Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25301
Total
1888
Critical
7733
High
7926
Medium
CVE ID Severity Score Description Published
CVE-2026-58034 UNKNOWN Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/blockConnectedTempAccountsField.Vue. … Jul 01, 2026
CVE-2026-58031 UNKNOWN Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js. … Jul 01, 2026
CVE-2026-2891 UNKNOWN The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed … Jul 01, 2026
CVE-2026-23537 CRITICAL 9.1 A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the … Jul 01, 2026
CVE-2026-14330 MEDIUM 5.5 Multiple unbounded alloca() calls in the PulseAudio protocol server. Jul 01, 2026
CVE-2026-14324 MEDIUM 6.5 RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. Jul 01, 2026
CVE-2026-13602 UNKNOWN We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access … Jul 01, 2026
CVE-2026-12374 UNKNOWN Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local … Jul 01, 2026
CVE-2026-5136 HIGH 8.8 A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an … Jul 01, 2026
CVE-2026-57692 CRITICAL 9.8 Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2. Jul 01, 2026
CVE-2026-53356 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset sg_page() returns struct page pointer not (void *) … Jul 01, 2026
CVE-2026-53355 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is written … Jul 01, 2026
CVE-2026-53354 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm CPUs A number of CPUs developed by … Jul 01, 2026
CVE-2026-53353 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syzbot reported the warning [0] in hsr_addr_is_self(), whose assumption is … Jul 01, 2026
CVE-2026-53352 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() When a multi-threaded process receives a stop signal … Jul 01, 2026
CVE-2026-53351 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFI Fixes a warning while dumping core: [54983.546369][ C7] WARNING: [!note_name] … Jul 01, 2026
CVE-2026-53350 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing firmware controls In wm_adsp_control_remove() check that the priv … Jul 01, 2026
CVE-2026-53349 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destroy stale expectfn expectations on unregister NAT helpers such as nf_nat_h323 store a … Jul 01, 2026
CVE-2026-53348 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions sdca_dev_unregister_functions() iterates over all SDCA function descriptors … Jul 01, 2026
CVE-2026-53347 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting aren't initialized if virtio-gpu … Jul 01, 2026
CVE-2026-53346 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES Due to a rustc bug [1] … Jul 01, 2026
CVE-2026-53345 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying … Jul 01, 2026
CVE-2026-53344 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init Regmap initialization triggers regcache_maple_populate() which attempts … Jul 01, 2026
CVE-2026-53343 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow Commit 44e9a3bb76e5 ("ARM: 9430/1: … Jul 01, 2026
CVE-2026-53342 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: arm64: mm: call pagetable dtor when freeing hot-removed page tables Since 5e8eb9aeeda3 ("arm64: mm: always … Jul 01, 2026