Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42400
Total
3455
Critical
12534
High
12466
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-33263 | MEDIUM | 4.3 | When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode … | Aug 28, 2026 |
| CVE-2026-27852 | HIGH | 7.5 | An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME … | Aug 28, 2026 |
| CVE-2026-18918 | UNKNOWN | — | In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those … | Aug 28, 2026 |
| CVE-2026-18393 | MEDIUM | 5.4 | A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote … | Aug 28, 2026 |
| CVE-2026-9548 | MEDIUM | 6.5 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, … | Aug 28, 2026 |
| CVE-2026-9491 | MEDIUM | 4.3 | A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information. | Aug 28, 2026 |
| CVE-2026-82123 | MEDIUM | 6.5 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & Logic. | Aug 28, 2026 |
| CVE-2026-80724 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming writable vmclock_miscdev_mmap() rejects writable mappings of the shared … | Aug 28, 2026 |
| CVE-2026-80723 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: of: reserved_mem: prevent OOB when too many dynamic regions are defined On boot, fdt_scan_reserved_mem() saves … | Aug 28, 2026 |
| CVE-2026-80722 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params before driver setup ieee80211_process_rx_twt_action() only partially validates a received … | Aug 28, 2026 |
| CVE-2026-80721 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon references in iso_conn After iso_conn_del(), ISO sockets should not … | Aug 28, 2026 |
| CVE-2026-80720 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iomap: add a separate bio_set for iomap_split_ioend iomap_split_ioend can split bios that already come from … | Aug 28, 2026 |
| CVE-2026-80719 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm: mglru: fix stale batch updates after memcg reparenting The mglru page table walker batches … | Aug 28, 2026 |
| CVE-2026-80718 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() In pcpu_create_chunk(), nr_pages is the total contiguous … | Aug 28, 2026 |
| CVE-2026-80717 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: sctp: validate Adaptation Indication parameter length The Adaptation Layer Indication parameter contains a fixed 32-bit … | Aug 28, 2026 |
| CVE-2026-80716 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: wake linked drain waiters on unlink snd_pcm_drain() on a linked stream parks an … | Aug 28, 2026 |
| CVE-2026-80715 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: igc: remove napi_synchronize() in igc_down() When an AF_XDP zero-copy application is killed abruptly, the XSK … | Aug 28, 2026 |
| CVE-2026-80714 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before … | Aug 28, 2026 |
| CVE-2026-80713 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: io_uring: preserve task restrictions across exec Per-task restrictions apply to all rings created by a … | Aug 28, 2026 |
| CVE-2026-80712 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: write the feature value before executing SET_FEATURE qcom_spi_send_cmdaddr() programs NAND_FLASH_CMD/NAND_EXEC_CMD and submits the … | Aug 28, 2026 |
| CVE-2026-80711 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: power: supply: max17040: handle missing status supplier MAX17040 does not report charger state itself, so … | Aug 28, 2026 |
| CVE-2026-80710 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Fix undersized format-check buffer fmt_buffer_size in dasd_eckd_check_device_format() is declared as int, even though one … | Aug 28, 2026 |
| CVE-2026-80709 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs There is a wrong upper limit … | Aug 28, 2026 |
| CVE-2026-80708 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() The helper function _ip_cprb_helper() … | Aug 28, 2026 |
| CVE-2026-80707 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer Zero the allocated buffer in j1939_session_fresh_new() to ensure … | Aug 28, 2026 |