| CVE-2026-67100 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
18.09.2026 |
9.8 |
| CVE-2026-67102 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
18.09.2026 |
8.1 |
| CVE-2026-67103 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
18.09.2026 |
7.6 |
| CVE-2026-75157 |
Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression) |
18.09.2026 |
|
| CVE-2026-12384 |
Broken Access Control in TECHIN2B Application |
18.09.2026 |
8.8 |
| CVE-2026-67101 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
18.09.2026 |
9.3 |
| CVE-2026-12739 |
WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion |
18.09.2026 |
4.3 |
| CVE-2026-12954 |
Mapster WP Maps <= 1.23.0 - Authenticated (Subscriber+) Arbitrary User Meta Write via 'acf-photo-gallery-groups' Parameter |
18.09.2026 |
8.8 |
| CVE-2026-13471 |
LatePoint <= 5.6.3 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking) |
18.09.2026 |
4.3 |
| CVE-2026-14323 |
Printcart Web to Print Product Designer for WooCommerce <= 2.8.5 - Unauthenticated Arbitrary File Read via 'folder' and 'mockups' Parameters |
18.09.2026 |
7.5 |
| CVE-2026-14472 |
Kubio AI Page Builder <= 2.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via kubio/copyright Block Content |
18.09.2026 |
6.4 |
| CVE-2026-15004 |
FileBird – WordPress Media Library Folders & File Manager <= 6.5.6 - Authenticated (Author+) Stored Cross-Site Scripting |
18.09.2026 |
5.4 |
| CVE-2026-15275 |
WP Multi Store Locator Pro <= 4.5.1 - Unauthenticated SQL Injection via 'store_locator_search_radius' Parameter |
18.09.2026 |
7.5 |
| CVE-2026-16777 |
Store Exporter <= 2.8.0 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read and Arbitrary File Deletion via 'filename' Parameter |
18.09.2026 |
4.9 |
| CVE-2026-17586 |
VK All in One Expansion Unit <= 9.118.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta |
18.09.2026 |
6.4 |
| CVE-2026-17607 |
WP Inventory Manager <= 2.5.1 - Authenticated (Contributor+) SQL Injection via 'where' Shortcode Attribute |
18.09.2026 |
6.5 |
| CVE-2026-18442 |
WCFM Marketplace <= 3.8.2 - Unauthenticated SQL Injection via 'wcfmmp_user_location_lat' / 'wcfmmp_user_location_lng' Parameter |
18.09.2026 |
7.5 |
| CVE-2026-75961 |
NEX-Forms <= 9.3.0 - Authenticated (Administrator+) SQL Injection via 'operator' Key of the 'additional_params' Parameter |
18.09.2026 |
4.9 |
| CVE-2026-85652 |
Photo Gallery by 10Web <= 1.8.44 - Authenticated (Author+) SQL Injection via 'album_id' Shortcode Attribute |
18.09.2026 |
6.5 |
| CVE-2026-85705 |
Location Manager <= 2.3.38 - Unauthenticated SQL Injection via 'latitude' and 'longitude' REST API Parameters |
18.09.2026 |
7.5 |
| CVE-2026-90981 |
Newsletter <= 9.3.8 - Reflected Cross-Site Scripting via 'nn' Parameter |
18.09.2026 |
6.1 |
| CVE-2026-92249 |
Qi Addons For Elementor <= 1.11 - Reflected DOM-Based Cross-Site Scripting via 's' Parameter |
18.09.2026 |
6.1 |
| CVE-2026-92554 |
ShopLentor <= 3.5.1 - Reflected Cross-Site Scripting via Query-String Parameter Name |
18.09.2026 |
6.1 |
| CVE-2026-92622 |
Strong Testimonials <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute |
18.09.2026 |
6.4 |
| CVE-2026-93494 |
Netty: netty-codec-stomp: io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated |
18.09.2026 |
|
| CVE-2026-89058 |
Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard config |
18.09.2026 |
|
| CVE-2026-89059 |
Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos) |
18.09.2026 |
|
| CVE-2024-27123 |
QcalAgent |
18.09.2026 |
|
| CVE-2024-38639 |
QTS |
18.09.2026 |
4.8 |
| CVE-2026-12106 |
Auto Upload Images <= 3.3.2 - Authenticated (Contributor+) Server-Side Request Forgery via 'src' Attribute of <img> Tags |
18.09.2026 |
6.4 |
| CVE-2026-17576 |
InfiniteWP Client <= 1.13.9 - Authenticated (Admin+) SQL Injection via 'iwp_get_comments_*' Array Key |
18.09.2026 |
6.5 |
| CVE-2026-18317 |
Foxtool All-in-One: Contact chat button, Custom login, Media optimize images <= 2.5.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification via 'option_key' Parameter of toggle_watermark AJAX Action |
18.09.2026 |
4.3 |
| CVE-2026-75016 |
Magazine Blocks <= 1.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'clientId' Block Attribute |
18.09.2026 |
6.4 |
| CVE-2026-75017 |
Magazine Blocks <= 1.8.6 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification / Site-Wide Template Takeover via Builder Templates REST Endpoint |
18.09.2026 |
4.3 |
| CVE-2026-84909 |
Custom Twitter Feeds <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute |
18.09.2026 |
6.4 |
| CVE-2026-89138 |
Filter Gallery <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'image_id' Parameter via ufg_save_gallery AJAX Action |
18.09.2026 |
4.3 |
| CVE-2026-89278 |
GPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Public Frontend Inline Script |
18.09.2026 |
5.3 |
| CVE-2026-89330 |
EmbedPress <= 4.6.5 - Reflected Cross-Site Scripting via 'hash' and 'unique' Parameters |
18.09.2026 |
6.1 |
| CVE-2026-89413 |
Filter Gallery <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Deletion via 'ufg_gallery_id' Parameter |
18.09.2026 |
8.1 |
| CVE-2026-91707 |
Divi <= 5.11.1 - Missing Authorization to Unauthenticated Arbitrary Registered Shortcode Execution via 'content' Parameter via Shortcode Module REST Endpoint |
18.09.2026 |
5.3 |
| CVE-2026-92561 |
Booking Calendar <= 11.8.2 - Reflected Cross-Site Scripting via 'options' Parameter |
18.09.2026 |
6.1 |
| CVE-2026-92619 |
Booking Calendar <= 11.8.2 - Authenticated (Editor+) Privilege Escalation to 'data_name' Parameter |
18.09.2026 |
7.2 |
| CVE-2026-92714 |
Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter |
18.09.2026 |
6.5 |
| CVE-2026-79713 |
Breeze Cache 1.2.5 - 2.5.14 - Unauthenticated Cache Poisoning via Unkeyed Tracking Parameters |
18.09.2026 |
6.5 |
| CVE-2026-86796 |
WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters |
18.09.2026 |
5.3 |
| CVE-2026-86800 |
WP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Compatibility Check |
18.09.2026 |
5.3 |
| CVE-2026-88994 |
All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block Attributes |
18.09.2026 |
6.6 |
| CVE-2026-90976 |
Clean Login < 1.19 - Unauthenticated Account Creation with Registration Disabled |
18.09.2026 |
5.3 |
| CVE-2026-90977 |
Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison |
18.09.2026 |
5.3 |
| CVE-2026-81340 |
MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation via IDOR |
18.09.2026 |
|
| CVE-2026-81810 |
All-in-One WP Migration and Backup < 7.111 - Authenticated Privilege Escalation to Admin via Import Secret Key Disclosure |
18.09.2026 |
|
| CVE-2026-84738 |
AF Companion < 2.2.0 - Shop Manager+ Arbitrary File Upload to RCE |
18.09.2026 |
|
| CVE-2026-84902 |
King Addons for Elementor < 51.1.81 - Contributor+ Stored XSS via Template Catalog Import |
18.09.2026 |
|
| CVE-2026-84903 |
King Addons for Elementor < 51.1.81 - Contributor+ Private Post Content Disclosure via kng_maintenance_page Shortcode |
18.09.2026 |
|
| CVE-2026-84904 |
King Addons for Elementor 51.1.56 - 51.1.80 - Author+ Missing Authorization via Image Optimizer |
18.09.2026 |
|
| CVE-2026-85009 |
RestroPress <= 3.4.6 - Unauthenticated Order Enumeration and Order Note Modification via Payment Recovery |
18.09.2026 |
|
| CVE-2026-85122 |
Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Confusion |
18.09.2026 |
|
| CVE-2026-85123 |
Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Registration Policy Bypass via Login Form Type Confusion |
18.09.2026 |
|
| CVE-2026-85127 |
VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment |
18.09.2026 |
|
| CVE-2026-85350 |
UpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought Together |
18.09.2026 |
|
| CVE-2026-87767 |
WP Shortcut Link <= 1.2.0 - Unauthenticated SQL Injection via url |
18.09.2026 |
|
| CVE-2026-87770 |
Price Drop Alert for WooCommerce <= 1.1 - Unauthenticated SQL Injection via product |
18.09.2026 |
|
| CVE-2026-87771 |
Product Question and Answer <= 1.1.0 - Unauthenticated SQL Injection via p_id and read |
18.09.2026 |
|
| CVE-2026-87774 |
Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQL Injection via week |
18.09.2026 |
|
| CVE-2026-87775 |
Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQLi via tzwrs_update_cell |
18.09.2026 |
|
| CVE-2026-87965 |
Easy Appointments < 4.0.2.2 - Unauthenticated Appointment Cancellation/Confirmation via Forgeable Email-Link Token |
18.09.2026 |
|
| CVE-2026-87966 |
Easy Appointments 4.0 - 4.0.2.1 - Unauthenticated Arbitrary Appointment Modification and Deletion via IDOR |
18.09.2026 |
|
| CVE-2026-88798 |
Really Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Growth via Spoofed Client IP Header |
18.09.2026 |
|
| CVE-2026-88825 |
iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings |
18.09.2026 |
|
| CVE-2026-88844 |
MasterStudy LMS 3.6.2 - < 3.7.50 - Instructor+ Student PII Disclosure via IDOR |
18.09.2026 |
|
| CVE-2026-88993 |
All Bootstrap Blocks <= 1.3.31 - Contributor+ Stored XSS via areoi/button type Attribute |
18.09.2026 |
|
| CVE-2026-89007 |
Bookit < 2.6.0.5 - Bookit Staff+ Arbitrary Appointment Deletion via Missing Authorization |
18.09.2026 |
|
| CVE-2026-89008 |
Bookit < 2.6.0.5 - Bookit Staff+ Appointment PII Disclosure |
18.09.2026 |
|
| CVE-2026-90978 |
Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check |
18.09.2026 |
|
| CVE-2026-90984 |
Generate PDF using Contact Form 7 < 4.2.2 - Unauthenticated Server-Side Request Forgery via Array-Valued Form Field |
18.09.2026 |
|
| CVE-2026-93485 |
WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability |
18.09.2026 |
7.1 |
| CVE-2026-18911 |
|
18.09.2026 |
7.5 |
| CVE-2026-18912 |
|
18.09.2026 |
7.7 |
| CVE-2026-17086 |
ShortPixel Image Optimizer <= 6.5.5 - Authenticated (Author+) PHP Object Injection via Nested JSON Post Content |
18.09.2026 |
8.8 |
| CVE-2026-14855 |
RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmega_update_menu_options AJAX Action |
18.09.2026 |
6.4 |
| CVE-2026-15650 |
RT Mega Menu <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute |
18.09.2026 |
6.4 |
| CVE-2026-92991 |
Biggopti Library (Various Versions) - Cross-Site Scripting via display_id from Sigmative API |
18.09.2026 |
5.4 |
| CVE-2026-93371 |
marcopiovanello yt-dlp-web-ui generic.go NewGenericDownload command injection |
18.09.2026 |
|
| CVE-2026-93467 |
HGiga|OAKlouds - Insecure Deserialization |
18.09.2026 |
|
| CVE-2026-93468 |
HGiga|OAKlouds - Arbitrary File Read |
18.09.2026 |
|
| CVE-2026-93331 |
GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds |
18.09.2026 |
|
| CVE-2026-68493 |
|
18.09.2026 |
|
| CVE-2026-77164 |
|
18.09.2026 |
|
| CVE-2026-77169 |
|
18.09.2026 |
|
| CVE-2026-77170 |
|
18.09.2026 |
|
| CVE-2026-82980 |
|
18.09.2026 |
|
| CVE-2026-82982 |
|
18.09.2026 |
|
| CVE-2026-82985 |
|
18.09.2026 |
|
| CVE-2026-93313 |
Freedesktop Poppler JBIG2Stream.cc readCodeTableSeg integer overflow |
18.09.2026 |
|
| CVE-2026-93314 |
Freedesktop Poppler FoFiTrueType.cc mapCodeToGID integer overflow |
18.09.2026 |
|
| CVE-2026-93455 |
django-page-cms through 2.0.13 Unauthorized Content Access via Staff Account |
18.09.2026 |
|
| CVE-2026-93456 |
django-page-cms through 2.0.13 CSRF via admin mutation views |
18.09.2026 |
|
| CVE-2026-79954 |
NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID |
18.09.2026 |
|
| CVE-2026-93311 |
Freedesktop Poppler SampledFunction Function.cc integer overflow |
18.09.2026 |
|
| CVE-2026-93312 |
Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference |
18.09.2026 |
|
| CVE-2026-93310 |
O-RAN-SC SMO OAM VES Collector allocation of resources |
18.09.2026 |
|
| CVE-2026-18441 |
LatePoint - Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]' Parameter |
17.09.2026 |
4.3 |
| CVE-2026-2585 |
Brizy – Page Builder <= 2.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'rootAttributes' Parameter |
17.09.2026 |
6.4 |
| CVE-2026-93309 |
O-RAN-SC SMO OAM VES Collector allocation of resources |
17.09.2026 |
|
| CVE-2026-93450 |
go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal and Unmarshal |
17.09.2026 |
|
| CVE-2026-93451 |
snappy-java through 1.1.10.8 Buffer Overflow via typed uncompress methods |
17.09.2026 |
|
| CVE-2026-93452 |
snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress |
17.09.2026 |
|
| CVE-2026-93453 |
SOGo before 5.12.11 Password Reset Token Interception via Origin Header |
17.09.2026 |
|
| CVE-2026-93454 |
Aureus ERP through 1.6.0 Stored XSS via Payment Term Note |
17.09.2026 |
|
| CVE-2026-62874 |
Azure Billing Elevation of Privilege Vulnerability |
17.09.2026 |
10 |
| CVE-2026-69843 |
Microsoft Fabric Elevation of Privilege Vulnerability |
17.09.2026 |
10 |
| CVE-2026-83946 |
Azure Portal Spoofing Vulnerability |
17.09.2026 |
8.2 |
| CVE-2026-85878 |
Azure Database for PostgreSQL Elevation of Privilege Vulnerability |
17.09.2026 |
9.9 |
| CVE-2026-85887 |
M365 Copilot Information Disclosure Vulnerability |
17.09.2026 |
7.7 |
| CVE-2026-93308 |
O-RAN-SC SMO OAM VES Collector allocation of resources |
17.09.2026 |
|
| CVE-2026-55946 |
Microsoft Copilot Information Disclosure Vulnerability |
17.09.2026 |
6.1 |
| CVE-2026-68791 |
Azure Machine Learning Information Disclosure Vulnerability |
17.09.2026 |
