Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51620
Total
4095
Critical
15305
High
14964
Medium
CVE ID Severity Score Description Published
CVE-2026-64217 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter() Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills pages[], then … Jul 24, 2026
CVE-2026-64216 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it is … Jul 24, 2026
CVE-2026-64215 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table Check the return value of kzalloc() to prevent a … Jul 24, 2026
CVE-2026-64214 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() A kernel panic is observed when handling machine … Jul 24, 2026
CVE-2026-64213 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Add lock protection to lm90_alert Sashiko reports: lm90_alert() executes in the smbus alert … Jul 24, 2026
CVE-2026-64212 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it In iwl_mld_remove_link, the link->fw_id … Jul 24, 2026
CVE-2026-64211 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: srcu: Don't queue workqueue handlers to never-online CPUs While an srcu_struct structure is in the … Jul 24, 2026
CVE-2026-64210 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ During napi poll, when the affinity changes and … Jul 24, 2026
CVE-2026-64209 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config swing_tbl and pre_emphasis_tbl are … Jul 24, 2026
CVE-2026-64208 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks Change the krb5 crypto library to provide … Jul 24, 2026
CVE-2026-17039 LOW 3.1 A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, … Jul 24, 2026
CVE-2026-8789 HIGH 8.1 The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the … Jul 24, 2026
CVE-2026-8308 MEDIUM 6.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue … Jul 24, 2026
CVE-2026-7007 MEDIUM 4.6 The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.c) before completing a mount. The validator checked the magic number, block size, revision … Jul 24, 2026
CVE-2026-66007 MEDIUM 6.5 Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated … Jul 24, 2026
CVE-2026-66006 MEDIUM 5.3 lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including … Jul 24, 2026
CVE-2026-66005 MEDIUM 6.3 Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host … Jul 24, 2026
CVE-2026-66004 MEDIUM 5.3 BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in … Jul 24, 2026
CVE-2026-58630 CRITICAL 10.0 Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. Jul 24, 2026
CVE-2026-58586 UNKNOWN — Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled … Jul 24, 2026
CVE-2026-57106 CRITICAL 10.0 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. Jul 24, 2026
CVE-2026-56163 CRITICAL 10.0 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Jul 24, 2026
CVE-2026-55732 UNKNOWN — Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an … Jul 24, 2026
CVE-2026-55731 UNKNOWN — Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 … Jul 24, 2026
CVE-2026-55730 UNKNOWN — Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a … Jul 24, 2026