Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48919
Total
3931
Critical
14503
High
14257
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15060 | MEDIUM | 4.7 | When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged … | Aug 10, 2026 |
| CVE-2026-15059 | MEDIUM | 5.5 | Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation. | Aug 10, 2026 |
| CVE-2026-72692 | HIGH | 7.5 | A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution … | Aug 10, 2026 |
| CVE-2026-72691 | HIGH | 7.5 | An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via … | Aug 10, 2026 |
| CVE-2026-72690 | HIGH | 7.1 | An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to inject persistent mandatory survey questions into another organizer's events via … | Aug 10, 2026 |
| CVE-2026-72689 | HIGH | 7.5 | A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud … | Aug 10, 2026 |
| CVE-2026-72688 | HIGH | 7.5 | A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stored documents via the fileupload Parse cloud function. … | Aug 10, 2026 |
| CVE-2026-6374 | HIGH | 7.3 | Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executable. This issue affects WAH7601: through 20.07.2026. | Aug 10, 2026 |
| CVE-2026-6373 | MEDIUM | 6.5 | Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026. | Aug 10, 2026 |
| CVE-2026-68428 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Fix use-after-free on vendor module reload mmu_destroy_caches() destroys pte_list_desc_cache and mmu_page_header_cache, but leaves … | Aug 10, 2026 |
| CVE-2026-68427 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings __host1x_bo_unpin() drops the last reference to the mapping and … | Aug 10, 2026 |
| CVE-2026-68426 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals a GSO segment skb_gso_segment() leaves the segment … | Aug 10, 2026 |
| CVE-2026-68425 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reassembly Kernel-handled RMPP receive processing starts reassembly for active … | Aug 10, 2026 |
| CVE-2026-68424 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy_joins() mtd_concat_destroy() frees item->concat so calling mtd_virt_concat_put_mtd_devices(item->concat) leads to a … | Aug 10, 2026 |
| CVE-2026-68423 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy() mtd_concat_destroy() frees item->concat so calling mtd_virt_concat_put_mtd_devices(item->concat) after that leads … | Aug 10, 2026 |
| CVE-2026-68422 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() If we have … | Aug 10, 2026 |
| CVE-2026-68421 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx() put_prev_task_scx() warns when a runnable task … | Aug 10, 2026 |
| CVE-2026-68420 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: reject optional IPTFS templates in outbound policies syzbot reported a stack-out-of-bounds read in xfrm_state_find() … | Aug 10, 2026 |
| CVE-2026-68419 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Prevent rereg_mr for non-mem regions When a QP/CQ/SRQ is created, a two step process … | Aug 10, 2026 |
| CVE-2026-68418 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Prevent user-triggered null deref on QP create Previously, the user QP creation path would … | Aug 10, 2026 |
| CVE-2026-68417 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: publish QP after initialization siw_create_qp() currently calls siw_qp_add() before the queues, CQ pointers, state, … | Aug 10, 2026 |
| CVE-2026-68416 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mtd: fix double free and WARN_ON in add_mtd_device() error paths When device_register() or mtd_nvmem_add() fails … | Aug 10, 2026 |
| CVE-2026-68415 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: clear mode callbacks after failed mode setup xfrm_state_gc_task can run long after a failed … | Aug 10, 2026 |
| CVE-2026-68414 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel sched scan results work on unregister cfg80211_sched_scan_results() can queue rdev->sched_scan_res_wk from a … | Aug 10, 2026 |
| CVE-2026-68413 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() The memory allocated in the ipw2100_alloc_device() function … | Aug 10, 2026 |