Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41893
Total
3420
Critical
12384
High
12282
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82911 | UNKNOWN | — | Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 allows an unauthenticated attacker to confirm any order … | Sep 04, 2026 |
| CVE-2026-80864 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp rxe_qp_from_attr() handles IB_QP_MAX_DEST_RD_ATOMIC outside the IB_QP_STATE path, so … | Sep 04, 2026 |
| CVE-2026-80863 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix OOB in free_rd_atomic_resources() free_rd_atomic_resources() iterates using qp->attr.max_dest_rd_atomic. Updating max_dest_rd_atomic before freeing the old … | Sep 04, 2026 |
| CVE-2026-80862 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix usage of page_frag_cache nvme uses page_frag_cache to preallocate PDU for each preallocated request … | Sep 04, 2026 |
| CVE-2026-80861 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: xhci: bail out of setup if the controller is inaccessible xhci_gen_setup() locates the operational … | Sep 04, 2026 |
| CVE-2026-80860 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fuse: fix race between interrupt and resend After commit f8fce75fedf7 ("fuse: clear intr_entry in fuse_resend … | Sep 04, 2026 |
| CVE-2026-80859 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fuse: fix missing barrier when checking io-uring readiness fuse_block_alloc() reads fch->initialized and then fch->io_uring. fch->io_uring … | Sep 04, 2026 |
| CVE-2026-80858 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fuse: publish io-uring queues with release semantics fuse_uring_create_queue() initializes a fuse_ring_queue and then publishes the … | Sep 04, 2026 |
| CVE-2026-80857 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free The abort_on_kill path in request_wait_answer() calls … | Sep 04, 2026 |
| CVE-2026-80856 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fuse: fix invalidate lock leak on setattr writeback failure fuse_do_setattr() takes filemap_invalidate_lock() for a DAX … | Sep 04, 2026 |
| CVE-2026-80855 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fuse: fix invalidate lock leak on open O_TRUNC DAX failure fuse_open() takes filemap_invalidate_lock() for a … | Sep 04, 2026 |
| CVE-2026-80854 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: keep port count until LUN teardown completes tcm_usbg_drop_nexus() permits session removal once … | Sep 04, 2026 |
| CVE-2026-80853 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts When {de,en}crypting memory of … | Sep 04, 2026 |
| CVE-2026-80852 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tls: device: fix out-of-bounds write in tls_append_frag() Found with syzkaller and a local syzbot instance … | Sep 04, 2026 |
| CVE-2026-80851 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: gtp: serialize PDP context updates PDP contexts can be deleted through GTP_CMD_DELPDP or while the … | Sep 04, 2026 |
| CVE-2026-80850 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tcp: fix AO info use-after-free in tcp_ao_connect_init() tcp_v4_connect() adds a SYN-SENT socket to the ehash … | Sep 04, 2026 |
| CVE-2026-80849 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: fix use-after-free of current_key on reconnect to another peer tcp_inbound_ao_hash() is called before bh_lock_sock_nested() … | Sep 04, 2026 |
| CVE-2026-80848 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: fix UAF during close ZDI reported and analyzed a race condition during close … | Sep 04, 2026 |
| CVE-2026-80847 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tcp: clamp route advmss to TCP_MIN_MSS tcp_select_initial_window() assumes that callers never pass an MSS smaller … | Sep 04, 2026 |
| CVE-2026-80846 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: drop ESP-in-TCP packets with no ingress device ESP-in-TCP receives records through the TCP strparser. … | Sep 04, 2026 |
| CVE-2026-80845 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: avoid lock inversion in nat keepalive work nat_keepalive_work() walks the state table while xfrm_state_walk() … | Sep 04, 2026 |
| CVE-2026-80844 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the … | Sep 04, 2026 |
| CVE-2026-80843 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: fix xfrm_state_construct() auth-trunc leak attach_auth_trunc() can allocate x->aalg while leaving x->props.aalgo at zero when … | Sep 04, 2026 |
| CVE-2026-80842 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: bridge: mcast: fix use-after-free of a master VLAN's multicast context br_multicast_toggle_one_vlan() clears BR_VLFLAG_MCAST_ENABLED under … | Sep 04, 2026 |
| CVE-2026-80841 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net/packet: defer vmalloc TX_RING free until skbs finish AF_PACKET TX_RING skbs keep a raw pointer … | Sep 04, 2026 |