Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41893
Total
3420
Critical
12384
High
12282
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-80871 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: crypto: xilinx-trng - Remove crypto_rng interface Implementing the crypto_rng interface has no purpose, as it … | Sep 04, 2026 |
| CVE-2026-80870 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Validate CRIU-restored IDs before idr_alloc The KFD CRIU restore flow restores previously saved object … | Sep 04, 2026 |
| CVE-2026-80869 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the attribute-list entry in ntfs_read_inode_mount() The $MFT attribute-list walk in ntfs_read_inode_mount() validates each … | Sep 04, 2026 |
| CVE-2026-80868 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ntfs3: Allocate iomap inline_data using alloc_page This fixes a BUG reported in iomap_write_end_inline: iomap_inline_data_valid checks … | Sep 04, 2026 |
| CVE-2026-80867 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: alpha/PCI: Add security_locked_down() check to pci_mmap_resource() Currently, Alpha's pci_mmap_resource() does not check security_locked_down(LOCKDOWN_PCI_ACCESS) before allowing … | Sep 04, 2026 |
| CVE-2026-80866 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tipc: avoid busy looping in tipc_exit_net() Blamed commit introduced a busy-wait loop in tipc_exit_net() to … | Sep 04, 2026 |
| CVE-2026-80865 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Add missing access_ok call to copy_user_syms As reported by sashiko we use __get_user without … | Sep 04, 2026 |
| CVE-2026-78849 | UNKNOWN | — | Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary … | Sep 04, 2026 |
| CVE-2026-78745 | UNKNOWN | — | An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd) | Sep 04, 2026 |
| CVE-2026-75430 | CRITICAL | 9.8 | PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker … | Sep 04, 2026 |
| CVE-2026-38961 | UNKNOWN | — | Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to … | Sep 04, 2026 |
| CVE-2026-31020 | CRITICAL | 9.8 | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality … | Sep 04, 2026 |
| CVE-2026-18489 | HIGH | 7.4 | IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due … | Sep 04, 2026 |
| CVE-2026-18486 | HIGH | 8.8 | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper … | Sep 04, 2026 |
| CVE-2026-18341 | MEDIUM | 6.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow. | Sep 04, 2026 |
| CVE-2026-18221 | HIGH | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters. | Sep 04, 2026 |
| CVE-2026-18175 | HIGH | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher. | Sep 04, 2026 |
| CVE-2026-18078 | MEDIUM | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow. | Sep 04, 2026 |
| CVE-2026-18076 | MEDIUM | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak. | Sep 04, 2026 |
| CVE-2026-18073 | MEDIUM | 4.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of … | Sep 04, 2026 |
| CVE-2026-17631 | MEDIUM | 5.0 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability. | Sep 04, 2026 |
| CVE-2026-17627 | MEDIUM | 4.9 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper … | Sep 04, 2026 |
| CVE-2026-17622 | MEDIUM | 6.5 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a … | Sep 04, 2026 |
| CVE-2026-17621 | MEDIUM | 5.4 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL … | Sep 04, 2026 |
| CVE-2026-17499 | MEDIUM | 4.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in … | Sep 04, 2026 |