| CVE-2026-67236 |
RabbitMQ: Plaintext username:password stored in an insecure cookie after successful POST /login |
25.09.2026 |
|
| CVE-2026-42322 |
Piwigo: Authenticated RCE via File Upload in Logo Upload Feature |
25.09.2026 |
9.1 |
| CVE-2026-42324 |
Piwigo: Second-Order SQL Injection |
25.09.2026 |
7.2 |
| CVE-2026-44642 |
Piwigo: SQL injection in upgrade authentication allows unauthenticated upgrade authorization bypass (PHP 8+) |
25.09.2026 |
8.1 |
| CVE-2026-92161 |
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider |
25.09.2026 |
9.8 |
| CVE-2026-62262 |
Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create` |
25.09.2026 |
9.1 |
| CVE-2026-100230 |
|
25.09.2026 |
5.3 |
| CVE-2026-33639 |
InvoicePlane permits DDL injection through tax_rate_decimal_places |
25.09.2026 |
7.2 |
| CVE-2026-42323 |
Piwigo: SQL Injection in Batch Manager |
25.09.2026 |
7.2 |
| CVE-2026-49850 |
InvoicePlane: Missing CSRF Protection on State-Changing delete Actions |
25.09.2026 |
7.5 |
| CVE-2026-50547 |
InvoicePlane permits local file inclusion through the e-invoice XML configuration identifier |
25.09.2026 |
7.5 |
| CVE-2026-97469 |
PostgreSQL Anonymizer: RESTRICTED functions are reachable through a subLink |
25.09.2026 |
4.3 |
| CVE-2026-39353 |
InvoicePlane: Remote Code Execution via Writable Templates Directory |
25.09.2026 |
9.1 |
| CVE-2026-39372 |
InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in Attachments |
25.09.2026 |
4.9 |
| CVE-2026-54790 |
InvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field in the Custom Fields module |
25.09.2026 |
6 |
| CVE-2026-85274 |
InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Protection |
25.09.2026 |
6.5 |
| CVE-2026-85289 |
InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints |
25.09.2026 |
6.5 |
| CVE-2026-85290 |
InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging |
25.09.2026 |
5.3 |
| CVE-2026-85291 |
InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorization Check |
25.09.2026 |
6.5 |
| CVE-2026-85292 |
InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth) |
25.09.2026 |
4.8 |
| CVE-2026-85293 |
InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer Forms |
25.09.2026 |
4.8 |
| CVE-2026-96874 |
Stored XSS in Cargo Drilldown tab names |
25.09.2026 |
|
| CVE-2026-97868 |
sheshbabu zen Note Editor NotesEditor.jsx dangerouslySetInnerHTML cross site scripting |
25.09.2026 |
|
| CVE-2026-97869 |
langchain4j LangChain4j-agentic AgenticScopeJsonSerializationIT.java AgenticScopeSerializer.fromJson deserialization |
25.09.2026 |
|
| CVE-2026-96812 |
Host Root Sandbox Escape in gVisor via Character Device Passthrough and CUSE |
25.09.2026 |
|
| CVE-2026-97866 |
Zhonglun CloudPOS Automatic Update Program.cs channel accessible |
25.09.2026 |
|
| CVE-2026-60096 |
|
25.09.2026 |
|
| CVE-2026-60097 |
|
25.09.2026 |
|
| CVE-2026-60098 |
|
25.09.2026 |
|
| CVE-2026-60099 |
|
25.09.2026 |
|
| CVE-2026-60100 |
|
25.09.2026 |
|
| CVE-2026-60101 |
|
25.09.2026 |
|
| CVE-2026-93030 |
|
25.09.2026 |
6.5 |
| CVE-2026-84862 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
25.09.2026 |
7.2 |
| CVE-2026-84882 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
25.09.2026 |
7.5 |
| CVE-2026-88389 |
|
25.09.2026 |
|
| CVE-2026-93306 |
This Power System update is being released to address |
25.09.2026 |
7.1 |
| CVE-2026-84884 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
25.09.2026 |
7.5 |
| CVE-2026-84893 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
25.09.2026 |
7.6 |
