Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28078
Total
2162
Critical
8456
High
8753
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-71289 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: handle attr_set_size() errors when truncating files If attr_set_size() fails while truncating down, the error … | May 06, 2026 |
| CVE-2025-71288 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: memory: mtk-smi: fix device leaks on common probe Make sure to drop the reference taken … | May 06, 2026 |
| CVE-2025-71287 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: memory: mtk-smi: fix device leak on larb probe Make sure to drop the reference taken … | May 06, 2026 |
| CVE-2025-71286 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Correct the allocation size for bytes controls The size of the data … | May 06, 2026 |
| CVE-2025-71285 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels MHI stack offers the … | May 06, 2026 |
| CVE-2025-71274 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: rpmsg: core: fix race in driver_override_show() and use core helper The driver_override_show function reads the … | May 06, 2026 |
| CVE-2025-71273 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band() Simplify the code by using device managed memory allocations. … | May 06, 2026 |
| CVE-2025-71272 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: most: core: fix resource leak in most_register_interface error paths The function most_register_interface() did not correctly … | May 06, 2026 |
| CVE-2025-71271 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: hfsplus: ensure sb->s_fs_info is always cleaned up When hfsplus was converted to the new mount … | May 06, 2026 |
| CVE-2025-62345 | LOW | 2.7 | HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component contains a security weakness in its input handling … | May 06, 2026 |
| CVE-2025-31951 | HIGH | 8.8 | HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that … | May 06, 2026 |
| CVE-2026-6420 | MEDIUM | 6.3 | A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability … | May 06, 2026 |
| CVE-2025-59854 | LOW | 3.1 | HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to … | May 06, 2026 |
| CVE-2025-59853 | LOW | 3.1 | HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to … | May 06, 2026 |
| CVE-2025-59852 | LOW | 3.7 | HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker … | May 06, 2026 |
| CVE-2025-59851 | LOW | 3.7 | HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, which could allow an attacker … | May 06, 2026 |
| CVE-2025-31970 | MEDIUM | 5.3 | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could … | May 06, 2026 |
| CVE-2026-6860 | UNKNOWN | — | A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard … | May 06, 2026 |
| CVE-2026-43975 | MEDIUM | 6.5 | FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to write … | May 06, 2026 |
| CVE-2026-43646 | HIGH | 7.5 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, … | May 06, 2026 |
| CVE-2026-43120 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix double free related to rereg_user_mr If IB_MR_REREG_TRANS is set during rereg_user_mr, the umem … | May 06, 2026 |
| CVE-2026-43119 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: annotate data-races around hdev->req_status __hci_cmd_sync_sk() sets hdev->req_status under hdev->req_lock: hdev->req_status = HCI_REQ_PEND; However, … | May 06, 2026 |
| CVE-2026-43118 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix zero size inode with non-zero size after log replay When logging that an … | May 06, 2026 |
| CVE-2026-43117 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() If overlay is used on … | May 06, 2026 |
| CVE-2026-43116 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference on the expectation is not … | May 06, 2026 |