Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28078
Total
2162
Critical
8456
High
8753
Medium
CVE ID Severity Score Description Published
CVE-2026-43090 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: xfrm: fix refcount leak in xfrm_migrate_policy_find syzkaller reported a memory leak in xfrm_policy_alloc: BUG: memory … May 06, 2026
CVE-2026-43089 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_mapping() struct xfrm_usersa_id has a one-byte padding hole after the … May 06, 2026
CVE-2026-43088 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: net: af_key: zero aligned sockaddr tail in PF_KEY exports PF_KEY export paths use `pfkey_sockaddr_size()` when … May 06, 2026
CVE-2026-43087 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Disable all pin interrupts during probe A chip being probed may have the … May 06, 2026
CVE-2026-43086 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: ipvs: fix NULL deref in ip_vs_add_service error path When ip_vs_bind_scheduler() succeeds in ip_vs_add_service(), the local … May 06, 2026
CVE-2026-43085 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator When batching multiple NFLOG messages (inst->qlen > 1), … May 06, 2026
CVE-2026-43084 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: make hash table per queue Sharing a global hash table among all queues … May 06, 2026
CVE-2026-43083 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... … May 06, 2026
CVE-2026-43082 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: net: txgbe: leave space for null terminators on property_entry Lists of struct property_entry are supposed … May 06, 2026
CVE-2026-43081 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ Fix the field masks to … May 06, 2026
CVE-2026-43080 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: l2tp: Drop large packets with UDP encap syzbot reported a WARN on my patch series … May 06, 2026
CVE-2026-43079 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Skip discovery table for offline dies This warning can be triggered if NUMA is … May 06, 2026
CVE-2026-43078 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl When page reassignment was added to … May 06, 2026
CVE-2026-43077 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Fix minimum RX size check for decryption The check for the minimum … May 06, 2026
CVE-2026-43076 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate inline data i_size during inode read When reading an inode from disk, ocfs2_validate_inode_block() … May 06, 2026
CVE-2026-43075 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix out-of-bounds write in ocfs2_write_end_inline KASAN reports a use-after-free write of 4086 bytes in … May 06, 2026
CVE-2026-43074 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c … May 06, 2026
CVE-2026-42509 MEDIUM 6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from … May 06, 2026
CVE-2026-40010 CRITICAL 9.1 Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue … May 06, 2026
CVE-2026-40001 MEDIUM 5.2 There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which may allow local arbitrary code execution, … May 06, 2026
CVE-2026-35255 MEDIUM 6.6 Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is affected is v2.3.2. Easily … May 06, 2026
CVE-2026-1719 HIGH 7.5 The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on … May 06, 2026
CVE-2026-7841 HIGH 8.8 A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on … May 06, 2026
CVE-2026-7457 MEDIUM 6.4 The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5.0. This is due to insufficient input … May 06, 2026
CVE-2026-7448 HIGH 7.2 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all … May 06, 2026