree() in rio_scan_alloc_net() When idtab allocation fails, net is not registered … | May 08, 2026 |
| CVE-2026-43294 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels Since commit 56de5e305d4b … | May 08, 2026 |
| CVE-2026-43293 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix kthread worker destruction in polling mode Fix the cleanup order in … | May 08, 2026 |
| CVE-2026-43292 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: prevent RCU stalls in kasan_release_vmalloc_node When CONFIG_PAGE_OWNER is enabled, freeing KASAN shadow pages during … | May 08, 2026 |
| CVE-2026-43291 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Fix parameter validation for packet data Since commit 9c328f54741b ("net: nfc: nci: … | May 08, 2026 |
| CVE-2026-43290 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Return queued buffers on start_streaming() failure Return buffers if streaming fails to start … | May 08, 2026 |
| CVE-2026-43289 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: kexec: derive purgatory entry from symbol kexec_load_purgatory() derives image->start by locating e_entry inside an SHF_EXECINSTR … | May 08, 2026 |
| CVE-2026-43288 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ext4: move ext4_percpu_param_init() before ext4_mb_init() When running `kvm-xfstests -c ext4/1k -C 1 generic/383` with the … | May 08, 2026 |
| CVE-2026-43287 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm: Account property blob allocations to memcg DRM_IOCTL_MODE_CREATEPROPBLOB allows userspace to allocate arbitrary-sized property blobs … | May 08, 2026 |
| CVE-2026-43286 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: restore failed global reservations to subpool Commit a833a693a490 ("mm: hugetlb: fix incorrect fallback for … | May 08, 2026 |
| CVE-2026-43285 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/slab: do not access current->mems_allowed_seq if !allow_spin Lockdep complains when get_from_any_partial() is called in an … | May 08, 2026 |
| CVE-2026-41512 | CRITICAL | 9.9 | ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerability … | May 08, 2026 |
| CVE-2026-41509 | UNKNOWN | — | CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused … | May 08, 2026 |
| CVE-2026-41507 | CRITICAL | 9.8 | math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim into a new Function() body without … | May 08, 2026 |
| CVE-2026-41506 | MEDIUM | 4.7 | go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following … | May 08, 2026 |
| CVE-2026-41497 | CRITICAL | 9.8 | PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or argument … | May 08, 2026 |
| CVE-2026-41496 | HIGH | 8.1 | PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input validation to SQLiteConversationStore only. … | May 08, 2026 |
| CVE-2026-41493 | UNKNOWN | — | YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. … | May 08, 2026 |
| CVE-2026-41491 | HIGH | 8.1 | Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-rc.1 to before 1.16.14, and … | May 08, 2026 |
| CVE-2026-41423 | UNKNOWN | — | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.21, 20.3.19, 21.2.9, and 22.0.0-next.8, … | May 08, 2026 |
| CVE-2026-41161 | UNKNOWN | — | Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.2.0, the /api/auth/login endpoint contains a logic flaw … | May 08, 2026 |
| CVE-2026-39816 | UNKNOWN | — | The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports … | May 08, 2026 |
| CVE-2026-32803 | LOW | 3.3 | Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains an Insufficient Logging vulnerability. A low privileged … | May 08, 2026 |