Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51787
Total
4103
Critical
15361
High
15039
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-10724 | MEDIUM | 4.8 | The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing … | Jul 20, 2026 |
| CVE-2026-10081 | HIGH | 8.8 | The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it … | Jul 20, 2026 |
| CVE-2026-45138 | MEDIUM | 5.4 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to sanitize blog post bodies relies … | Jul 20, 2026 |
| CVE-2026-44359 | CRITICAL | 10.0 | Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs … | Jul 20, 2026 |
| CVE-2026-42566 | HIGH | 7.5 | Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can … | Jul 20, 2026 |
| CVE-2026-12484 | HIGH | 7.8 | A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)` without … | Jul 19, 2026 |
| CVE-2026-64186 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs In iommu_mmio_write() and iommu_capability_write(), the variables dbg_mmio_offset … | Jul 19, 2026 |
| CVE-2026-64185 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: sysfs: don't remove existing directory on update failure When sysfs_update_group() is called for a named … | Jul 19, 2026 |
| CVE-2026-64184 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() damon_sysfs_memcg_path_to_id() breaks mem_cgroup_iter() loop without calling mem_cgroup_iter_break(). This leaks the cgroup … | Jul 19, 2026 |
| CVE-2026-64183 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: efi: Allocate runtime workqueue before ACPI init Since commit 5894cf571e14 ("acpi/prmt: Use EFI runtime sandbox … | Jul 19, 2026 |
| CVE-2026-64182 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drivers/base/memory: fix memory block reference leak in poison accounting memblk_nr_poison_inc() and memblk_nr_poison_sub() look up a … | Jul 19, 2026 |
| CVE-2026-64181 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special() On x86 32-bit with THP enabled, … | Jul 19, 2026 |
| CVE-2026-64180 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/memory_hotplug: fix memory block reference leak on remove Patch series "mm: Fix memory block leaks … | Jul 19, 2026 |
| CVE-2026-64179 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: fix potential memory leaks in ipc_imem_init() The memory allocated in ipc_protocol_init() is … | Jul 19, 2026 |
| CVE-2026-64178 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF read of dev->name bnep_add_connection() needs to keep holding the bnep_session_sem while … | Jul 19, 2026 |
| CVE-2026-64177 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: phonet/pep: disable BH around forwarded sk_receive_skb() The networking receive path is usually run from softirq … | Jul 19, 2026 |
| CVE-2026-64176 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix driver-set TX rates on old devices On old devices such as … | Jul 19, 2026 |
| CVE-2026-64175 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: stop TX during firmware restart When iwlwifi firmware crashes (e.g., NMI_INTERRUPT_UNKNOWN on … | Jul 19, 2026 |
| CVE-2026-64174 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: advance loop vars in cfg80211_merge_profile() cfg80211_merge_profile() reassembles a Multi-BSSID non-transmitted BSS profile that … | Jul 19, 2026 |
| CVE-2026-64173 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tracing: Do not call map->ops->elt_free() if elt_alloc() fails In paths where tracing_map_elt_alloc() failed to allocate … | Jul 19, 2026 |
| CVE-2026-64172 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235) Hygon Family 18h … | Jul 19, 2026 |
| CVE-2026-64171 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: fix pm_runtime leak on mutex_lock failure If tegra_i2c_mutex_lock() fails, the function returns without … | Jul 19, 2026 |
| CVE-2026-64170 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: spi: qup: fix error pointer deref after DMA setup failure The driver falls back to … | Jul 19, 2026 |
| CVE-2026-64169 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: spi: ep93xx: fix error pointer deref after DMA setup failure The driver falls back to … | Jul 19, 2026 |
| CVE-2026-64168 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: spi: sprd: fix error pointer deref after DMA setup failure The driver falls back to … | Jul 19, 2026 |