8.6 |
| CVE-2026-69399 |
Azure Arc Elevation of Privilege Vulnerability |
17.09.2026 |
10 |
| CVE-2026-69865 |
Microsoft Container Registry Elevation of Privilege Vulnerability |
17.09.2026 |
10 |
| CVE-2026-70009 |
Azure Arc Elevation of Privilege Vulnerability |
17.09.2026 |
9.3 |
| CVE-2026-70200 |
Azure Logic Apps Elevation of Privilege Vulnerability |
17.09.2026 |
10 |
| CVE-2026-77903 |
Microsoft Dataverse Elevation of Privilege Vulnerability |
17.09.2026 |
9 |
| CVE-2026-78501 |
Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability |
17.09.2026 |
7.4 |
| CVE-2026-83944 |
Azure Logic Apps Elevation of Privilege Vulnerability |
17.09.2026 |
10 |
| CVE-2026-85885 |
Microsoft 365 Copilot Elevation of Privilege Vulnerability |
17.09.2026 |
9.9 |
| CVE-2026-85889 |
Azure AI Foundry Elevation of Privilege Vulnerability |
17.09.2026 |
10 |
| CVE-2026-85917 |
Azure AI Foundry Elevation of Privilege Vulnerability |
17.09.2026 |
7.5 |
| CVE-2026-87701 |
Azure Cosmos DB Elevation of Privilege Vulnerability |
17.09.2026 |
9.6 |
| CVE-2026-87886 |
|
17.09.2026 |
|
| CVE-2026-65323 |
|
17.09.2026 |
|
| CVE-2026-93435 |
redis-parser through 3.0.0 Denial of Service via Unbounded Recursion |
17.09.2026 |
|
| CVE-2026-93436 |
vLLM through 0.29.0 Memory Exhaustion via Rejected Requests |
17.09.2026 |
|
| CVE-2026-54519 |
AI Agent Automation: Missing ownership checks in memory APIs allow cross-user memory read and deletion |
17.09.2026 |
8.8 |
| CVE-2026-54520 |
AI Agent Automation: Workflow file step path traversal allows read and write outside the expected directory |
17.09.2026 |
8.1 |
| CVE-2026-54642 |
CubeCart: CSRF Protection Missing for Download Resets and Card Deletions in orders.index.inc.php |
17.09.2026 |
|
| CVE-2026-54643 |
CubeCart: Missing Authorization Check for Order Note Deletion in orders.index.inc.php |
17.09.2026 |
5.4 |
| CVE-2026-54644 |
CubeCart: XSS via Anchor Tag Attribute Injection in gui.class.php Message System |
17.09.2026 |
6.1 |
| CVE-2026-54645 |
CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypass |
17.09.2026 |
4.8 |
| CVE-2026-54646 |
CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.inc.php |
17.09.2026 |
7.2 |
| CVE-2026-54647 |
CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php |
17.09.2026 |
7.2 |
| CVE-2026-54648 |
CubeCart: Missing Authorization Check in customers.gdpr.inc.php Leads to Unauthorized Customer Data Deletion |
17.09.2026 |
6.5 |
| CVE-2026-54734 |
Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction |
17.09.2026 |
10 |
| CVE-2026-76949 |
Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement |
17.09.2026 |
|
| CVE-2026-86688 |
Session id is not renewed on authentication in ash_authentication, allowing session fixation |
17.09.2026 |
|
| CVE-2026-54634 |
Hamlib: rigctld `send_raw` Stack Out-of-Bounds Write and Uninitialized Memory Disclosure |
17.09.2026 |
7.3 |
| CVE-2026-54670 |
WeGIA: Unauthenticated Auth Bypass + Local File Inclusion |
17.09.2026 |
9.1 |
| CVE-2026-54671 |
WeGIA: Authorization Bypass via Empty Resource Array in InternoControle |
17.09.2026 |
8.8 |
| CVE-2026-54767 |
WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php |
17.09.2026 |
9.1 |
| CVE-2026-54506 |
Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field |
17.09.2026 |
7.6 |
| CVE-2026-54608 |
MythicalDash: Unauthenticated payment bypass in Stripe success-redirect endpoint allows arbitrary free credit top-up |
17.09.2026 |
|
| CVE-2026-54612 |
Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-global |
17.09.2026 |
8.8 |
| CVE-2026-54613 |
Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parameter |
17.09.2026 |
5.4 |
| CVE-2026-93307 |
O-RAN-SC SMO OAM VES Collector memory allocation |
17.09.2026 |
|
| CVE-2026-50158 |
yutu: Arbitrary File Write via MCP `caption-download` Tool |
17.09.2026 |
7.7 |
| CVE-2026-53534 |
JabRef CAYW Sublime Text integration permits operating-system command injection |
17.09.2026 |
|
| CVE-2026-53555 |
Stored XSS via SVG Upload |
17.09.2026 |
|
| CVE-2026-53556 |
SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary File Read |
17.09.2026 |
|
| CVE-2026-53557 |
SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Command Execution |
17.09.2026 |
|
| CVE-2026-54507 |
Vvveb oEmbedProxy vulnerable to server-side request forgery |
17.09.2026 |
|
| CVE-2026-50291 |
OpenImageIO: Segmentation Fault in BmpInput::read_native_scanline (bmpinput.cpp:399) |
17.09.2026 |
5.5 |
| CVE-2026-53554 |
SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import Processing |
17.09.2026 |
|
| CVE-2026-54343 |
Frappe LMS: Path Traversal in SCORM File Serving |
17.09.2026 |
|
| CVE-2026-54633 |
PoDoFo: Heap Out-of-Bounds Read in Indexed Color Space Image Decoding (FetchScanLine) |
17.09.2026 |
|
| CVE-2026-78668 |
|
17.09.2026 |
|
| CVE-2026-11432 |
|
17.09.2026 |
|
| CVE-2026-14311 |
Booking for Appointments and Events Calendar – Amelia (Premium) <= 2.4.4 - Authenticated (Custom+) Missing Authorization to Limited Account Takeover |
17.09.2026 |
5.4 |
| CVE-2026-16582 |
Booking for Appointments and Events Calendar - Amelia <= 2.4.5 - Missing Authorization to Unauthenticated Payment Bypass |
17.09.2026 |
5.3 |
| CVE-2026-16750 |
Motors – Car Dealership & Classified Listings <= 1.4.120 - Missing Authorization to Unauthenticated Private/Draft/Password-Protected Listings Exposure |
17.09.2026 |
5.3 |
| CVE-2026-73638 |
Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd |
18.09.2026 |
|
| CVE-2026-73639 |
Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8 |
18.09.2026 |
|
| CVE-2026-93426 |
SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names |
17.09.2026 |
|
| CVE-2026-77281 |
Caddy: rewrite placeholder re-expansion |
17.09.2026 |
6.5 |
| CVE-2026-93372 |
|
17.09.2026 |
|
| CVE-2026-93373 |
|
17.09.2026 |
|
| CVE-2026-93374 |
|
17.09.2026 |
|
| CVE-2026-93375 |
|
17.09.2026 |
|
| CVE-2026-93376 |
|
17.09.2026 |
|
| CVE-2026-93377 |
|
17.09.2026 |
|
| CVE-2026-93378 |
|
17.09.2026 |
|
| CVE-2026-93379 |
|
17.09.2026 |
|
| CVE-2026-93380 |
|
17.09.2026 |
|
| CVE-2026-93381 |
|
17.09.2026 |
|
| CVE-2026-93382 |
|
17.09.2026 |
|
| CVE-2026-93383 |
|
17.09.2026 |
|
| CVE-2026-93384 |
|
17.09.2026 |
|
| CVE-2026-93385 |
|
17.09.2026 |
|
| CVE-2026-93386 |
|
17.09.2026 |
|
| CVE-2026-93387 |
|
17.09.2026 |
|
| CVE-2025-62167 |
|
17.09.2026 |
|
| CVE-2026-11314 |
|
17.09.2026 |
|
| CVE-2026-77615 |
Paella Player: Stored XSS via caption cue text |
17.09.2026 |
8.7 |
| CVE-2026-15815 |
CVE-2026-15815 CVE Record |
17.09.2026 |
8.8 |
| CVE-2026-57847 |
|
17.09.2026 |
|
| CVE-2026-54596 |
ITFlow: Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration |
17.09.2026 |
8.1 |
| CVE-2026-54597 |
ITFlow: Authenticated Time-Based Blind SQL Injection in ITFlow via expires Parameter |
17.09.2026 |
8.3 |
| CVE-2026-54907 |
Caddy Proxy Manager: Registrations enabled by default allows creating users with "user" permission |
17.09.2026 |
5.3 |
| CVE-2026-93395 |
Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer() |
17.09.2026 |
|
| CVE-2026-10594 |
|
17.09.2026 |
|
| CVE-2026-48977 |
OpenSlide: Arbitrary memory write with crafted Ventana BIF file |
17.09.2026 |
|
| CVE-2026-49137 |
|
17.09.2026 |
|
| CVE-2026-54339 |
Glean: Server-Side Request Forgery (SSRF) with Full Response Disclosure via Malicious RSS Feed in /api/feeds/discover |
17.09.2026 |
7.7 |
| CVE-2026-54354 |
MapServer: PostGIS Numeric Filter Value SQL Injection in MapServer Runtime Query Translation |
17.09.2026 |
8.2 |
| CVE-2026-54355 |
MapServer: Reflected XSS in OpenLayers HTML Output via `HTTP_X_FORWARDED_HOST` |
17.09.2026 |
|
| CVE-2026-54510 |
Speakr: CSRF bypass via unauthenticated API token parameter in csrf_exempt_for_api_tokens hook |
17.09.2026 |
7.1 |
| CVE-2026-54604 |
OpenSlide: openslide_read_region() returns uninitialized memory with libtiff 4.7.1 |
17.09.2026 |
|
| CVE-2026-67071 |
HCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensitive Information Before Storage or Transfer |
17.09.2026 |
6.5 |
| CVE-2026-68523 |
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service |
17.09.2026 |
7.5 |
| CVE-2026-76154 |
CVE-2026-76154 CVE Record |
17.09.2026 |
7.3 |
| CVE-2026-86049 |
Jupyter Server: 5xx request logging leaks token-bearing Referer header values |
17.09.2026 |
7.1 |
| CVE-2026-93393 |
Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream |
17.09.2026 |
|
| CVE-2026-93394 |
libmongoc SCRAM client nonce-validation bypass |
17.09.2026 |
|
| CVE-2021-3030 |
|
17.09.2026 |
|
| CVE-2025-55787 |
|
17.09.2026 |
|
| CVE-2026-45140 |
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution |
17.09.2026 |
9.8 |
| CVE-2026-45143 |
Chamilo LMS: Student-to-admin stored XSS in private messages via v-html |
17.09.2026 |
9 |
| CVE-2026-50022 |
Metacat acts as unintended proxy to backend Apache SOLR engine |
17.09.2026 |
5.8 |
| CVE-2026-50275 |
Datadog PHP Tracer: Improper parsing of W3C baggage headers may lead to DoS |
17.09.2026 |
7.5 |
| CVE-2026-50277 |
dd-trace-cpp: Improper parsing of W3C baggage headers may lead to DoS |
17.09.2026 |
7.5 |
| CVE-2026-52483 |
|
17.09.2026 |
|
| CVE-2026-54237 |
Wavelog: Unauthenticated Remote Code Execution |
17.09.2026 |
|
| CVE-2026-54460 |
OpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeover |
17.09.2026 |
9.8 |
| CVE-2026-54501 |
Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviors |
17.09.2026 |
|
| CVE-2026-54521 |
FairEmail: Cross-site scripting (XSS) in AMP message rendering (ActivityAMP) |
17.09.2026 |
6.1 |
| CVE-2026-54565 |
rhwp browser extension performs SSRF / private-network requests and leaks HWP preview data to untrusted pages |
17.09.2026 |
4.7 |
| CVE-2026-54916 |
NetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE via missing `tests/__init__.py` + SSRF via unfixed `NETBOX_DT_LIBRARY_URL` → Cloud Metadata credential theft |
17.09.2026 |
8.8 |
| CVE-2026-54918 |
NetBox Device Type Library: PR-controllable upstream clone URL (NETBOX_DT_LIBRARY_URL) enables SSRF and test-data substitution from CI |
17.09.2026 |
5.3 |
| CVE-2026-68537 |
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service |
17.09.2026 |
7.5 |
| CVE-2026-54752 |
NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull Request |
17.09.2026 |
9.6 |
| CVE-2026-50125 |
MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion |
17.09.2026 |
7.5 |
| CVE-2026-50285 |
Pomerium: Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback |
17.09.2026 |
7.5 |
| CVE-2026-54594 |
OmniBlocks: Spamming in Discussions tab possible via disc.yml |
17.09.2026 |
|
| CVE-2026-57846 |
|
17.09.2026 |
|
| CVE-2026-54495 |
Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters |
17.09.2026 |
4.3 |
| CVE-2026-54618 |
Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user |
17.09.2026 |
9.4 |
| CVE-2026-54626 |
SAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch) |
17.09.2026 |
9.8 |
| CVE-2026-54627 |
SAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth) |
17.09.2026 |
9.8 |
| CVE-2026-54692 |
SAIL: XBM X10 decoder writes 2 bytes per literal into a 1-byte-per-literal buffer (heap out-of-bounds write) |
17.09.2026 |
7.8 |
| CVE-2026-54716 |
Valhalla: Degenerate exclude_polygons (collinear points, zero area) causes OOM in /sources_to_targets |
17.09.2026 |
7.5 |
| CVE-2026-45720 |
Omni: TOCTOU race condition allows multiple concurrent uses of a single-use SAML session token |
17.09.2026 |
7 |
| CVE-2026-45723 |
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic |
17.09.2026 |
2.7 |
| CVE-2026-45726 |
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService |
17.09.2026 |
7.6 |
| CVE-2026-92757 |
Malformed connection string may disable field level encryption |
17.09.2026 |
|
| CVE-2026-92756 |
Combining encryption settings may disable encryption |
17.09.2026 |
|
| CVE-2026-92758 |
Logs may collect sensitive information |
17.09.2026 |
|
| CVE-2026-92943 |
Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python |
17.09.2026 |
8.1 |
| CVE-2026-92993 |
Dromara mayfly-go Machine Script Feature machine_script.go RunMachineScript os command injection |
17.09.2026 |
|
| CVE-2026-93337 |
NetworkManager-l2tp Privilege Escalation via pppd Plugin Injection |
17.09.2026 |
|
| CVE-2026-19477 |
Stack-based Buffer Overflow Vulnerability in Linux (uldaq) |
17.09.2026 |
7.8 |
| CVE-2026-90997 |
Keycloak: Replay protection bypass leads to unauthorized access via database driver semantics mismatch |
17.09.2026 |
7.4 |
| CVE-2026-92230 |
Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching |
17.09.2026 |
|
| CVE-2026-49292 |
Kiwi TCMS: The /init-db/ page renders and responds to requests after first use |
17.09.2026 |
0 |
| CVE-2026-52851 |
Traccar: Authenticated Blind SQL Injection in DELETE /api/permissions |
17.09.2026 |
7.1 |
| CVE-2026-52852 |
Traccar: Uncontrolled Infinite Loop DoS via Group Parent Cycle |
17.09.2026 |
6.5 |
| CVE-2026-54239 |
FaustWP — Authentication Bypass via Initialization Vector Modification in Token Envelope |
17.09.2026 |
8.8 |
| CVE-2026-54253 |
TS3 Manager: Reflected XSS via /api/download port parameter steals operator session |
17.09.2026 |
8.2 |
| CVE-2026-54504 |
MCP Documentation Server: Web UI API binds to all interfaces without authentication by default |
