Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44727
Total
3597
Critical
13286
High
13138
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-78051 | MEDIUM | 5.3 | A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie … | Aug 23, 2026 |
| CVE-2026-78050 | CRITICAL | 9.9 | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone of the component Web Management. The … | Aug 23, 2026 |
| CVE-2026-5723 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 23, 2026 |
| CVE-2026-18027 | MEDIUM | 6.5 | The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, … | Aug 23, 2026 |
| CVE-2026-16149 | HIGH | 8.8 | The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's … | Aug 23, 2026 |
| CVE-2026-0551 | HIGH | 8.8 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization … | Aug 23, 2026 |
| CVE-2026-78122 | HIGH | 7.4 | docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests … | Aug 22, 2026 |
| CVE-2026-78049 | LOW | 3.7 | A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVariableNodeAttributes of the file src/ClientServer/address_space/internal/sopc_node_mgt_helper_internal.c of the component AddNodes Service. … | Aug 22, 2026 |
| CVE-2026-19684 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 22, 2026 |
| CVE-2026-47895 | HIGH | 7.5 | In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a … | Aug 22, 2026 |
| CVE-2026-12999 | MEDIUM | 5.3 | The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a net_buf from the fixed airoc_pool for every outbound packet. When whd_network_send_ethernet_data() returns a … | Aug 22, 2026 |
| CVE-2026-74733 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock Locking is disabled in the regmap config as this … | Aug 22, 2026 |
| CVE-2026-74732 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check for tg ops in dce110_set_avmute Some older DCE timing generators do not implement … | Aug 22, 2026 |
| CVE-2026-74731 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Skip sub-disable teardown for never-linked sub-schedulers A sub-scheduler enable can fail before scx_link_sched() links … | Aug 22, 2026 |
| CVE-2026-74730 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call Dan Aloni reports that he was … | Aug 22, 2026 |
| CVE-2026-74729 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read put_fifo_with_discard() acts as both producer and consumer … | Aug 22, 2026 |
| CVE-2026-74728 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfs: handle NULL b_addr in xfs_buf_free When xfs_buf_alloc_backing_mem() fails, xfs_buf_free() is called with bp->b_addr still … | Aug 22, 2026 |
| CVE-2026-74727 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ovpn: skip rehash for peers already removed from by_id ovpn_nl_peer_set_doit() resolves the target peer via … | Aug 22, 2026 |
| CVE-2026-74726 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor bond_alb_monitor() reads primary_is_promisc under RCU, then drops … | Aug 22, 2026 |
| CVE-2026-74725 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: enic: fix tx_hang_reset use-after-free on device removal enic_remove() cancels the reset and change_mtu_work items but … | Aug 22, 2026 |
| CVE-2026-74724 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ipvs: avoid out-of-bounds write in ip_vs_nat_icmp Sashiko warns that local attacker can modify the packet … | Aug 22, 2026 |
| CVE-2026-74723 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid headers [BUG] For a crafted btrfs image, the … | Aug 22, 2026 |
| CVE-2026-74722 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak in btrfs_do_encoded_write() Local fuzzing of 6.12.94 has found the following memory … | Aug 22, 2026 |
| CVE-2026-74721 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages() Two error paths in amdxdna_insert_pages() called vma->vm_ops->close(vma) before returning … | Aug 22, 2026 |
| CVE-2026-74720 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer state for commuted arithmetic When scalar += pointer is handled in adjust_ptr_min_max_vals(), … | Aug 22, 2026 |