Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26990
Total
2034
Critical
8144
High
8390
Medium
CVE ID Severity Score Description Published
CVE-2026-47900 UNKNOWN Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the "name" field of its "package.json" file, … Jun 09, 2026
CVE-2026-47899 UNKNOWN The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers without proper path validation. An attacker … Jun 09, 2026
CVE-2026-46332 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive buffering cc1352_bootloader_rx() appends each serdev chunk into the fixed rx_buffer … Jun 09, 2026
CVE-2026-46330 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Revert "net/smc: Introduce TCP ULP support" This reverts commit d7cd421da9da2cc7b4d25b8537f66db5c8331c40. As reported by Al Viro, … Jun 09, 2026
CVE-2026-46329 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem properly for file-backed mounts I/O requests beyond the end of … Jun 09, 2026
CVE-2026-46328 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cpu timers requires an additional step beyond … Jun 09, 2026
CVE-2026-46327 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_suspended_md The function dm_blk_report_zones tests if the device is suspended … Jun 09, 2026
CVE-2026-46326 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix spi_transfer struct initialisation Make sure that the spi_transfer struct is zeroed … Jun 09, 2026
CVE-2026-46325 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE The current implementation incorrectly handles … Jun 09, 2026
CVE-2026-11793 MEDIUM 4.9 A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack … Jun 09, 2026
CVE-2026-11792 LOW 3.3 A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog.c copies a fixed-length password … Jun 09, 2026
CVE-2026-11790 MEDIUM 4.9 A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from … Jun 09, 2026
CVE-2026-11789 MEDIUM 4.9 A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password … Jun 09, 2026
CVE-2026-11788 MEDIUM 5.9 A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an … Jun 09, 2026
CVE-2026-11787 MEDIUM 5.0 A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap … Jun 09, 2026
CVE-2026-11786 LOW 1.9 A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing … Jun 09, 2026
CVE-2026-11785 MEDIUM 4.3 A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be … Jun 09, 2026
CVE-2026-46324 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use list_del_rcu for netlink hooks nft_netdev_unregister_hooks and __nft_unregister_flowtable_net_hooks need to use list_del_rcu(), this … Jun 09, 2026
CVE-2026-46323 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and … Jun 09, 2026
CVE-2026-46322 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one() When build_skb() fails in tun_xdp_one(), the function … Jun 09, 2026
CVE-2026-46321 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns -EINVAL on a frame shorter … Jun 09, 2026
CVE-2026-46320 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects a frame shorter than ETH_HLEN … Jun 09, 2026
CVE-2026-46319 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: Only release RCU read lock after ct_ft When looking up a flow table … Jun 09, 2026
CVE-2026-46318 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hugetlbfs to use mmap_prepare" This reverts commit ea52cb24cd3f ("mm/hugetlbfs: update hugetlbfs to … Jun 09, 2026
CVE-2026-46317 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_lock kvm->arch.nested_mmus[] is walked under kvm->mmu_lock, including from the … Jun 09, 2026