17.09.2026 |
8.8 |
| CVE-2026-54524 |
Frappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode Report |
17.09.2026 |
|
| CVE-2026-54571 |
ESPAsyncWebServer: Integer overflow in multipart boundary parser causes denial of service |
17.09.2026 |
|
| CVE-2026-54617 |
GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler |
17.09.2026 |
9.8 |
| CVE-2026-54649 |
punchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloudflare forward() drops the relay Reply-To |
17.09.2026 |
|
| CVE-2026-92992 |
Dromara mayfly-go AI Assistant ai.go authorization |
17.09.2026 |
|
| CVE-2026-47252 |
Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari) |
17.09.2026 |
9 |
| CVE-2026-52727 |
lxc-ci: Pacman keyring stored in archlinux image with a private key |
17.09.2026 |
7.2 |
| CVE-2026-54451 |
Elixir protobuf: Unbounded recursion depth in embedded-message decoding |
17.09.2026 |
|
| CVE-2026-55061 |
uniget: EDITOR Command Injection in uniget CLI |
17.09.2026 |
|
| CVE-2026-55062 |
uniget: Path Traversal in Hook Files - Directory Escape Vulnerability |
17.09.2026 |
|
| CVE-2026-92927 |
SourceCodester Drug Recommendation System drug_recommendor.sql information disclosure |
17.09.2026 |
|
| CVE-2026-89038 |
Verizon Cloud for Android < 26.7.10 Path Traversal via OneTouchUploadActivity |
17.09.2026 |
|
| CVE-2026-92926 |
code-projects Matrimonial System partner_preference.php writepartnerprefs sql injection |
17.09.2026 |
|
| CVE-2026-44235 |
rabbitmq-c: size_t underflow in AMQP frame length computation leads to out-of-bounds read |
17.09.2026 |
6.5 |
| CVE-2026-44236 |
rabbitmq-c: Heap buffer overflow in AMQP login handshake via undersized connection.tune.frame_max |
17.09.2026 |
7.1 |
| CVE-2026-52836 |
OpenDDS: out-of-bounds `rd_ptr` dereference in `RtpsSampleHeader::init` — triggered by malformed RTPS submessage, remotely exploitable denial of service |
17.09.2026 |
|
| CVE-2026-54053 |
Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults |
17.09.2026 |
9.6 |
| CVE-2026-54446 |
NetLicensing MCP Server: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode |
17.09.2026 |
8.1 |
| CVE-2026-54546 |
CloudTAK: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard |
17.09.2026 |
5 |
| CVE-2026-54551 |
WireGuard Portal: Authenticated WebSocket /api/v0/ws broadcasts all peers' and interfaces' traffic stats to every user (missing per-user authorization) |
17.09.2026 |
4.3 |
| CVE-2026-54676 |
Scoold: GET /api/posts/{id}/answers leaks private-space replies when personal API tokens are enabled |
17.09.2026 |
6.5 |
| CVE-2026-54677 |
Scoold: Authenticated user can post replies and comments to private-space questions without space membership |
17.09.2026 |
6.5 |
| CVE-2026-54576 |
mport package installation has symlink TOCTOU in chown and chmod handling |
17.09.2026 |
|
| CVE-2026-54579 |
mport mirror-selection ping accepts insufficiently validated ICMP replies |
17.09.2026 |
|
| CVE-2026-54587 |
mport directory asset installation is vulnerable to symlink and path traversal races |
17.09.2026 |
|
| CVE-2026-54575 |
mport package fetch and clean paths are vulnerable to TOCTOU filesystem races |
17.09.2026 |
|
| CVE-2026-54578 |
mport verify can compare stale checksum data after hashing failures |
17.09.2026 |
|
| CVE-2026-54580 |
mport index decompression can leave partial or corrupt index data after zstd failures |
17.09.2026 |
|
| CVE-2026-54582 |
mport package installation can overwrite existing unmanaged or differently owned files |
17.09.2026 |
|
| CVE-2026-54585 |
mport sample file handling can write outside the configured root |
17.09.2026 |
|
| CVE-2026-54586 |
mport permits repository and package mirror fetches over insecure transport |
17.09.2026 |
|
| CVE-2026-8674 |
Assertion failure in the DNS stub resolver with a long search domain |
17.09.2026 |
5.3 |
| CVE-2026-54577 |
mport audit can inspect the wrong package when options are present |
17.09.2026 |
|
| CVE-2026-54581 |
mport bootstrap index fetch can continue after hash verification failure |
17.09.2026 |
|
| CVE-2026-54583 |
mport package bundle downloads allow unsafe destination filenames |
17.09.2026 |
|
| CVE-2026-28326 |
SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability |
18.09.2026 |
8.8 |
| CVE-2026-85716 |
AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verified |
17.09.2026 |
3.7 |
| CVE-2026-93292 |
SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders |
17.09.2026 |
|
| CVE-2026-93295 |
MISP Background Job Argument Injection via Console Path Switches Enables Remote Code Execution |
17.09.2026 |
|
| CVE-2026-93296 |
MISP Overmind: Stored Cross-Site Scripting via Unescaped Object Names in Statistics Legends |
17.09.2026 |
|
| CVE-2026-85720 |
AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNECT request |
17.09.2026 |
5.9 |
| CVE-2026-90050 |
net/sched: fq: clamp quantum and initial_quantum in change path |
17.09.2026 |
|
| CVE-2026-90051 |
tcp: reject non zerocopy devmem tx |
17.09.2026 |
|
| CVE-2026-90052 |
dm-integrity: fix buffer overflow with keyed discard |
17.09.2026 |
|
| CVE-2026-90053 |
net/sched: sch_htb: limit htb_classify inner-class filter hops |
17.09.2026 |
|
| CVE-2026-90054 |
tcp: fix corruption of urgent data on multi-segment retransmit |
17.09.2026 |
|
| CVE-2026-90055 |
usb: atm: usbatm: fix invalid ci_range initialization |
17.09.2026 |
|
| CVE-2026-90056 |
net: fec: only stop PTP if it was initialized |
17.09.2026 |
|
| CVE-2026-90057 |
slip: remove slip_hangup() to fix use-after-free in slip_receive_buf() |
17.09.2026 |
|
| CVE-2026-90058 |
net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup |
17.09.2026 |
|
| CVE-2026-90059 |
net: stmmac: restore NET_IP_ALIGN in the RX DMA offset |
17.09.2026 |
|
| CVE-2026-90060 |
ALSA: control: Don't add invalid kcontrols to LED layer |
17.09.2026 |
|
| CVE-2026-90061 |
netfilter: nf_tables: skip double clone set expressions on element insert |
17.09.2026 |
|
| CVE-2026-90062 |
netfilter: nf_tables: move hardware offload step after building the chain blob |
17.09.2026 |
|
| CVE-2026-90063 |
virtio-net: Ensure that TCP packets don't overflow gso_segs |
17.09.2026 |
|
| CVE-2026-90064 |
drm/xe: Reject page faults from non-fault-mode scratch VMs |
17.09.2026 |
|
| CVE-2026-90065 |
net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure |
17.09.2026 |
|
| CVE-2026-90066 |
samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify |
17.09.2026 |
|
| CVE-2026-90067 |
libceph: validate banner payload length |
17.09.2026 |
|
| CVE-2026-90068 |
ASoC: dapm: Fix off-by-one check on the second enum channel |
17.09.2026 |
|
| CVE-2026-90069 |
crypto: acomp - allocate async request context when cloning |
17.09.2026 |
|
| CVE-2026-90070 |
tpm: st33zp24: Return zero on status read failure |
17.09.2026 |
|
| CVE-2026-90071 |
net/sched: sch_teql: restore skb->dev on the slave failure path |
17.09.2026 |
|
| CVE-2026-90072 |
net/sched: sfq: clamp quantum to avoid signed overflow soft lockup |
17.09.2026 |
|
| CVE-2026-90073 |
net/sched: hhf: clamp quantum before hhf_change() to avoid overflow |
17.09.2026 |
|
| CVE-2026-90074 |
net/sched: fq_pie: clamp default quantum to avoid signed overflow |
17.09.2026 |
|
| CVE-2026-90075 |
net/sched: fq_codel: clamp default quantum and mtu |
17.09.2026 |
|
| CVE-2026-90076 |
net/sched: fq: add overflow bounds to quantum and initial quantum |
17.09.2026 |
|
| CVE-2026-90077 |
net: fix a resource leak in copy_net_ns() error handling path |
17.09.2026 |
|
| CVE-2026-90078 |
net/sched: act_skbmod: fix length calculations and avoid invalid header warnings |
17.09.2026 |
|
| CVE-2026-90079 |
octeontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init() |
17.09.2026 |
|
| CVE-2026-90080 |
octeontx2-pf: fix NULL deref of af_xdp_zc_qidx on rep setup |
17.09.2026 |
|
| CVE-2026-90081 |
net/rds: use wq_has_sleeper() in rds_cong_map_updated() |
17.09.2026 |
|
| CVE-2026-90082 |
net: mana: Cap MSI-X vectors to the device MSI-X table size |
17.09.2026 |
|
| CVE-2026-90083 |
net/sched: act_ife: Only operate on Ethernet frames |
17.09.2026 |
|
| CVE-2026-90084 |
octeontx2-vf: fix workqueue and netdev race in probe/remove |
17.09.2026 |
|
| CVE-2026-90085 |
octeontx2-af: fix NULL deref in NIX TM tree debugfs read path |
17.09.2026 |
|
| CVE-2026-90086 |
xsk: honor XDP_TX_METADATA in zero-copy path |
17.09.2026 |
|
| CVE-2026-90087 |
Bluetooth: do not leak an hci_conn when a second LE connect is rejected |
17.09.2026 |
|
| CVE-2026-90088 |
Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop |
17.09.2026 |
|
| CVE-2026-90089 |
Bluetooth: btnxpuart: Validate the FW dump header length |
17.09.2026 |
|
| CVE-2026-90090 |
Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path |
17.09.2026 |
|
| CVE-2026-90091 |
Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan |
17.09.2026 |
|
| CVE-2026-90092 |
Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN |
17.09.2026 |
|
| CVE-2026-90093 |
Bluetooth: L2CAP: access chan->conn safely in get/setsockopt |
17.09.2026 |
|
| CVE-2026-90094 |
arm64: process: Fix context switching MTE store-only tag check |
17.09.2026 |
|
| CVE-2026-90095 |
fuse: Fix the condition to enable over-io-uring |
17.09.2026 |
|
| CVE-2026-90096 |
fuse: invalidate the correct range after O_APPEND direct write |
17.09.2026 |
|
| CVE-2026-90097 |
Drivers: hv: vmbus: Skip VMBus module cleanup for non-nested root partition |
17.09.2026 |
|
| CVE-2026-90098 |
net: sparx5: fix sleep in atomic context in MAC table access |
17.09.2026 |
|
| CVE-2026-90099 |
net/sched: account classifier filter allocations to memcg |
17.09.2026 |
|
| CVE-2026-90100 |
ptp: netc: fix period truncation and potential divide-by-zero in PEROUT |
17.09.2026 |
|
| CVE-2026-90101 |
bnxt_en: Fix call to hardware monitoring event handler |
17.09.2026 |
|
| CVE-2026-90102 |
NFSv4/pnfs: key the data server cache on the NFS version |
17.09.2026 |
|
| CVE-2026-90103 |
NFSv4.2: fix LAYOUTSTATS send buffer exhaustion |
17.09.2026 |
|
| CVE-2026-90104 |
NFSv4.1: zero referring call lists before decoding |
17.09.2026 |
|
| CVE-2026-90105 |
vxlan: fix reading neigh ha |
17.09.2026 |
|
| CVE-2026-90106 |
net: bridge: arp/nd proxy: fix reading neigh ha |
17.09.2026 |
|
| CVE-2026-90107 |
net/smc: free pending qentry in smc_llc_flow_stop() before memset |
17.09.2026 |
|
| CVE-2026-90108 |
net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition |
17.09.2026 |
|
| CVE-2026-90109 |
net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue |
17.09.2026 |
|
| CVE-2026-90110 |
inetpeer: randomize RB-tree node comparison using SipHash |
17.09.2026 |
|
| CVE-2026-90111 |
ip6mr: do not clone dst in ip6mr_cache_report() |
17.09.2026 |
|
| CVE-2026-90112 |
net: qlcnic: validate unified ROM sections before loading |
17.09.2026 |
|
| CVE-2026-90113 |
netdevsim: update queue NAPI association on queue reset |
17.09.2026 |
|
| CVE-2026-90114 |
net: bridge: Reject descending VLAN tunnel ranges |
17.09.2026 |
|
| CVE-2026-90115 |
xsk: fix NULL pointer dereference in __xsk_rcv() |
17.09.2026 |
|
| CVE-2026-90116 |
ALSA: mtpav: shut down output timer before card teardown |
17.09.2026 |
|
| CVE-2026-90117 |
ntfs: validate usa_ofs before preserving the update sequence number |
17.09.2026 |
|
| CVE-2026-90118 |
ntfs: fix off-by-one page overflow in ntfs_decompress() |
17.09.2026 |
|
| CVE-2026-90119 |
ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup |
17.09.2026 |
|
| CVE-2026-90120 |
irqchip/gic-v5: Check get_logical_index() return value in MADT IAFFID parsing |
17.09.2026 |
|
| CVE-2026-90121 |
irqchip/gic-v5: Clear per-CPU IRS data on teardown |
17.09.2026 |
|
| CVE-2026-90122 |
clk: visconti: Make sure clk_init_data is fully initialized |
17.09.2026 |
|
| CVE-2026-90123 |
irqchip/ast2700-intc: Avoid allocating in the irq_domain activate() callback |
17.09.2026 |
|
| CVE-2026-90124 |
irqchip/renesas-rzg2l: Fix loss of interrupt |
17.09.2026 |
|
| CVE-2026-90125 |
smb: client: fix request buffer leak in smb2_new_read_req() |
17.09.2026 |
|
| CVE-2026-90126 |
rtc: pcf8563: fix clock provider leak on unbind |
17.09.2026 |
|
| CVE-2026-90127 |
virtio: rtc: time out alarm requests |
17.09.2026 |
|
| CVE-2026-90128 |
vdpa/mlx5: fix wrong list iterated in add_direct_chain error path |
17.09.2026 |
|
| CVE-2026-90129 |
virtio_balloon: quiesce balloon work before device shutdown |
17.09.2026 |
|
| CVE-2026-90130 |
vdpa_sim: fix cleanup after worker creation failure |
17.09.2026 |
|
| CVE-2026-90131 |
ntfs: serialize resident iomap reads with mrec_lock |
17.09.2026 |
|
| CVE-2026-90132 |
ntfs: reject unprivileged writes to reserved $LX* xattrs |
17.09.2026 |
|
| CVE-2026-90133 |
ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib() |
17.09.2026 |
|
| CVE-2026-90134 |
ntfs: fix kmap_local_page() usage in compress |
17.09.2026 |
|
| CVE-2026-90135 |
net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs() |
17.09.2026 |
|
| CVE-2026-90136 |
platform/x86/amd/hsmp: Reject negative power cap writes in hwmon |
17.09.2026 |
|
| CVE-2026-90137 |
platform/x86: hp-bioscfg: fix password encoding bounds check |
17.09.2026 |
|
| CVE-2026-90138 |
vsock: don't check the listener's sk_err in vsock_accept() |
17.09.2026 |
|
| CVE-2026-90139 |
