Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45002
Total
3609
Critical
13358
High
13243
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-58085 | UNKNOWN | — | After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded. The driver … | Aug 19, 2026 |
| CVE-2026-58084 | UNKNOWN | — | To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For a timer using CLOCK_TAI this … | Aug 19, 2026 |
| CVE-2026-58083 | HIGH | 8.4 | While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before … | Aug 19, 2026 |
| CVE-2026-58082 | UNKNOWN | — | The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some ISO-2022 variants can require up to 10 … | Aug 19, 2026 |
| CVE-2026-58081 | UNKNOWN | — | Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An … | Aug 19, 2026 |
| CVE-2026-49425 | UNKNOWN | — | The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct. An unprivileged … | Aug 19, 2026 |
| CVE-2026-49424 | UNKNOWN | — | The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct. An unprivileged user … | Aug 19, 2026 |
| CVE-2026-75981 | HIGH | 7.2 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including … | Aug 19, 2026 |
| CVE-2026-49423 | UNKNOWN | — | When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index for every mbuf in the chain, including mbufs … | Aug 19, 2026 |
| CVE-2026-15780 | HIGH | 7.2 | The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions … | Aug 19, 2026 |
| CVE-2026-15446 | MEDIUM | 6.4 | The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up … | Aug 19, 2026 |
| CVE-2026-8810 | MEDIUM | 6.9 | On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables. | Aug 19, 2026 |
| CVE-2026-49431 | UNKNOWN | — | The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able to set metadata on a dataset indicating … | Aug 19, 2026 |
| CVE-2026-49430 | UNKNOWN | — | The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit integer for allocation, then used the original 64-bit … | Aug 19, 2026 |
| CVE-2026-49429 | HIGH | 7.8 | The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the kernel allocation, but used the original 64-bit … | Aug 19, 2026 |
| CVE-2026-49428 | HIGH | 8.4 | Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on … | Aug 19, 2026 |
| CVE-2026-49427 | UNKNOWN | — | Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) transmitted such an object with the SF_NOCACHE flag, it freed the underlying … | Aug 19, 2026 |
| CVE-2026-49426 | UNKNOWN | — | When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup function to AUDIT_SYSCALL_EXIT() rather than the actual … | Aug 19, 2026 |
| CVE-2026-49422 | HIGH | 8.4 | The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacquires the lock. After reacquiring, it verifies that … | Aug 19, 2026 |
| CVE-2026-49421 | UNKNOWN | — | The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pass it through to the underlying path lookup. The flag … | Aug 19, 2026 |
| CVE-2026-49420 | HIGH | 8.8 | The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten data fit in the buffer, or whether … | Aug 19, 2026 |
| CVE-2026-19842 | HIGH | 8.8 | The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and … | Aug 19, 2026 |
| CVE-2026-19782 | MEDIUM | 5.4 | The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any authenticated user, such as a subscriber, … | Aug 19, 2026 |
| CVE-2026-19709 | MEDIUM | 5.3 | The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the … | Aug 19, 2026 |
| CVE-2026-19417 | MEDIUM | 6.5 | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users … | Aug 19, 2026 |