Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49000
Total
3934
Critical
14522
High
14275
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-68093 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug If a … | Aug 10, 2026 |
| CVE-2026-59233 | UNKNOWN | — | Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, … | Aug 10, 2026 |
| CVE-2026-59090 | HIGH | 8.4 | A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens … | Aug 10, 2026 |
| CVE-2026-19429 | HIGH | 8.8 | Jenkins FilePath.untarFrom() does not validate symlink targets in extracted TAR archives, even in versions patched for CVE-2026-33001 and CVE-2026-70427. An authenticated attacker with job configuration … | Aug 10, 2026 |
| CVE-2026-19278 | MEDIUM | 6.8 | A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions … | Aug 10, 2026 |
| CVE-2026-18370 | UNKNOWN | — | entr is vulnerable to Heap-based buffer overflow in run_utility() function. The function allocates a fixed-size heap buffer using malloc(ARG_MAX) and copies command-line arguments into it. … | Aug 10, 2026 |
| CVE-2026-13206 | CRITICAL | 9.8 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects … | Aug 10, 2026 |
| CVE-2026-12984 | HIGH | 8.2 | Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. This issue affects WAH7601: through 20072026. | Aug 10, 2026 |
| CVE-2026-68092 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: time/jiffies: Register jiffies clocksource before usage Teddy reported that a XEN HVM has a long … | Aug 10, 2026 |
| CVE-2026-68091 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: HID: wacom: stop hardware after post-start probe failures wacom_parse_and_register() starts HID hardware before registering inputs … | Aug 10, 2026 |
| CVE-2026-68090 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: debugobjects: Plug race against a concurrent OOM disable syzbot reported a puzzling splat: WARNING: kernel/time/hrtimer.c:443 … | Aug 10, 2026 |
| CVE-2026-68089 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iio: core: fix uninitialized data in debugfs If *ppos is non-zero then simple_write_to_buffer() will not … | Aug 10, 2026 |
| CVE-2026-68088 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: function: rndis: add length check to response query Add variable representations for BufLength … | Aug 10, 2026 |
| CVE-2026-68087 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush() wacom_wac_queue_flush() is called via the .raw_event callback (wacom_raw_event → … | Aug 10, 2026 |
| CVE-2026-68086 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/khugepaged: write all dirty file folios when collapsing [There is no upstream commit, as this … | Aug 10, 2026 |
| CVE-2026-68085 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled HCI_UART_SENDING bit in tx_state means write_work is … | Aug 10, 2026 |
| CVE-2026-68084 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: fix location monitor leak in tsi148 bridge tsi148_probe() allocates a location monitor resource … | Aug 10, 2026 |
| CVE-2026-68083 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_create The SMB2 open lookup is rooted at the share … | Aug 10, 2026 |
| CVE-2026-64941 | UNKNOWN | — | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attacker to send a victim's browser to an origin of the attacker's … | Aug 10, 2026 |
| CVE-2026-59088 | MEDIUM | 5.5 | A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to … | Aug 10, 2026 |
| CVE-2026-72594 | HIGH | 7.6 | A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary JavaScript into the application by uploading a … | Aug 10, 2026 |
| CVE-2026-72593 | CRITICAL | 9.8 | A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including reading, writing, deleting, and … | Aug 10, 2026 |
| CVE-2026-72592 | CRITICAL | 9.8 | An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The application ships … | Aug 10, 2026 |
| CVE-2026-72591 | HIGH | 7.7 | A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP requests to arbitrary internal or … | Aug 10, 2026 |
| CVE-2026-72590 | CRITICAL | 9.8 | An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET … | Aug 10, 2026 |