fuse: check for NULL root inode in fuse_fill_super_submount |
17.09.2026 |
|
| CVE-2026-90140 |
cuse: wait for pending RCU callbacks on module exit |
17.09.2026 |
|
| CVE-2026-90141 |
ipvs: fix integer overflow in ftp helper port/address parsing |
17.09.2026 |
|
| CVE-2026-90142 |
virtio_net: Fix resize of the RX ring |
17.09.2026 |
|
| CVE-2026-90143 |
net: kcm: Hold RCU read lock while running BPF parser |
17.09.2026 |
|
| CVE-2026-90144 |
dpll: fix NULL deref in dpll_device_ops() during teardown race |
17.09.2026 |
|
| CVE-2026-90145 |
hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed |
17.09.2026 |
|
| CVE-2026-90146 |
bpf, xdp: move offload check into dev_xdp_install() |
17.09.2026 |
|
| CVE-2026-90147 |
clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate() |
17.09.2026 |
|
| CVE-2026-90148 |
NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease() |
17.09.2026 |
|
| CVE-2026-90149 |
NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data servers |
17.09.2026 |
|
| CVE-2026-90150 |
pnfs/blocklayout: Fix device leaks on parse failure |
17.09.2026 |
|
| CVE-2026-90151 |
NFSv4: remove callback IDR entry on client allocation failure |
17.09.2026 |
|
| CVE-2026-90152 |
smb/server: fix session leak in ksmbd_session_register() |
17.09.2026 |
|
| CVE-2026-90153 |
ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size |
17.09.2026 |
|
| CVE-2026-90154 |
ksmbd: scope session state changes to bound connections |
17.09.2026 |
|
| CVE-2026-90155 |
ksmbd: detach blocked lock requests before freeing |
17.09.2026 |
|
| CVE-2026-90156 |
ksmbd: safely discard unregistered deferred locks |
17.09.2026 |
|
| CVE-2026-90157 |
bpf: Reject negative optlen in cgroup getsockopt hook |
17.09.2026 |
|
| CVE-2026-90158 |
m68k: nfcon: Do not call console_is_registered() in nfcon_device() |
17.09.2026 |
|
| CVE-2026-90159 |
bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks |
17.09.2026 |
|
| CVE-2026-90160 |
lwt_bpf: Restore reserved headroom after xmit program |
17.09.2026 |
|
| CVE-2026-90161 |
erofs: fix interlaced ztailpacking pclusters |
17.09.2026 |
|
| CVE-2026-90162 |
ksmbd: defer publishing granted locks to prevent UAF/double-free race |
17.09.2026 |
|
| CVE-2026-90163 |
smb/server: call ksmbd_proc_cleanup() on module init failure |
17.09.2026 |
|
| CVE-2026-90164 |
smb/server: abort initialization when proc setup fails |
17.09.2026 |
|
| CVE-2026-90165 |
smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger() |
17.09.2026 |
|
| CVE-2026-90166 |
smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request() |
17.09.2026 |
|
| CVE-2026-90167 |
ksmbd: serialize oplock close with pending break ownership |
17.09.2026 |
|
| CVE-2026-90168 |
ksmbd: retain connection for pending notify work |
17.09.2026 |
|
| CVE-2026-90169 |
ksmbd: free preauth sessions on connection teardown |
17.09.2026 |
|
| CVE-2026-90170 |
ksmbd: validate ipc response length before dereferencing its fields |
17.09.2026 |
|
| CVE-2026-90171 |
smb: smbdirect: release pending child sockets outside the handler lock |
17.09.2026 |
|
| CVE-2026-90172 |
smb: smbdirect: destroy QP before mem pools on accept failure |
17.09.2026 |
|
| CVE-2026-90173 |
smb: smbdirect: free completion queues with ib_free_cq() |
17.09.2026 |
|
| CVE-2026-90174 |
ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user() |
17.09.2026 |
|
| CVE-2026-90175 |
smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer |
17.09.2026 |
|
| CVE-2026-90176 |
ksmbd: Do not skip lock checks for single-byte ranges |
17.09.2026 |
|
| CVE-2026-90177 |
bpf: Check pointer type for all atomic RMW paths |
17.09.2026 |
|
| CVE-2026-90178 |
hwmon: (coretemp) Fix core_data leak on CPUs without PTS |
17.09.2026 |
|
| CVE-2026-90179 |
apparmor: fix deadlock in complain-mode change_hat |
17.09.2026 |
|
| CVE-2026-90180 |
block: mtip32xx: synchronize ioctls with device removal |
17.09.2026 |
|
| CVE-2026-90181 |
ublk: avoid teardown retry loop on xarray allocation failure |
17.09.2026 |
|
| CVE-2026-90182 |
blk-iocost: clear delay state when freeing policy data |
17.09.2026 |
|
| CVE-2026-90183 |
blk-iolatency: clear delay state when freeing policy data |
17.09.2026 |
|
| CVE-2026-90184 |
null_blk: serialize configfs attribute updates with device setup |
17.09.2026 |
|
| CVE-2026-90185 |
null_blk: serialize configfs attribute stores with the lock |
17.09.2026 |
|
| CVE-2026-90186 |
null_blk: reject per-device queue resize for shared tag set |
17.09.2026 |
|
| CVE-2026-90187 |
null_blk: free zones array on device power-off |
17.09.2026 |
|
| CVE-2026-90188 |
null_blk: free global tag_set on init error path |
17.09.2026 |
|
| CVE-2026-90189 |
null_blk: register configfs subsystem after creating default devices |
17.09.2026 |
|
| CVE-2026-90190 |
null_blk: use DEFINE_MUTEX for the file-scope mutex |
17.09.2026 |
|
| CVE-2026-90191 |
mailbox: riscv-sbi-mpxy: validate RPMI notification lengths |
17.09.2026 |
|
| CVE-2026-90192 |
mailbox: qcom-cpucp: handle NULL data in send_data callback |
17.09.2026 |
|
| CVE-2026-90193 |
mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler |
17.09.2026 |
|
| CVE-2026-90194 |
ACPI: scan: fix bus ID cleanup on device_add() failures |
17.09.2026 |
|
| CVE-2026-90195 |
riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args |
17.09.2026 |
|
| CVE-2026-90196 |
ASoC: SOF: validate topology volume range before allocation |
17.09.2026 |
|
| CVE-2026-90197 |
HID: haptic: don't write an uninitialized value to unhandled usages |
17.09.2026 |
|
| CVE-2026-90198 |
ALSA: core: Fix use-after-free in snd_card_do_free() |
17.09.2026 |
|
| CVE-2026-90199 |
fs/ntfs3: reject out-of-range evcn in mi_enum_attr() |
17.09.2026 |
|
| CVE-2026-90200 |
fs/ntfs3: fix integer overflow in MFT cluster validation |
17.09.2026 |
|
| CVE-2026-90201 |
net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race |
17.09.2026 |
|
| CVE-2026-90202 |
scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers |
17.09.2026 |
|
| CVE-2026-90203 |
Squashfs: check block offset is not negative |
17.09.2026 |
|
| CVE-2026-90204 |
ocfs2: validate DIO orphan slot during inode read |
17.09.2026 |
|
| CVE-2026-90205 |
ocfs2: validate orphan slot during inode read |
17.09.2026 |
|
| CVE-2026-90206 |
nvmet: fix max_qid race between configfs and controller allocation |
17.09.2026 |
|
| CVE-2026-90207 |
ALSA: seq: midi: Serialize input teardown with event_input |
17.09.2026 |
|
| CVE-2026-90208 |
clocksource/drivers/samsung_pwm: Switch to raw_spinlock_t type |
17.09.2026 |
|
| CVE-2026-90209 |
s390/debug: Fix deadlock during unregister |
17.09.2026 |
|
| CVE-2026-90210 |
bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure |
17.09.2026 |
|
| CVE-2026-90211 |
bpf, s390: Clear fetch destination on faulting arena atomic |
17.09.2026 |
|
| CVE-2026-90212 |
arm64/efi: Avoid voluntary preemption with efi_mm installed |
17.09.2026 |
|
| CVE-2026-90213 |
firewire: core: fix memory leak in error path of build_tree() |
17.09.2026 |
|
| CVE-2026-90214 |
ASoC: xilinx: formatter_pcm: fix stream_data leak on open error |
17.09.2026 |
|
| CVE-2026-90215 |
mtd: ubi: Release device reference on busy detach |
17.09.2026 |
|
| CVE-2026-90216 |
ubi: Fix rollback for explicit UBI device numbers |
17.09.2026 |
|
| CVE-2026-90217 |
bpf: Compare iterator types during state pruning |
17.09.2026 |
|
| CVE-2026-90218 |
RDMA/cma: Fix WARNING in res_to_rt |
17.09.2026 |
|
| CVE-2026-90219 |
RDMA/cxgb4: Free debugfs on registration failure |
17.09.2026 |
|
| CVE-2026-90220 |
ALSA: seq: Don't leak the extension cell pointer in the bounce payload |
17.09.2026 |
|
| CVE-2026-90221 |
nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing |
17.09.2026 |
|
| CVE-2026-90222 |
nfc: pn533: hold a reference to the request skb during send_frame |
17.09.2026 |
|
| CVE-2026-90223 |
nfc: llcp: bound SNL TLV parsing to the skb and add length checks |
17.09.2026 |
|
| CVE-2026-90224 |
nfc: nci: fix double completion race in nci_data_exchange_complete |
17.09.2026 |
|
| CVE-2026-90225 |
nfc: llcp: read llcp_sock->local under the socket lock in getsockopt |
17.09.2026 |
|
| CVE-2026-90226 |
nfc: llcp: avoid userspace overflow on invalid optlen |
17.09.2026 |
|
| CVE-2026-90227 |
nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() |
17.09.2026 |
|
| CVE-2026-90228 |
nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns() |
17.09.2026 |
|
| CVE-2026-90229 |
nvme-apple: Destroy the admin queue on removal |
17.09.2026 |
|
| CVE-2026-90230 |
nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() |
17.09.2026 |
|
| CVE-2026-90231 |
apparmor: fix unconfined user namespace restriction forced stack |
17.09.2026 |
|
| CVE-2026-90232 |
amt: Don't support cross-netns setup. |
17.09.2026 |
|
| CVE-2026-90233 |
nvme-pci: release descriptor pools on probe failure |
17.09.2026 |
|
| CVE-2026-90234 |
NFS: Return a delegation the client fails to record |
17.09.2026 |
|
| CVE-2026-90235 |
sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE |
17.09.2026 |
|
| CVE-2026-90236 |
NFSD: Release the export reference when reaping open stateids |
17.09.2026 |
|
| CVE-2026-90237 |
netfilter: nft_ct: move custom expectation support to helper |
17.09.2026 |
|
| CVE-2026-90238 |
media: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() error path |
17.09.2026 |
|
| CVE-2026-90239 |
media: amd: isp4: release partial allocations in isp4if_alloc_fw_gpumem() |
17.09.2026 |
|
| CVE-2026-90240 |
iommu/vt-d: Flush context cache with correct SID when tearing down aliases |
17.09.2026 |
|
| CVE-2026-90241 |
iommu/vt-d: Tear down scalable-mode context on probe failure |
17.09.2026 |
|
| CVE-2026-90242 |
iommu/vt-d: Fix iopf_refcount leak on RID domain replacement |
17.09.2026 |
|
| CVE-2026-90243 |
iommu/vt-d: Clear Present bit before tearing down copied context entry |
17.09.2026 |
|
| CVE-2026-90244 |
iommu/dma: Restore locking around msi_page_list |
17.09.2026 |
|
| CVE-2026-90245 |
fbdev: kyro: Validate overlay viewport coordinates |
17.09.2026 |
|
| CVE-2026-90246 |
apparmor: fix integer overflow in verify_tags() bounds check |
17.09.2026 |
|
| CVE-2026-90247 |
bpf: Fix mmap_lock leak in irq_work path |
17.09.2026 |
|
| CVE-2026-90248 |
net/sched: cls_api: fix teardown of an adopted proto on insert-race loss |
17.09.2026 |
|
| CVE-2026-90249 |
iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes |
17.09.2026 |
|
| CVE-2026-90250 |
bpf, cgroup: Fix storage null-ptr-deref after replacing prog |
17.09.2026 |
|
| CVE-2026-90251 |
Bluetooth: MSFT: validate evt_prefix_len against the response length |
17.09.2026 |
|
| CVE-2026-90252 |
Bluetooth: MGMT: free the HCI command when it is cancelled |
17.09.2026 |
|
| CVE-2026-90253 |
Bluetooth: MGMT: free the mesh send cancel command when it is cancelled |
17.09.2026 |
|
| CVE-2026-90254 |
Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths |
17.09.2026 |
|
| CVE-2026-90255 |
Bluetooth: hci_conn: fix the SCO setup context lifetime |
17.09.2026 |
|
| CVE-2026-90256 |
Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind |
17.09.2026 |
|
| CVE-2026-90257 |
Bluetooth: virtio_bt: avoid OOB read of build info string |
17.09.2026 |
|
| CVE-2026-90258 |
pinctrl: airoha: add missed IRQ resource helpers |
17.09.2026 |
|
| CVE-2026-90259 |
btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data() |
17.09.2026 |
|
| CVE-2026-90260 |
btrfs: zoned: don't clobber the extent buffer when zeroing it out |
17.09.2026 |
|
| CVE-2026-90261 |
btrfs: zoned: flush active metadata block group at btree_writepages() start |
17.09.2026 |
|
| CVE-2026-90262 |
btrfs: retry verity reads for not-uptodate Merkle folios |
17.09.2026 |
|
| CVE-2026-90263 |
btrfs: check if root is readonly when setting posix acl |
17.09.2026 |
|
| CVE-2026-90264 |
btrfs: always wait for ordered extents to avoid OE races |
17.09.2026 |
|
| CVE-2026-90265 |
btrfs: defrag: fix deadlock between defrag and delalloc space reservation |
17.09.2026 |
|
| CVE-2026-90266 |
btrfs: zoned: don't force read-only on transient -EAGAIN from reloc merge |
17.09.2026 |
|
| CVE-2026-90267 |
scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails |
17.09.2026 |
|
| CVE-2026-90268 |
scsi: sd: Fix error handling in sd_probe() after large pool creation failure |
17.09.2026 |
|
| CVE-2026-90269 |
bpf: Reject load-acquire from pointers requiring fault protection |
17.09.2026 |
|
| CVE-2026-90270 |
arm_mpam: Disable driver unbind to avoid UAF |
17.09.2026 |
|
| CVE-2026-90271 |
arm_mpam: Fix a NULL pointer dereference on unbinding after an error interrupt |
17.09.2026 |
|
| CVE-2026-90272 |
perf: arm_pmuv3: Zero initialize hw_id branch stack field |
17.09.2026 |
|
| CVE-2026-90273 |
coresight: etm4x: missing cscfg_csdev_disable_active_config() in perf enable |
17.09.2026 |
|
| CVE-2026-90274 |
coresight: etm4x: fix underflow for usage of (nrseqstate - 1) |
17.09.2026 |
|
| CVE-2026-90275 |
md/raid1: don't set array_frozen in raid1_takeover() |
17.09.2026 |
|
| CVE-2026-90276 |
md/md-llbitmap: stop daemon timer rearm on destroy |
17.09.2026 |
|
| CVE-2026-90277 |
md/md-llbitmap: prevent create failure bitmap UAF |
17.09.2026 |
|
| CVE-2026-90278 |
md: wait for behind writes before destroying bitmap |
17.09.2026 |
|
| CVE-2026-90279 |