| CVE-2026-85029 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
25.09.2026 |
7.5 |
| CVE-2026-93642 |
Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation |
25.09.2026 |
9.3 |
| CVE-2026-93643 |
Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request |
25.09.2026 |
9.8 |
| CVE-2026-93647 |
Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address |
25.09.2026 |
9.3 |
| CVE-2026-100190 |
Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework showDomain Page |
25.09.2026 |
|
| CVE-2026-85542 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
25.09.2026 |
8.8 |
| CVE-2026-85750 |
Piwigo arbitrary file read and remote code execution via insecure image processing |
25.09.2026 |
7.2 |
| CVE-2026-93641 |
Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation |
25.09.2026 |
9.3 |
| CVE-2026-97222 |
Gnumeric: gnumeric: heap use-after-free when opening a malformed workbook |
25.09.2026 |
|
| CVE-2026-100177 |
Ail Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Organization Cookiejar Attachment |
25.09.2026 |
|
| CVE-2026-100187 |
AIL Framework Onion Module: Non-Onion URL Accepted as Crawler Task Due to Bypassed Domain Validation |
25.09.2026 |
|
| CVE-2026-93834 |
Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape |
25.09.2026 |
|
| CVE-2026-100174 |
Stored Cross-Site Scripting (XSS) in AIL Framework Tag Selector via Unescaped Tag Names |
25.09.2026 |
|
| CVE-2026-100176 |
Stored Cross-Site Scripting (XSS) in AIL Framework Username Timeline Tooltip |
25.09.2026 |
|
| CVE-2026-80431 |
Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal process |
25.09.2026 |
|
| CVE-2026-97865 |
Open-Web-Analytics Remote Event Queue Endpoint queue.php loadFromArray deserialization |
25.09.2026 |
|
| CVE-2026-100070 |
netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet |
25.09.2026 |
|
| CVE-2026-100071 |
net: hsr: free learned nodes on device setup failure |
25.09.2026 |
|
| CVE-2026-100072 |
ACPI: platform: Use acpi_bus_get_primary_device() |
25.09.2026 |
|
| CVE-2026-100073 |
ext4: fix transaction overflow during writeback |
25.09.2026 |
|
| CVE-2026-100074 |
bpf: Mark bpf_refcount field as unique |
25.09.2026 |
|
| CVE-2026-100075 |
RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters |
25.09.2026 |
9.8 |
| CVE-2026-100076 |
staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths |
25.09.2026 |
|
| CVE-2026-100077 |
drm/msm: Recover HW before retire hung submit |
25.09.2026 |
|
| CVE-2026-100078 |
wifi: iwlwifi: mei: pass correct argument to function |
25.09.2026 |
|
| CVE-2026-100079 |
usb: typec: ucsi: unregister debugfs entries on teardown |
25.09.2026 |
|
| CVE-2026-100172 |
Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic values in HTML-enabled data-content attributes |
25.09.2026 |
|
| CVE-2026-80430 |
Improper link resolution in the kitty drag and drop protocol allows a client to create files outside the staging directory |
25.09.2026 |
|
| CVE-2026-97864 |
GibbonEdu Gibbon Unit Planner units_add_blockAjax.php makeBlock missing authentication |
25.09.2026 |
|
| CVE-2026-98160 |
staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() |
25.09.2026 |
|
| CVE-2026-98161 |
nvdimm: pmem: keep PREFLUSH before data writes |
25.09.2026 |
|
| CVE-2026-98162 |
smb/server: fix tree connection leak in smb2_tree_connect() |
25.09.2026 |
|
| CVE-2025-51457 |
|
25.09.2026 |
|
| CVE-2026-79153 |
|
25.09.2026 |
|
| CVE-2026-88421 |
|
25.09.2026 |
|
| CVE-2026-95832 |
Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell |
25.09.2026 |
|
| CVE-2026-51772 |
|
