Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41893
Total
3420
Critical
12384
High
12282
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18149 | MEDIUM | 5.9 | undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only part … | Sep 04, 2026 |
| CVE-2021-44320 | HIGH | 7.5 | Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., … | Sep 04, 2026 |
| CVE-2021-44319 | UNKNOWN | — | Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and … | Sep 04, 2026 |
| CVE-2026-85152 | HIGH | 7.4 | undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or … | Sep 04, 2026 |
| CVE-2026-85024 | MEDIUM | 5.9 | undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream … | Sep 04, 2026 |
| CVE-2026-85014 | MEDIUM | 5.9 | undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean … | Sep 04, 2026 |
| CVE-2026-85008 | LOW | 3.7 | undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from … | Sep 04, 2026 |
| CVE-2026-84961 | HIGH | 7.4 | undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, … | Sep 04, 2026 |
| CVE-2026-84947 | LOW | 3.7 | undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, … | Sep 04, 2026 |
| CVE-2026-84933 | MEDIUM | 6.5 | undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. … | Sep 04, 2026 |
| CVE-2026-80886 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: serial: msm: Disable DMA for kernel console UART At the moment, concurrent writes from userspace … | Sep 04, 2026 |
| CVE-2026-80885 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: afs: Fix uncancelled rxrpc OOB message handler Fix AFS to cancel its OOB message processing … | Sep 04, 2026 |
| CVE-2026-80884 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ntb: Store original DMA address for future release The DMA API requires that dma_free_attrs receive … | Sep 04, 2026 |
| CVE-2026-80883 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered The host1x_client_register() function is … | Sep 04, 2026 |
| CVE-2026-80882 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm Ensure the ENOMEM … | Sep 04, 2026 |
| CVE-2026-80881 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix buffer head management in ocfs2_read_blocks() In ocfs2_read_blocks(), caller should't assume that buffer head … | Sep 04, 2026 |
| CVE-2026-80880 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Properly support implicit ODP rereg_mr Due to all the child mkeys in the implicit … | Sep 04, 2026 |
| CVE-2026-80879 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write A circular locking dependency involves INODE_ALLOC_SYSTEM_INODE, EXTENT_ALLOC_SYSTEM_INODE, and … | Sep 04, 2026 |
| CVE-2026-80878 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: afs: Fix leak of ungot volume Fix afs_lookup_volume_rcu() so that it doesn't leak a dying … | Sep 04, 2026 |
| CVE-2026-80877 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: afs: Fix vllist leak Fix a leak of the new vllist in afs_update_cell() in the … | Sep 04, 2026 |
| CVE-2026-80876 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix event length with forced 8-byte alignment When RB_FORCE_8BYTE_ALIGNMENT is true, rb_calculate_event_length() reserves the … | Sep 04, 2026 |
| CVE-2026-80875 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ipvs: use parsed transport offset in TCP state lookup TCP state handling reparses the skb … | Sep 04, 2026 |
| CVE-2026-80874 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: arm64: dts: renesas: ironhide: Describe inline ECC carveouts The DBSC5 DRAM controller protects DRAM content … | Sep 04, 2026 |
| CVE-2026-80873 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions kvm_inject_el2_exception() writes ESR_EL2 for synchronous … | Sep 04, 2026 |
| CVE-2026-80872 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/tas2781: Cancel async firmware request at unbind TAS2781 HDA I2C and SPI queue RCA … | Sep 04, 2026 |