md/raid5: round bitmap stripes with sector division |
17.09.2026 |
|
| CVE-2026-90280 |
phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend |
17.09.2026 |
|
| CVE-2026-90281 |
phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend |
17.09.2026 |
|
| CVE-2026-90282 |
phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend |
17.09.2026 |
|
| CVE-2026-90283 |
hugetlbfs: release subpool on fill_super failure |
17.09.2026 |
|
| CVE-2026-90284 |
firmware_loader: do not queue completed sysfs fallback requests |
17.09.2026 |
|
| CVE-2026-90285 |
scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path |
17.09.2026 |
|
| CVE-2026-90286 |
drm/amdgpu/gfx6: Use PFP on the compute queues too |
17.09.2026 |
|
| CVE-2026-90287 |
phy: sunplus: fix error handling in sp_uphy_init() |
17.09.2026 |
|
| CVE-2026-90288 |
phy: renesas: rcar-gen2: Fix double of_node_put on phy creation failure |
17.09.2026 |
|
| CVE-2026-90289 |
drm/amd/display: Resize MST HDCP per-connector arrays to 32 |
17.09.2026 |
|
| CVE-2026-90290 |
arm64: hibernate: Restore DAIF state on error |
17.09.2026 |
|
| CVE-2026-90291 |
module/dups: Fix use-after-free in kmod_dup_req lifetime handling |
17.09.2026 |
|
| CVE-2026-90292 |
RDMA/siw: Fix use-after-free in siw_accept() |
17.09.2026 |
|
| CVE-2026-90293 |
IB/isert: post the full-feature receive buffers after session registration |
17.09.2026 |
|
| CVE-2026-90294 |
IB/isert: delay the final Login Response until the session is registered |
17.09.2026 |
|
| CVE-2026-90295 |
cpufreq: imx6q: fix out-of-bounds write when probed more than once |
17.09.2026 |
|
| CVE-2026-90296 |
cpufreq: imx6q: fix devres accumulation across driver rebind |
17.09.2026 |
|
| CVE-2026-90297 |
drm/sun4i: crtc: Propagate layer initialization error |
17.09.2026 |
|
| CVE-2026-90298 |
drm/sun4i: tcon: Drop TCON TOP device reference |
17.09.2026 |
|
| CVE-2026-90299 |
bpf: Fix sleepable check for tracing/lsm prog |
17.09.2026 |
|
| CVE-2026-90300 |
bpf: Clear buf on error in __bpf_get_task_stack |
17.09.2026 |
|
| CVE-2026-90301 |
ocfs2: o2hb: quiesce negotiate handlers and timeout work |
17.09.2026 |
|
| CVE-2026-90302 |
ocfs2: synchronize heartbeat callbacks with o2net teardown |
17.09.2026 |
|
| CVE-2026-90303 |
ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults |
17.09.2026 |
|
| CVE-2026-90304 |
ARM: 9484/1: enable interrupts when unhandled user faults are triggered |
17.09.2026 |
|
| CVE-2026-90305 |
ARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK |
17.09.2026 |
|
| CVE-2026-90306 |
ARM: 9481/2: breakpoint: CFI breakpoints only on demand |
17.09.2026 |
|
| CVE-2026-90307 |
RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ |
17.09.2026 |
|
| CVE-2026-90308 |
RDMA/erdma: Hold QP references for AE and CM processing |
17.09.2026 |
|
| CVE-2026-90309 |
RDMA/erdma: Hold CQ references when processing EQ events |
17.09.2026 |
|
| CVE-2026-90310 |
xen/xenbus: check otherend_id only after it has been initialized |
17.09.2026 |
|
| CVE-2026-90311 |
thermal: hwmon: Remove hwmon class device along with its parent |
17.09.2026 |
|
| CVE-2026-90312 |
bpf: Check load-acquire src ptr type before the load |
17.09.2026 |
|
| CVE-2026-90313 |
bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed |
17.09.2026 |
|
| CVE-2026-90314 |
remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry() |
17.09.2026 |
|
| CVE-2026-90315 |
PCI/sysfs: Add lockdown checks to legacy I/O and memory handlers |
17.09.2026 |
|
| CVE-2026-90316 |
drm/omap: dsi: Do not copy isr table |
17.09.2026 |
|
| CVE-2026-90317 |
bpf: Invalidate RCU pointers after final spin unlock |
17.09.2026 |
|
| CVE-2026-90318 |
fat: release buffer head after rebuilding parent |
17.09.2026 |
|
| CVE-2026-90319 |
rapidio: clear mport->net when rio_add_net() fails |
17.09.2026 |
|
| CVE-2026-90320 |
ocfs2: validate external xattr entries when reading metadata |
17.09.2026 |
|
| CVE-2026-90321 |
ocfs2: validate inline xattrs during inode block validation |
17.09.2026 |
|
| CVE-2026-90322 |
ocfs2/cluster: keep heartbeat local node stable |
17.09.2026 |
|
| CVE-2026-90323 |
ublk: validate auto buf reg before taking uring_cmd |
17.09.2026 |
|
| CVE-2026-90324 |
ublk: check import_ubuf() return value |
17.09.2026 |
|
| CVE-2026-90325 |
blk-cgroup: skip dying blkg in blkcg_activate_policy() |
17.09.2026 |
|
| CVE-2026-90326 |
blk-cgroup: fix race between policy activation and blkg destruction |
17.09.2026 |
|
| CVE-2026-90327 |
phonet: pep: do not write beyond optlen in getsockopt |
17.09.2026 |
|
| CVE-2026-90328 |
HID: steam: Reject short reads |
17.09.2026 |
|
| CVE-2026-90329 |
HID: synchronize input before cleaning up a failed probe |
17.09.2026 |
|
| CVE-2026-90330 |
HID: logitech-hidpp: Fix FF device cleanup on init failure |
17.09.2026 |
|
| CVE-2026-90331 |
HID: asus: refactor the two workqueues and init sequence |
17.09.2026 |
|
| CVE-2026-90332 |
PCI: dwc: ep: Flush cached MSI write before unmapping the iATU |
17.09.2026 |
|
| CVE-2026-90333 |
dm-integrity: replace forgeable discard filler with a keyed sector marker |
17.09.2026 |
|
| CVE-2026-90334 |
tty: clear cdev pointer after cdev_add() failure |
17.09.2026 |
|
| CVE-2026-90335 |
tty: skip cdev_del() when no cdev is registered |
17.09.2026 |
|
| CVE-2026-90336 |
serial: core: clear freed pointers on uart_register_driver() failure |
17.09.2026 |
|
| CVE-2026-90337 |
serial: core: do fallible allocations before the console can be registered |
17.09.2026 |
|
| CVE-2026-90338 |
serial: amba-pl011: keep console clock enabled for atomic writes |
17.09.2026 |
|
| CVE-2026-90339 |
powerpc/syscall: Fix syscall skip handling for seccomp and ptrace |
17.09.2026 |
|
| CVE-2026-90340 |
pinctrl: generic: free maps on pinctrl_generic_to_map() failure |
17.09.2026 |
|
| CVE-2026-90341 |
firmware: coreboot: Validate table bounds |
17.09.2026 |
|
| CVE-2026-90342 |
bpf: Fix mmap_lock deadlock on arena lock failure |
17.09.2026 |
|
| CVE-2026-90343 |
wifi: cfg80211: stop PMSR before P2P and NAN teardown |
17.09.2026 |
|
| CVE-2026-90344 |
wifi: mac80211: disconnect on CSA to channel 0 |
17.09.2026 |
|
| CVE-2026-90345 |
wifi: brcmfmac: fix P2P action frame handling without device vif |
17.09.2026 |
|
| CVE-2026-90346 |
wifi: nl80211: clean up color-change beacon data on errors |
17.09.2026 |
|
| CVE-2026-90347 |
arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry |
17.09.2026 |
|
| CVE-2026-90348 |
wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump |
17.09.2026 |
|
| CVE-2026-90349 |
wifi: mt76: mt7996: fix out-of-bounds link array access in mt7996_tx() |
17.09.2026 |
|
| CVE-2026-90350 |
wifi: mt76: reject out-of-range link ids in mt76_vif_link() |
17.09.2026 |
|
| CVE-2026-90351 |
wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed |
17.09.2026 |
|
| CVE-2026-90352 |
wifi: mt76: mt7915: release hif2 reference on probe IRQ failure |
17.09.2026 |
|
| CVE-2026-90353 |
wifi: mt76: mt7915: fix ext PHY use-after-free on register error path |
17.09.2026 |
|
| CVE-2026-90354 |
wifi: mt76: mt7915: fix double hif2 init on the non-WED path |
17.09.2026 |
|
| CVE-2026-90355 |
wifi: mt76: mt7996: clear stale link state on full reset |
17.09.2026 |
|
| CVE-2026-90356 |
wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset |
17.09.2026 |
|
| CVE-2026-90357 |
wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement |
17.09.2026 |
|
| CVE-2026-90358 |
bpf, x86: Fix trampoline stack size for 128-bit arguments |
17.09.2026 |
|
| CVE-2026-90359 |
bpf: Reject >8 byte return values on return-reading trampoline paths |
17.09.2026 |
|
| CVE-2026-90360 |
regulator: core: use system_freezable_wq for init complete work |
17.09.2026 |
|
| CVE-2026-90361 |
wifi: ath11k: fix leak in ath11k_service_ready_ext_event() |
17.09.2026 |
|
| CVE-2026-90362 |
drm/msm/dsi: Drop dev_pm_opp_set_rate(0) |
17.09.2026 |
|
| CVE-2026-90363 |
drm/msm: don't tear down KMS twice when KMS init fails |
17.09.2026 |
|
| CVE-2026-90364 |
ACPI: processor: Unregister cpufreq notifier on init failure |
17.09.2026 |
|
| CVE-2026-90365 |
wifi: mt76: cancel reset and rc work on device unregister |
17.09.2026 |
|
| CVE-2026-90366 |
wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV |
17.09.2026 |
|
| CVE-2026-90367 |
wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER |
17.09.2026 |
|
| CVE-2026-90368 |
wifi: mt76: mt7915: unwind state on add_interface failure |
17.09.2026 |
|
| CVE-2026-90369 |
wifi: mt76: fix out-of-bounds access in mmio copy helpers |
17.09.2026 |
|
| CVE-2026-90370 |
wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config |
17.09.2026 |
|
| CVE-2026-90371 |
wifi: mt76: fix RXDMAD_C buffer recycling race |
17.09.2026 |
|
| CVE-2026-90372 |
wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss |
17.09.2026 |
|
| CVE-2026-90373 |
wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear |
17.09.2026 |
|
| CVE-2026-90374 |
wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[] |
17.09.2026 |
|
| CVE-2026-90375 |
wifi: mt76: fix non-AQL packet accounting for MLO stations |
17.09.2026 |
|
| CVE-2026-90376 |
wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP |
17.09.2026 |
|
| CVE-2026-90377 |
wifi: mt76: fix RX data queuing of RRO 3.0 |
17.09.2026 |
|
| CVE-2026-90378 |
wifi: mt76: mt792x: Fix memory leak in SDIO TX path |
17.09.2026 |
|
| CVE-2026-90379 |
wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash |
17.09.2026 |
|
| CVE-2026-90380 |
wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete |
17.09.2026 |
|
| CVE-2026-90381 |
wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx() |
17.09.2026 |
|
| CVE-2026-90382 |
wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length |
17.09.2026 |
|
| CVE-2026-90383 |
misc: sgi-gru: remove interrupt-context page-table walks |
17.09.2026 |
|
| CVE-2026-90384 |
iomap: release the folio batch on iomap callback failures |
17.09.2026 |
|
| CVE-2026-90385 |
md/raid1: create serial pool adding rdev to array with serialize_policy=1 |
17.09.2026 |
|
| CVE-2026-90386 |
i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices |
17.09.2026 |
|
| CVE-2026-90387 |
swiotlb: Preserve allocation virtual address for dynamic pools |
17.09.2026 |
|
| CVE-2026-90388 |
iommu/dma: Check atomic pool allocation result directly |
17.09.2026 |
|
| CVE-2026-90389 |
md: scope memalloc_noio to allocation critical sections |
17.09.2026 |
|
| CVE-2026-90390 |
md/bitmap: resume array on backlog_store() error path |
17.09.2026 |
|
| CVE-2026-90391 |
lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone |
17.09.2026 |
|
| CVE-2026-90392 |
bpf: Fix potential UAF when reading bpf link info |
17.09.2026 |
|
| CVE-2026-90393 |
bpf: Fix potential UAF in bpf_netns_link_update_prog |
17.09.2026 |
|
| CVE-2026-90394 |
power: supply: sc2731_charger: cancel work on remove |
17.09.2026 |
|
| CVE-2026-90395 |
power: supply: isp1704_charger: cancel work on remove |
17.09.2026 |
|
| CVE-2026-90396 |
block: fix dio leak on metadata mapping error |
17.09.2026 |
|
| CVE-2026-90397 |
firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published |
17.09.2026 |
|
| CVE-2026-90398 |
wifi: ath11k: fix stride mismatch in mac_phy_caps_parse() |
17.09.2026 |
|
| CVE-2026-90399 |
wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() |
17.09.2026 |
|
| CVE-2026-90400 |
md: recheck spare changes before starting sync |
17.09.2026 |
|
| CVE-2026-90401 |
md: remove REQ_NOWAIT support from raid1/10/456 |
17.09.2026 |
|
| CVE-2026-90402 |
bus: mhi: host: Fix controller cleanup on EDL sysfs failure |
17.09.2026 |
|
| CVE-2026-90403 |
wifi: rtlwifi: pci: fix error path in rtl_pci_probe() |
17.09.2026 |
|
| CVE-2026-90404 |
platform/chrome: cros_ec_debugfs: Unregister panic notifier |
17.09.2026 |
|
| CVE-2026-90405 |
media: stm32: dcmi: fix some error handling bugs in probe() |
17.09.2026 |
|
| CVE-2026-90406 |
media: qcom: iris: handle runtime PM resume failure in core deinit |
17.09.2026 |
|
| CVE-2026-90407 |
wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() |
17.09.2026 |
|
| CVE-2026-90408 |
wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event() |
17.09.2026 |
|
| CVE-2026-90409 |
drm/panthor: Add vm_bind region with kbo range overlap check |
17.09.2026 |
|
| CVE-2026-90410 |
spi: davinci: switch to managed controller allocation |
17.09.2026 |
|
| CVE-2026-90411 |
nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request |
17.09.2026 |
|
| CVE-2026-90412 |
nvmet: fix return status of RMI log page on allocation failure |
17.09.2026 |
|
| CVE-2026-90413 |
IB/isert: reject login PDUs declaring more data than was received |
17.09.2026 |
|
| CVE-2026-90414 |
IB/isert: reject PDUs declaring more data than was received |
17.09.2026 |
|
| CVE-2026-90415 |
RDMA/cxgb4: free STAG index when TPT entry write fails |
17.09.2026 |
|
| CVE-2026-90416 |
RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs |
17.09.2026 |
|
| CVE-2026-90417 |
RDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_entry() |
17.09.2026 |
|
| CVE-2026-90418 |
nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch |
17.09.2026 |
|
| CVE-2026-90419 |
nilfs2: prevent out-of-bounds read in super root block parsing |
17.09.2026 |
|
| CVE-2026-90420 |
nilfs2: fix infinite loop in nilfs_clean_segments() |
17.09.2026 |
|
| CVE-2026-90421 |
PCI: Fix UAF when probe runs concurrent to dyn ID removal |
17.09.2026 |
|
| CVE-2026-90422 |
clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path |
17.09.2026 |
|
| CVE-2026-90423 |
RDMA/rxe: Fix UAF in ODP init error-handling path |
17.09.2026 |
|
| CVE-2026-90424 |
iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path |
17.09.2026 |
|
| CVE-2026-90425 |
iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID |
17.09.2026 |
|
| CVE-2026-90426 |
iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs |
17.09.2026 |
|
| CVE-2026-90427 |
iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc() |
17.09.2026 |
|
| CVE-2026-90428 |
iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs |
17.09.2026 |
|
| CVE-2026-90429 |
iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init |
17.09.2026 |
|
| CVE-2026-90430 |
iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized |
17.09.2026 |
|
| CVE-2026-90431 |
remoteproc: Prevent crash handling to race with rproc_del() |
17.09.2026 |
|
| CVE-2026-90432 |
sched_ext: Abort directly from the hardlockup handler |
17.09.2026 |
|
| CVE-2026-90433 |
spi: oc-tiny: switch to managed controller allocation |
17.09.2026 |
|
| CVE-2026-90434 |
isofs: release zisofs block pointer buffer head |
17.09.2026 |
|
| CVE-2026-90435 |
RDMA/mlx5: Fix integer overflow of user QP buffer size |
17.09.2026 |
|
| CVE-2026-92476 |
crypto: keembay - Initialize completion before requesting IRQ |
17.09.2026 |
|
| CVE-2026-92477 |
scsi: ufs: debugfs: Reserve space for a string terminator |
17.09.2026 |
|
| CVE-2026-92478 |
scsi: ufs: core: Validate connected lane counts |
17.09.2026 |
|
| CVE-2026-92479 |
scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags |
17.09.2026 |
|
| CVE-2026-92480 |
scsi: ufs: core: Validate string descriptors |
17.09.2026 |
|
| CVE-2026-92481 |
pinctrl: mediatek: free EINT resources on unbind |
17.09.2026 |
|
| CVE-2026-92482 |
pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip |
17.09.2026 |
|
| CVE-2026-92483 |
liveupdate: Remember FLB retrieve() status |
17.09.2026 |
|
| CVE-2026-92484 |
cxl/region: Fix use-after-free in find_pos_and_ways() error path |
17.09.2026 |
|
| CVE-2026-92485 |
bpf: Fix WARNING in bpf_tracing_link_release |
17.09.2026 |
|
| CVE-2026-92486 |
bpf: Fix CFI mismatch in task work callback |
17.09.2026 |
|
| CVE-2026-92487 |
exfat: fix valid_size extension over a shared writable mapping |
17.09.2026 |
|
| CVE-2026-92488 |
RDMA/erdma: complete object teardown when the destroy command fails |
17.09.2026 |
|
| CVE-2026-92489 |
xfrm: Fix skb double-free in xfrm_dev_direct_output() |
17.09.2026 |
|
| CVE-2026-92490 |
firmware: arm_scmi: Unrequest devices if driver registration fails |
17.09.2026 |
|
| CVE-2026-92491 |
firmware: arm_scmi: Roll back partial protocol table registration |
17.09.2026 |
|
| CVE-2026-92492 |
cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks |
17.09.2026 |
|
| CVE-2026-92493 |
cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active |
17.09.2026 |
|
| CVE-2026-92494 |
ext4: fix buffer_head leak in ext4_init_orphan_info |
17.09.2026 |
|
| CVE-2026-92495 |
RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap |
17.09.2026 |
|
| CVE-2026-92496 |
wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() |
17.09.2026 |
|
| CVE-2026-92497 |
wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() |
17.09.2026 |
|
| CVE-2026-92498 |
wifi: ath6kl: avoid buffer overreads in WMI event handlers |
17.09.2026 |
|
| CVE-2026-92499 |
ext4: validate readdir offset before accessing dirent |
17.09.2026 |
|
| CVE-2026-92500 |
ext4: use fsdata to track inline data write state and fix race |
17.09.2026 |
|
| CVE-2026-92501 |
ext4: drain in-flight DIO before buffered write fallback |
17.09.2026 |
|
| CVE-2026-92502 |
ext4: clear stale xarray tags on folios skipped during writeback |
17.09.2026 |
|
| CVE-2026-92503 |
ext4: fix ABBA deadlock in ext4_xattr_inode_cache_find() |
17.09.2026 |
|
| CVE-2026-92504 |
thermal: intel: int3400: clean up ODVP on probe failures |
17.09.2026 |
|
| CVE-2026-92505 |
iommu/amd: Fix undefined behavior in devid_write debugfs function |
17.09.2026 |
|
| CVE-2026-92506 |
firmware: arm_scmi: Fix requested device removal race |
17.09.2026 |
|
| CVE-2026-92507 |
RDMA/core: Fix potential use after free in ib_dealloc_pd_user() |
17.09.2026 |
|
| CVE-2026-92508 |
RDMA/core: Fix potential use after free in ib_free_cq() |
17.09.2026 |
|
| CVE-2026-92509 |
RDMA/core: Fix potential use after free in counter_release() |
17.09.2026 |
|
| CVE-2026-92510 |
RDMA/core: Fix potential use after free in ib_destroy_srq_user() |
17.09.2026 |
|
| CVE-2026-92511 |
RDMA/core: Fix potential use after free in ib_destroy_cq_user() |
17.09.2026 |
|
| CVE-2026-92512 |
RDMA/core: Fix use after free in ib_query_qp() |
17.09.2026 |
|
| CVE-2026-92513 |
RDMA/mana_ib: drain QP references after partial table insertion |
17.09.2026 |
|
| CVE-2026-92514 |
RDMA/erdma: Fix CEQ tasklet use-after-free on removal |
17.09.2026 |
|
| CVE-2026-92515 |
bpf: Preserve unique-field state across nested structs |
17.09.2026 |
|
| CVE-2026-92516 |
bpf: Fix offset warn check for bpf_res_spin_lock |
17.09.2026 |
|
| CVE-2026-92517 |
bpf, riscv: Fix extable handling for arena load_acquire |
17.09.2026 |
|
| CVE-2026-92518 |
riscv, bpf: Fix kernel stack corruption in tailcall with CFI |
17.09.2026 |
|
| CVE-2026-92519 |
riscv, bpf: Fix memory leak in bpf_jit_free |
17.09.2026 |
|
| CVE-2026-92520 |
bpf: Zero queue and stack outputs on lock failure |
17.09.2026 |
|
| CVE-2026-92521 |
ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root |
17.09.2026 |
|
| CVE-2026-92522 |
ACPI: processor: validate MADT IOAPIC entry bounds |
17.09.2026 |
|
| CVE-2026-92523 |
RDMA/nldev: validate dynamic counter attribute length |
17.09.2026 |
|
| CVE-2026-92524 |
irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() |
17.09.2026 |
|
| CVE-2026-92525 |
RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] |
17.09.2026 |
|
| CVE-2026-92980 |
HortusFox-Web < 6.1 Remote Code Execution via Import/Export |
17.09.2026 |
|
| CVE-2026-93037 |
RDMA/hfi1: Propagate sdma_txinit_ahg() errors |
17.09.2026 |
|
| CVE-2026-93038 |
iio: dac: ad5686: missing NULL check on match data |
17.09.2026 |
|
| CVE-2026-93039 |
ASoC: meson: Keep link pointers valid on realloc failure |
17.09.2026 |
|
| CVE-2026-93040 |
dmaengine: dw-edma: Serialize channel state checks |
17.09.2026 |
|
| CVE-2026-93041 |
dmaengine: dw-edma: Serialize abort state updates |
17.09.2026 |
|
| CVE-2026-93042 |
dmaengine: dw-edma: Terminate all descriptors without callbacks |
17.09.2026 |
|
| CVE-2026-93043 |
bpf: Disallow interpreter fallback for gotox insn |
17.09.2026 |
|
| CVE-2026-93044 |
bpf: Disallow interpreter fallback for arena-related insns |
17.09.2026 |
|
| CVE-2026-93045 |
bpf: Reject arena frees below the arena base |
17.09.2026 |
|
| CVE-2026-93046 |
software node: Fix software_node_get_reference_args() with index -1 |
17.09.2026 |
|
| CVE-2026-93047 |
drm/v3d: Associate BOs with every job that accesses them |
17.09.2026 |
|
| CVE-2026-93048 |
mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() |
17.09.2026 |
|
| CVE-2026-93049 |
mtd: mtdswap: Avoid freeing registered blktrans device twice |
17.09.2026 |
|
| CVE-2026-93050 |
ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove |
17.09.2026 |
|
| CVE-2026-93051 |
misc: ad525x_dpot: use driver core groups for sysfs files |
17.09.2026 |
|
| CVE-2026-93052 |
misc: bcm-vk: Use acquire/release for msgq_inited |
17.09.2026 |
|
| CVE-2026-93053 |
speakup: keyhelp: guard letter_offsets possible out-of-range indexing |
17.09.2026 |
|
| CVE-2026-93054 |
uio: Fix stale info pointer in failed registration path |
17.09.2026 |
|
| CVE-2026-93055 |
UDF symlink pathComponent header OOB read |
17.09.2026 |
|
| CVE-2026-93056 |
usb: gadget: f_uac1_legacy: remove broken string configfs attributes |
17.09.2026 |
|
| CVE-2026-93057 |
scsi: ufs: core: Avoid possible memory reclaim deadlock in TX EQTR context |
17.09.2026 |
|
| CVE-2026-93058 |
drm/msm: Only fini scheduler after successful init |
17.09.2026 |
|
| CVE-2026-93059 |
drm/msm: Fix task_struct reference leak in recover_worker |
17.09.2026 |
|
| CVE-2026-93060 |
drm/msm/adreno: fix use after free on error path in a6xx_gpu_init() |
17.09.2026 |
|
| CVE-2026-93061 |
gpu: host1x: Avoid stack over-read in debug output helpers |
17.09.2026 |
|
| CVE-2026-93062 |
wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments |
17.09.2026 |
|
| CVE-2026-93063 |
wifi: iwlwifi: mei: check SAP message length before reading it |
17.09.2026 |
|
| CVE-2026-93064 |
wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser |
17.09.2026 |
|
| CVE-2026-93065 |
wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs |
17.09.2026 |
|
| CVE-2026-93066 |
x86/mm/pat: Take cpa_lock around large-page collapse |
17.09.2026 |
|
| CVE-2026-93067 |
drm/bridge: tc358767: clamp the reported AUX read size to the request |
17.09.2026 |
|
| CVE-2026-93068 |
drm/amd/display: Fix DM I2C teardown race |
17.09.2026 |
|
| CVE-2026-93069 |
OPP: Fix cleanup ordering |
17.09.2026 |
|
| CVE-2026-93070 |
media: ipu6: Do not free aux device pdata after init |
17.09.2026 |
|
| CVE-2026-93071 |
media: bcm2835-unicam: Fix asc leaked in error/remove path |
17.09.2026 |
|
| CVE-2026-93072 |
irqchip/renesas-irqc: Fix generic interrupt chip leak on remove |
17.09.2026 |
|
| CVE-2026-93073 |
dax: read holder_ops once in dax_holder_notify_failure() |
17.09.2026 |
|
| CVE-2026-93074 |
dax/fsdev: use __va(phys) for kaddr in direct_access |
17.09.2026 |
|
| CVE-2026-93075 |
dax/fsdev: clear pgmap ops and owner on unbind |
17.09.2026 |
|
| CVE-2026-93076 |
dax/fsdev: clear vmemmap_shift when binding static pgmap |
17.09.2026 |
|
| CVE-2026-93077 |
cxl/features: Clamp Get Feature output size to the remaining buffer |
17.09.2026 |
|
| CVE-2026-93078 |
cxl/features: Reject Set Features output buffer smaller than the header |
17.09.2026 |
|
| CVE-2026-93079 |
cxl/features: Reject Get Feature count larger than the output buffer |
17.09.2026 |
|
| CVE-2026-93080 |
firmware: arm_scmi: Fix transport device teardown lookup |
17.09.2026 |
|
| CVE-2026-93081 |
firmware: arm_scmi: Fix SCMI device destroy lifetimes |
17.09.2026 |
|
| CVE-2026-93082 |
firmware: arm_scmi: Unwind P2A receiver mailbox setup failure |
17.09.2026 |
|
| CVE-2026-93083 |
firmware: arm_scmi: Unwind TX receiver mailbox setup failure |
17.09.2026 |
|
| CVE-2026-93084 |
firmware: arm_scmi: Drop handle on protocol bind failures |
17.09.2026 |
|
| CVE-2026-93085 |
firmware: arm_scmi: Reject out of range DT protocol IDs |
17.09.2026 |
|
| CVE-2026-93086 |
firmware: arm_scmi: Avoid IDR updates while cleaning channels |
17.09.2026 |
|
| CVE-2026-93089 |
firmware: arm_scmi: Free transport channel on IDR failure |
17.09.2026 |
|
| CVE-2026-93090 |
firmware: arm_scmi: Clean up channels on setup failure |
17.09.2026 |
|
| CVE-2026-93091 |
firmware: arm_scmi: Quiesce notifications before teardown |
17.09.2026 |
|
| CVE-2026-93092 |
firmware: arm_scmi: Unregister device notifier before IDR teardown |
17.09.2026 |
|
| CVE-2026-93093 |
firmware: arm_scmi: Publish channel state before callbacks |
17.09.2026 |
|
| CVE-2026-93094 |
wifi: ath12k: fix dp_link_peer dangling references on AP vdev rollback |
17.09.2026 |
|
| CVE-2026-93095 |
hfsplus: validate thread record before delete key rebuild |
17.09.2026 |
|
| CVE-2026-93096 |
cxl/features: Serialize multi-part Get/Set Feature transfers |
17.09.2026 |
|
| CVE-2026-93097 |
cxl/mbox: Break poison list loop on an empty payload |
17.09.2026 |
|
| CVE-2026-93098 |
rpmsg: glink: fix deadlock in endpoint destroy during driver detach |
17.09.2026 |
|
| CVE-2026-93099 |
fs/resctrl: Fix UAF from worker threads when domains are removed |
17.09.2026 |
|
| CVE-2026-93100 |
fs/resctrl: Prevent use-after-free in rdtgroup_kn_put() |
17.09.2026 |
|
| CVE-2026-93101 |
media: v4l2-async: Unregister sub-device if asc_list is empty |
17.09.2026 |
|
| CVE-2026-93102 |
RDMA/hfi1: Free RX data on late probe failure |
17.09.2026 |
|
| CVE-2026-93103 |
RDMA/hfi1: Preserve unit 0 on allocation failure |
17.09.2026 |
|
| CVE-2026-93104 |
RDMA/rvt: Return NULL after port allocation failure |
17.09.2026 |
|
| CVE-2026-93105 |
esp: do not unref managed frag pages in esp_ssg_unref() |
17.09.2026 |
|
| CVE-2026-93106 |
crash_dump: release keyring reference at the correct time |
17.09.2026 |
|
| CVE-2026-93107 |
RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state |
17.09.2026 |
|
| CVE-2026-93108 |
RDMA/ipoib: Drain RCU callbacks during module teardown |
17.09.2026 |
|
| CVE-2026-93109 |
RDMA/mlx5: Drain RCU callbacks during module teardown |
17.09.2026 |
|
| CVE-2026-93110 |
RDMA/core: Wait for RCU callbacks before unloading ib_core |
17.09.2026 |
|
| CVE-2026-93111 |
bpf: Mark tracing_multi trampolines as ftrace managed |
17.09.2026 |
|
| CVE-2026-93112 |
bpf: Require a BPF cpumask for bpf_cpumask_populate() |
17.09.2026 |
|
| CVE-2026-93113 |
clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK |
17.09.2026 |
|
| CVE-2026-93114 |
platform/surface: acpi-notify: Check ACPI companion before use |
17.09.2026 |
|
| CVE-2026-93115 |
platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL |
17.09.2026 |
|
| CVE-2026-93116 |
platform/x86: asus-wmi: fix resource leaks on probe failure |
17.09.2026 |
|
| CVE-2026-93117 |
usb: fix UAF when probe runs concurrent to dyn ID removal |
17.09.2026 |
|
| CVE-2026-93118 |
usb: gadget: aspeed_udc: check endpoint DMA allocation |
17.09.2026 |
|
| CVE-2026-93119 |
usb: ljca: bound bank_num in ljca_enumerate_gpio() |
17.09.2026 |
|
| CVE-2026-93120 |
usb: gadget: configfs: fix out-of-bounds read of qw_sign |
17.09.2026 |
|
| CVE-2026-93121 |
usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths |
17.09.2026 |
|
| CVE-2026-93122 |
usb: gadget: uac: validate rate list length before storing |
17.09.2026 |
|
| CVE-2026-93123 |
serial: qcom-geni: do not advance stale DMA completions |
17.09.2026 |
|
| CVE-2026-93124 |
platform/x86: asus-wireless: Fail probe when there is no ACPI match |
17.09.2026 |
|
| CVE-2026-93125 |
bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max |
17.09.2026 |
|
| CVE-2026-93126 |
remoteproc: qcom_q6v5_adsp: Fix reference leak for device node |
17.09.2026 |
|
| CVE-2026-93127 |
bpf: Drop scalar id on sign-extending narrowing stack fills |
17.09.2026 |
|
| CVE-2026-93128 |
platform/x86: lg-laptop: Fix LED resource handling |
17.09.2026 |
|
| CVE-2026-93129 |
platform/x86: dell-wmi-base: Fix handling of ultra performance key |
17.09.2026 |
|
| CVE-2026-93130 |
platform/x86: dell-wmi-base: Fix resource leak on module load failure |
17.09.2026 |
|
| CVE-2026-93131 |
platform/x86: dell-privacy: Fix race condition |
17.09.2026 |
|
| CVE-2026-93132 |
ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling |
17.09.2026 |
|
| CVE-2026-93133 |
ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep() |
17.09.2026 |
|
| CVE-2026-93134 |
printk: Fix possible console use-after-free |
17.09.2026 |
|
| CVE-2026-93135 |
bpf: Reject programs with inlined helpers if JIT is not available |
17.09.2026 |
|
| CVE-2026-93136 |
bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation |
17.09.2026 |
|
| CVE-2026-93137 |
bpf: Fix use-after-free on mm_struct in bpf_find_vma() |
17.09.2026 |
|
| CVE-2026-93138 |
bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux |
17.09.2026 |
|
| CVE-2026-93139 |
drm/amdgpu/mes: Fix hung_queue_db_array loop limit for multi-XCC |
17.09.2026 |
|
| CVE-2026-93140 |
udf: Mark LVID buffer as uptodate before marking it dirty |
17.09.2026 |
|
| CVE-2026-93141 |
usb: gadget: r8a66597: avoid double free of ep0_req in probe error path |
17.09.2026 |
|
| CVE-2026-93142 |
thermal/drivers/rcar: Fix error checking in probe() |
17.09.2026 |
|
| CVE-2026-93143 |
staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume() |
17.09.2026 |
|
| CVE-2026-93144 |
bpf: Reject writes through untrusted BTF pointers |
17.09.2026 |
|
| CVE-2026-93145 |
clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister() |
17.09.2026 |
|
| CVE-2026-93146 |
time/namespace: Validate nanosecond field in proc_timens_set_offset() |
17.09.2026 |
|
| CVE-2026-93147 |
s390/bpf: Replace ly instruction with llgf |
17.09.2026 |
|
| CVE-2026-93148 |
bpf: Reject MEM_ALLOC BTF accesses past object bounds |
17.09.2026 |
|
| CVE-2026-93149 |
wifi: mac80211_hwsim: avoid NULL skb in stop queue drain |
17.09.2026 |
|
| CVE-2026-93150 |
cgroup/cpuset: Make nr_deadline_tasks an atomic_t |
17.09.2026 |
|
| CVE-2026-93151 |
nvmet-rdma: fix response resource leak on queue teardown |
17.09.2026 |
|
| CVE-2026-93152 |
nvme-apple: Use acquire/release for queue enabled state |
17.09.2026 |
|
| CVE-2026-93153 |
RDMA/bng_re: return a timeout when firmware responses stall |
17.09.2026 |
|
| CVE-2026-93154 |
RDMA/irdma: Add refcounting to user ring MRs |
17.09.2026 |
|
| CVE-2026-93155 |
crypto: keembay - Fix AEAD unregister count in error path |
17.09.2026 |
|
| CVE-2026-93156 |
crypto: rk3288 - fail ahash requests on HASH idle timeout |
17.09.2026 |
|
| CVE-2026-93157 |
hwrng: xilinx-trng - propagate timeout before any data is read |
17.09.2026 |
|
| CVE-2026-93158 |
crypto: sa2ul - stop probe if context pool creation fails |
17.09.2026 |
|
| CVE-2026-93159 |
crypto: atmel-sha204a - fix heap info leak on I2C transfer failure |
17.09.2026 |
|
| CVE-2026-93160 |
crypto: atmel-ecc - reject hardware ECDH without a public key |
17.09.2026 |
|
| CVE-2026-93161 |
crypto: qat - clear AES key schedule from stack |
17.09.2026 |
|
| CVE-2026-93162 |
crypto: qat - cancel work on re-enable SR-IOV timeout |
17.09.2026 |
|
| CVE-2026-93163 |
hwrng: core - fix rng list on registration error |
17.09.2026 |
|
| CVE-2026-93164 |
uprobes/x86: Move optimized uprobe from nop5 to nop10 |
17.09.2026 |
|
| CVE-2026-93165 |
platform/chrome: sensorhub: Fix memory overread in ring handler |
17.09.2026 |
|
| CVE-2026-93166 |
wifi: rtw89: debug: fix off by on in rtw89_ppdu_str() |
17.09.2026 |
|
| CVE-2026-93167 |
csky: Fix a4/a5 restoration in syscall trace path |
17.09.2026 |
|
| CVE-2026-93168 |
dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout |
17.09.2026 |
|
| CVE-2026-93169 |
dmaengine: zynqmp_dma: fix race between runtime PM and device removal |
17.09.2026 |
|
| CVE-2026-93170 |
dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers |
17.09.2026 |
|
| CVE-2026-93171 |
leds: lp5860: Fix a potential double-unlock |
17.09.2026 |
|
| CVE-2026-93172 |
mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug |
17.09.2026 |
|
| CVE-2026-93173 |
bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks |
17.09.2026 |
|
| CVE-2026-93174 |
bpf: Copy per-CPU map value padding in copy_map_value_long() |
17.09.2026 |
|
| CVE-2026-93175 |
drm/amd/display: Fix dangling pointer in CRTC reset function |
17.09.2026 |
|
| CVE-2026-93176 |
drm/amd/display: Fix dangling pointer in plane reset function |
17.09.2026 |
|
| CVE-2026-93177 |
drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup |
17.09.2026 |
|
| CVE-2026-93178 |
drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup |
17.09.2026 |
|
| CVE-2026-93179 |
drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read |
17.09.2026 |
|
| CVE-2026-93180 |
drm/panthor: Fix NPD issue on partial unmap of an evicted BO |
17.09.2026 |
|
| CVE-2026-93181 |
perf/x86/intel/uncore: Fix uncore_box ref/unref ordering |
17.09.2026 |
|
| CVE-2026-93182 |
sched/fair: Fix overflow in update_tg_cfs_runnable() |
17.09.2026 |
|
| CVE-2026-93183 |
drm/lima: call drm_mm_init() with a valid allocation range |
17.09.2026 |
|
| CVE-2026-93184 |
ASoC: fsl_audmix: rework runtime PM handling in probe |
17.09.2026 |
|
| CVE-2026-93185 |
ASoC: rt700-sdw: always drain jack work on remove |
17.09.2026 |
|
| CVE-2026-93186 |
cxl/mbox: Clamp mailbox output allocation to the payload size |
17.09.2026 |
|
| CVE-2026-93187 |
ASoC: SOF: ipc4-topology: Return error for invalid number of formats |
17.09.2026 |
|
| CVE-2026-93188 |
HID: roccat: bound device-supplied profile index |
17.09.2026 |
|
| CVE-2026-93189 |
HID: core: quiesce input in hid_hw_stop() to prevent use-after-free |
17.09.2026 |
|
| CVE-2026-93190 |
platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count |
17.09.2026 |
|
| CVE-2026-93191 |
smack: fix incorrect task context in smack_msg_queue_msgrcv |
17.09.2026 |
|
| CVE-2026-93192 |
drm/v3d: Clear queue->active_job when v3d_fence_create() fails |
17.09.2026 |
|
| CVE-2026-93193 |
drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup |
17.09.2026 |
|
| CVE-2026-93194 |
drm/rockchip: dw_dp: Release core resources |
17.09.2026 |
|
| CVE-2026-93195 |
drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel |
17.09.2026 |
|
| CVE-2026-93196 |
nvdimm: virtio_pmem: refcount requests for token lifetime |
17.09.2026 |
|
| CVE-2026-93197 |
memcg: move LRU size accounting on reparenting instead of copying it |
17.09.2026 |
|
| CVE-2026-93198 |
dm-pcache: validate the persisted dirty_tail chain at load |
17.09.2026 |
|
| CVE-2026-93199 |
i3c: master: Do not treat master device as a duplicate target |
17.09.2026 |
|
| CVE-2026-93200 |
i3c: master: Fix use-after-free of master->this |
17.09.2026 |
|
| CVE-2026-93201 |
dm-pcache: validate seg_id fields from persistent memory |
17.09.2026 |
|
| CVE-2026-93202 |
i3c: master: Fix recursive locking during device registration |
17.09.2026 |
|
| CVE-2026-93203 |
batman-adv: bla: avoid CRC corruption due to parallel claim add |
17.09.2026 |
|
| CVE-2026-93204 |
batman-adv: dat: atomically update mac addresses |
17.09.2026 |
|
| CVE-2026-9314 |
|
17.09.2026 |
|
| CVE-2026-85717 |
AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target |
17.09.2026 |
6.8 |
| CVE-2026-85718 |
AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of service |
17.09.2026 |
5.9 |
| CVE-2026-85721 |
AsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service |
17.09.2026 |
7.5 |
| CVE-2026-89036 |
Appwrite < 2.0.0 Argument Injection via providerRootDirectory Parameter |
17.09.2026 |
|
| CVE-2026-61700 |
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests |
17.09.2026 |
3.7 |
| CVE-2026-85719 |
AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTP |
17.09.2026 |
7.5 |
| CVE-2026-69197 |
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion |
17.09.2026 |
|
| CVE-2026-75523 |
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets |
17.09.2026 |
5.9 |
| CVE-2026-81515 |
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS) |
17.09.2026 |
7.5 |
| CVE-2026-81516 |
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS) |
17.09.2026 |
7.5 |
| CVE-2026-81868 |
Steeltoe: Header-forwarded client cert lacks proof of private-key possession |
17.09.2026 |
6.5 |
| CVE-2026-85715 |
ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion |
17.09.2026 |
7.5 |
| CVE-2026-86863 |
pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode |
17.09.2026 |
9.8 |
| CVE-2026-86864 |
pgAdmin 4: Argument and connection-string injection via the database field in the Backup tool |
17.09.2026 |
8.8 |
| CVE-2026-56795 |
|
17.09.2026 |
8.2 |
| CVE-2026-85999 |
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors) |
17.09.2026 |
5.3 |
| CVE-2026-86000 |
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns |
17.09.2026 |
5.3 |
| CVE-2026-86861 |
pgAdmin 4: File Manager save_file writes through a symbolic link planted after the containment check |
17.09.2026 |
5.9 |
| CVE-2026-86862 |
pgAdmin 4: Connection-string injection via the database field in the Restore and Maintenance tools |
17.09.2026 |
6.5 |
| CVE-2026-92881 |
vgmstream AWB parser awb.c init_vgmstream_awb_memory divide by zero |
17.09.2026 |
|
| CVE-2026-12284 |
Mattermost Desktop App Missing IPC Sender Validation in Calls Leave Handler |
17.09.2026 |
3.8 |
| CVE-2026-75588 |
Mattermost Desktop App plugin popout scheme validation bypass |
17.09.2026 |
2.6 |
| CVE-2026-76781 |
Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute |
18.09.2026 |
|
| CVE-2026-76834 |
b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key |
17.09.2026 |
|
| CVE-2026-86038 |
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID |
17.09.2026 |
7.5 |
| CVE-2026-86039 |
libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses |
17.09.2026 |
8.2 |
| CVE-2026-86040 |
libp2p: Unbounded RPC decode + synchronous subscription processing in @libp2p/floodsub allows unauthenticated DoS |
17.09.2026 |
7.5 |
| CVE-2026-91039 |
dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover |
17.09.2026 |
|
| CVE-2026-93013 |
RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal |
17.09.2026 |
|
| CVE-2026-93014 |
RosarioSIS before 12.9 Path Traversal in File Deletion via filename Parameter |
17.09.2026 |
|
| CVE-2026-93015 |
BlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds Write |
17.09.2026 |
|
| CVE-2026-26950 |
|
18.09.2026 |
8.1 |
| CVE-2026-87742 |
Quarkus-websockets-next: denial of service (oom) in quarkus-websockets-next via unbounded message buffering |
17.09.2026 |
|
| CVE-2026-92880 |
vgmstream EA SCHl parser vadpcm_decoder.c vadpcm_read_coefs_be out-of-bounds write |
17.09.2026 |
|
| CVE-2026-54471 |
|
17.09.2026 |
3.5 |
| CVE-2026-61793 |
Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter |
17.09.2026 |
|
| CVE-2026-79752 |
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection |
17.09.2026 |
|
| CVE-2026-63459 |
Vendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions |
17.09.2026 |
8.7 |
| CVE-2026-63461 |
Vendure: Shop API list queries can return non-public entities when filterOperator is OR |
17.09.2026 |
5.3 |
| CVE-2026-81447 |
|
18.09.2026 |
6.8 |
| CVE-2026-63460 |
Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends |
17.09.2026 |
7.5 |
| CVE-2026-63472 |
Vendure: External-authentication account takeover: external login linked to a pre-existing account by email without verification |
17.09.2026 |
9.1 |
| CVE-2026-71538 |
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows |
17.09.2026 |
|
| CVE-2026-80356 |
|
17.09.2026 |
7.3 |
| CVE-2026-81446 |
|
17.09.2026 |
7.4 |
| CVE-2026-77614 |
Opencast: Session fixation in login enables account takeover via crafted link |
17.09.2026 |
8.8 |
| CVE-2026-81445 |
|
18.09.2026 |
7.2 |
| CVE-2026-85077 |
Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 responses |
17.09.2026 |
8.2 |
| CVE-2026-85078 |
sanic chunked trailer request smuggling allows hidden second request execution |
17.09.2026 |
6.5 |
| CVE-2026-88952 |
OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication |
17.09.2026 |
|
| CVE-2026-92983 |
InternLM LMDeploy through 0.17.0 Memory Exhaustion via Session ID Mismatch |
17.09.2026 |
|
| CVE-2026-92984 |
HUBzero CMS through 2.2.32 Session Fixation via Query-String Session Identifier |
17.09.2026 |
|
| CVE-2026-92985 |
SiYuan before 3.8.4 Cross-Site Scripting via Bookmark Labels |
17.09.2026 |
|
| CVE-2026-92986 |
SiYuan before 3.8.4 Cross-Site Scripting via Document Title |
17.09.2026 |
|
| CVE-2026-92987 |
roxmltree through 0.21.1 Denial of Service via Quadratic Parsing |
17.09.2026 |
|
| CVE-2026-81453 |
|
17.09.2026 |
6.5 |
| CVE-2026-81829 |
Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via unsanitized jwt kid header in awsalbkeyresolver |
17.09.2026 |
|
| CVE-2026-92879 |
vgmstream mus_acm.c parse_mus resource consumption |
17.09.2026 |
|
| CVE-2026-81443 |
|
17.09.2026 |
6.4 |
| CVE-2026-81442 |
|
17.09.2026 |
8.1 |
| CVE-2026-71568 |
BMCtest exposes Ironic without authentication and TLS during the test |
17.09.2026 |
5.3 |
| CVE-2026-80355 |
|
18.09.2026 |
5.4 |
| CVE-2026-92933 |
vm2 before 3.11.8 Information Disclosure via util.getCallSites |
17.09.2026 |
|
| CVE-2026-92934 |
vm2 before 3.11.8 Sandbox Escape RCE via AggregateError |
17.09.2026 |
|
| CVE-2026-92935 |
vm2 NodeVM Remote Code Execution via Array-Shaped Require |
17.09.2026 |
|
| CVE-2026-92936 |
vm2 3.11.0 before 3.11.7 Information Disclosure via Error Stack |
17.09.2026 |
|
| CVE-2026-92937 |
vm2 3.11.6 Remote Code Execution via Promise call/apply |
17.09.2026 |
|
| CVE-2026-92938 |
vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite |
17.09.2026 |
|
| CVE-2026-92939 |
vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine |
17.09.2026 |
|
| CVE-2026-92940 |
vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent |
17.09.2026 |
|
| CVE-2026-92941 |
vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation |
17.09.2026 |
|
| CVE-2026-92942 |
vm2 before 3.11.7 Timeout Bypass via FinalizationRegistry |
17.09.2026 |
|
| CVE-2026-92944 |
vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector |
17.09.2026 |
|
| CVE-2026-92945 |
vm2 before 3.11.7 Module Allowlist Bypass via Prefix Matching |
17.09.2026 |
|
| CVE-2026-92946 |
vm2 before 3.11.7 Remote Code Execution via require.external |
17.09.2026 |
|
| CVE-2026-92947 |
vm2 before 3.11.7 Memory Disclosure via Buffer Pool |
17.09.2026 |
|
| CVE-2026-92948 |
vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test |
17.09.2026 |
|
| CVE-2026-92949 |
vm2 3.9.6 before 3.11.7 Sandbox Bypass via Accessor Descriptor |
17.09.2026 |
|
| CVE-2026-92950 |
vm2 before 3.11.7 Sandbox Escape via CLI require |
17.09.2026 |
|
| CVE-2026-92951 |
vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver |
17.09.2026 |
|
| CVE-2026-92952 |
vm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering Bypass |
17.09.2026 |
|
| CVE-2026-92953 |
vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray |
17.09.2026 |
|
| CVE-2026-92954 |
vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise |
17.09.2026 |
|
| CVE-2026-92955 |
vm2 before 3.11.8 Sandbox Escape via NodeVM |
17.09.2026 |
|
| CVE-2026-92956 |
vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming |
17.09.2026 |
|
| CVE-2026-92957 |
vm2 before 3.11.7 Authentication Bypass via node: Prefix |
17.09.2026 |
|
| CVE-2026-92958 |
vm2 before 3.11.7 Denylist Bypass via fs/promises |
17.09.2026 |
|
| CVE-2026-92959 |
vm2 before 3.11.8 allowAsync Bypass via Promise Thenable |
17.09.2026 |
|
| CVE-2026-92960 |
vm2 before 3.11.6 Process-wide State Exposure via os and dns |
17.09.2026 |
|
| CVE-2026-92961 |
vm2 before 3.11.6 Memory Exhaustion DoS via bufferAllocLimit Bypass |
17.09.2026 |
|
| CVE-2026-92962 |
vm2 before 3.11.4 Defense Invariant Violation via setup-sandbox.js |
17.09.2026 |
|
| CVE-2026-92963 |
vm2 before 3.11.2 Information Disclosure via Internal State |
17.09.2026 |
|
| CVE-2026-92970 |
HUBzero CMS through 2.2.32 Path Traversal via File Upload |
17.09.2026 |
|
| CVE-2026-92971 |
InternLM LMDeploy through 0.17.0 Assertion Denial of Service |
17.09.2026 |
|
| CVE-2026-92972 |
SGLang through 0.5.19 Unauthenticated Route Poisoning via PUT endpoint |
17.09.2026 |
|
| CVE-2026-92973 |
ansi2html 1.7.0a0 through 1.9.3 Cross-Site Scripting via OSC 8 |
17.09.2026 |
|
| CVE-2026-14850 |
Weak password recovery mechanism for forgotten password in MobiAPParc |
17.09.2026 |
|
| CVE-2026-62101 |
WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability |
17.09.2026 |
9.8 |
| CVE-2026-62104 |
WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability |
17.09.2026 |
10 |
| CVE-2026-62108 |
WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability |
17.09.2026 |
9.8 |
| CVE-2026-66571 |
WordPress Asset CleanUp: Page Speed Booster plugin <= 1.4.0.5 - Cross Site Request Forgery (CSRF) vulnerability |
17.09.2026 |
7.1 |
| CVE-2026-66572 |
WordPress JetBlog plugin <= 2.4.10 - Cross Site Scripting (XSS) vulnerability |
17.09.2026 |
6.5 |
| CVE-2026-66573 |
WordPress JetTabs plugin <= 2.3.3.1 - Cross Site Scripting (XSS) vulnerability |
17.09.2026 |
6.5 |
| CVE-2026-66574 |
WordPress Element Pack Elementor Addons plugin <= 8.8.3 - Cross Site Scripting (XSS) vulnerability |
17.09.2026 |
6.5 |
| CVE-2026-66575 |
WordPress King Addons for Elementor plugin <= 51.1.81 - Insecure Direct Object References (IDOR) vulnerability |
17.09.2026 |
5.3 |
| CVE-2026-66576 |
WordPress JetBlocks For Elementor plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability |
17.09.2026 |
6.5 |
| CVE-2026-66577 |
WordPress JetSearch plugin <= 3.6.3 - Cross Site Scripting (XSS) vulnerability |
17.09.2026 |
6.5 |
| CVE-2026-66578 |
WordPress PropertyHive plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerability |
17.09.2026 |
6.5 |
| CVE-2026-66579 |
WordPress JetElements For Elementor plugin <= 2.9.2.1 - Cross Site Scripting (XSS) vulnerability |
17.09.2026 |
6.5 |
| CVE-2026-66580 |
WordPress Product Feed Manager plugin <= 7.12.0 - SQL Injection vulnerability |
17.09.2026 |
8.5 |
| CVE-2026-66608 |
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.19 - Server Side Request Forgery (SSRF) vulnerability |
17.09.2026 |
6.4 |
| CVE-2026-66617 |
WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Scripting (XSS) vulnerability |
17.09.2026 |
6.5 |
| CVE-2026-66618 |
WordPress WP Maps plugin <= 4.9.9 - SQL Injection vulnerability |
17.09.2026 |
7.6 |
| CVE-2026-66619 |
WordPress Newsletters plugin <= 4.18 - SQL Injection vulnerability |
17.09.2026 |
7.6 |
| CVE-2026-66624 |
WordPress WPMasterToolKit plugin <= 2.22.0 - SQL Injection vulnerability |
17.09.2026 |
7.6 |
| CVE-2026-66625 |
WordPress WC Vendors Marketplace plugin <= 2.7.2.1 - SQL Injection vulnerability |
17.09.2026 |
7.6 |
| CVE-2026-66626 |
WordPress SKT Addons for Elementor plugin <= 4.0 - SQL Injection vulnerability |
17.09.2026 |
7.6 |
| CVE-2026-66628 |
WordPress WP-Lister Lite for eBay plugin <= 3.8.11 - SQL Injection vulnerability |
17.09.2026 |
7.6 |
| CVE-2026-66630 |
WordPress PublishPress Series plugin <= 3.1.3 - SQL Injection vulnerability |
17.09.2026 |
7.6 |
| CVE-2026-66631 |
WordPress MC Woocommerce Wishlist plugin <= 1.9.21 - SQL Injection vulnerability |
17.09.2026 |
7.6 |
| CVE-2026-66676 |
WordPress Easy Invoice plugin <= 2.3.8 - Broken Access Control vulnerability |
17.09.2026 |
5.3 |
| CVE-2026-73999 |
WordPress Cooked plugin <= 1.16.0 - Insecure Direct Object References (IDOR) vulnerability |
17.09.2026 |
5.4 |
| CVE-2026-74000 |
WordPress Simple Membership plugin <= 4.8.2 - Broken Access Control vulnerability |
17.09.2026 |
5.3 |
| CVE-2026-74002 |
WordPress Booking Calendar plugin <= 11.7 - Broken Access Control vulnerability |
17.09.2026 |
5.3 |
| CVE-2026-74005 |
WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Request Forgery (CSRF) vulnerability |
17.09.2026 |
5.4 |
| CVE-2026-74017 |
WordPress User Registration plugin <= 5.2.7 - Broken Access Control vulnerability |
17.09.2026 |
5.3 |
| CVE-2026-78294 |
WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability |
17.09.2026 |
6.5 |
| CVE-2026-78295 |
WordPress Xagio SEO plugin <= 7.1.0.43 - Cross Site Request Forgery (CSRF) vulnerability |
17.09.2026 |
8.8 |
| CVE-2026-78528 |
WordPress BerqWP plugin <= 4.1.15 - Broken Access Control vulnerability |
17.09.2026 |
5.3 |
| CVE-2026-89418 |
Uncontrolled Recursion leading to Denial of Service in protobuf-javascript (google-protobuf) |
17.09.2026 |
|
| CVE-2026-90887 |
WordPress WP Inventory Manager plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability |
17.09.2026 |
7.1 |
| CVE-2026-90986 |
WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.21 - Cross Site Scripting (XSS) vulnerability |
17.09.2026 |
7.1 |
| CVE-2026-78223 |
Token revocation record built from unverified JWT claims in AshAuthentication |
17.09.2026 |
|
| CVE-2026-80218 |
Sign-in token minted for one resource accepted by another in AshAuthentication |
17.09.2026 |
|
| CVE-2026-81632 |
Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix |
17.09.2026 |
|
| CVE-2026-81637 |
Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication |
17.09.2026 |
|
| CVE-2026-82685 |
Confirmation token accepted on any record in AshAuthentication |
17.09.2026 |
|
| CVE-2026-82723 |
Actor record with password digest stored in AshAuthentication audit log entries |
17.09.2026 |
|
| CVE-2026-82759 |
Reversible IP address pseudonymisation in AshAuthentication audit log hash mode |
17.09.2026 |
|
| CVE-2026-82760 |
Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in |
17.09.2026 |
|
| CVE-2026-82761 |
Magic link single-use tokens replayable via TOCTOU race in AshAuthentication |
17.09.2026 |
|
| CVE-2026-85500 |
`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication |
17.09.2026 |
|
| CVE-2026-86522 |
Log injection via an unescaped password reset identity in AshAuthentication |
17.09.2026 |
|
| CVE-2026-86533 |
Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix |
17.09.2026 |
|
| CVE-2026-92904 |
Rubygem-foreman_remote_execution: job output readable without object-level view_job_invocations check |
17.09.2026 |
|
| CVE-2026-53681 |
|
17.09.2026 |
|
| CVE-2026-81481 |
|
17.09.2026 |
7.5 |
| CVE-2026-92918 |
admin3 through 3.0.0 Session Token Disclosure via Audit Log |
17.09.2026 |
8.8 |
| CVE-2026-92919 |
admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload Filename |
17.09.2026 |
8.1 |
| CVE-2026-92920 |
admin3 through 3.0.0 Session Not Invalidated When a User Account Is Disabled |
17.09.2026 |
5.4 |
| CVE-2026-92921 |
admin3 through 3.0.0 Weak Password Hashing via Single-Round MD5 |
17.09.2026 |
4.9 |
| CVE-2026-92932 |
MISP sachertortephp Xml::build() Operator Precedence Bypass Allows Unintended HTTPS SSRF When readFile Is Disabled |
17.09.2026 |
|
| CVE-2026-11874 |
|
17.09.2026 |
|
| CVE-2026-53679 |
|
17.09.2026 |
|
| CVE-2026-81480 |
|
18.09.2026 |
7.2 |
| CVE-2026-90822 |
|
17.09.2026 |
9.8 |
| CVE-2026-90823 |
|
17.09.2026 |
9.8 |
| CVE-2026-92860 |
rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation |
17.09.2026 |
|
| CVE-2026-81441 |
|
17.09.2026 |
4 |
| CVE-2026-92925 |
Redis: redis: out-of-bounds read via crafted cluster bus packets |
18.09.2026 |
|
| CVE-2026-81440 |
|
17.09.2026 |
7.3 |
| CVE-2026-81479 |
|
17.09.2026 |
5.8 |
| CVE-2026-81477 |
|
18.09.2026 |
7.2 |
| CVE-2026-81478 |
|
18.09.2026 |
8.1 |
| CVE-2026-92912 |
AVideo Cryptographically Weak PRNG via uniqid Stream Key |
17.09.2026 |
|
| CVE-2026-92913 |
AVideo Weak PRNG Activation Code Authentication Bypass |
17.09.2026 |
|
| CVE-2026-92914 |
AVideo LoginControl PGP Second Factor Authentication Bypass |
17.09.2026 |
|
| CVE-2026-92915 |
WWBN AVideo userVerifyEmail.php Unauthenticated Access Control |
17.09.2026 |
|
| CVE-2026-92916 |
Grav through 2.0.21 Unauthenticated Information Disclosure via Clockwork |
17.09.2026 |
|
| CVE-2026-92917 |
Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_r |
17.09.2026 |
|
| CVE-2026-78296 |
WordPress FluentAuth plugin <= 2.1.2 - Email Verification Bypass vulnerability |
17.09.2026 |
5.3 |
| CVE-2026-81475 |
|
18.09.2026 |
8.1 |
| CVE-2026-81476 |
|
18.09.2026 |
8.1 |
| CVE-2026-81439 |
|
17.09.2026 |
3.7 |
| CVE-2026-81438 |
|
17.09.2026 |
3.7 |
| CVE-2026-92903 |
Improper Input Validation in Snowflake CLI Versions Allow Unsanitized User-Controlled Values to be Interpolated into SQL Strings |
17.09.2026 |
8.2 |
| CVE-2026-81474 |
|
18.09.2026 |
7.8 |
| CVE-2026-66269 |
|
17.09.2026 |
7.3 |
| CVE-2026-92611 |
|
17.09.2026 |
|
| CVE-2026-92893 |
Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, exposes hidden parameters |
17.09.2026 |
|
| CVE-2026-92894 |
Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model override value destruction |
17.09.2026 |
|
| CVE-2026-78425 |
SAML Audience Confusion Allows Cross-SP Authentication |
17.09.2026 |
|
| CVE-2026-78426 |
Logout bypass via alternate JWT spelling |
17.09.2026 |
3.7 |
| CVE-2026-78427 |
Admission Control Bypass via Hardcoded Sidecar Image Exemption |
17.09.2026 |
4.3 |
| CVE-2026-78428 |
Flaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently |
17.09.2026 |
8 |