25.09.2026 |
|
| CVE-2026-51773 |
|
25.09.2026 |
|
| CVE-2026-52622 |
|
25.09.2026 |
7.5 |
| CVE-2026-78902 |
|
25.09.2026 |
|
| CVE-2026-88420 |
|
25.09.2026 |
|
| CVE-2026-97622 |
|
25.09.2026 |
|
| CVE-2026-97875 |
DNS rebinding vulnerability in rojo serve HTTP API |
25.09.2026 |
8.1 |
| CVE-2026-98101 |
ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source() |
25.09.2026 |
|
| CVE-2026-98102 |
ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src() |
25.09.2026 |
|
| CVE-2026-98103 |
igmp: convert struct ip_sf_list to RCU |
25.09.2026 |
|
| CVE-2026-98104 |
net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted |
25.09.2026 |
|
| CVE-2026-98105 |
net: ethernet: oa_tc6: Improve the error recovery |
25.09.2026 |
|
| CVE-2026-98106 |
drm/pagemap: Prevent double migration of device pages |
25.09.2026 |
|
| CVE-2026-98107 |
Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect |
25.09.2026 |
|
| CVE-2026-98108 |
Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan |
25.09.2026 |
7.5 |
| CVE-2026-98109 |
Bluetooth: hci_core: Fix race condition during device registration |
25.09.2026 |
|
| CVE-2026-98110 |
Bluetooth: btintel: bound firmware ID by TLV length |
25.09.2026 |
|
| CVE-2026-98111 |
Bluetooth: btintel: validate version TLV value lengths |
25.09.2026 |
|
| CVE-2026-98112 |
ksmbd: fix listener task lifetime on netdev events |
25.09.2026 |
7.8 |
| CVE-2026-98113 |
ksmbd: rate limit unmapped SID errors |
25.09.2026 |
|
| CVE-2026-98114 |
ksmbd: propagate DACL parsing errors |
25.09.2026 |
|
| CVE-2026-98115 |
ksmbd: safely drain sessions during logoff |
25.09.2026 |
8.8 |
| CVE-2026-98116 |
ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF |
25.09.2026 |
7.8 |
| CVE-2026-98117 |
cachefiles: Fix potential UAF/KASAN warning |
25.09.2026 |
|
| CVE-2026-98118 |
netfs: Fix readahead synchronisation issues by loading all folios upfront |
25.09.2026 |
|
| CVE-2026-98119 |
netfs: break unbuffered write when netfs_alloc_subrequest() fails |
25.09.2026 |
|
| CVE-2026-98120 |
netfs: Fix subreq ref leak |
25.09.2026 |
|
| CVE-2026-98121 |
watchdog: msc313e: Fix NULL pointer dereference in PM callbacks |
25.09.2026 |
|
| CVE-2026-98122 |
vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() |
25.09.2026 |
7.8 |
| CVE-2026-98123 |
sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration |
25.09.2026 |
|
| CVE-2026-98124 |
smb/client: invalidate fscache for fallocate range operations |
25.09.2026 |
|
| CVE-2026-98125 |
smb/client: fix stale page cache in insert/collapse range |
25.09.2026 |
|
| CVE-2026-98126 |
smb/client: validate new EOF for zero range |
25.09.2026 |
|
| CVE-2026-98127 |
smb/client: validate new EOF for insert range |
25.09.2026 |
|
| CVE-2026-98128 |
scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add() |
25.09.2026 |
|
| CVE-2026-98129 |
scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() |
25.09.2026 |
|
| CVE-2026-98130 |
sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START |
25.09.2026 |
8.1 |
| CVE-2026-98131 |
net: stmmac: fix dma mapping leak in stmmac_tso_xmit() |
25.09.2026 |
|
| CVE-2026-98132 |
bpf: don't downgrade half-dead scalar zero spills to STACK_ZERO |
25.09.2026 |
|
| CVE-2026-98133 |
ntfs: leave HasEA flag untouched on setxattr failure |
25.09.2026 |
|
| CVE-2026-98134 |
bpf: check_cond_jmp_op(): properly infer if register is null |
25.09.2026 |
|
| CVE-2026-98135 |
ntfs: reject invalid sectors_per_cluster in the boot sector |
25.09.2026 |
|
| CVE-2026-98136 |
ntfs: bound $AttrDef table walk to the loaded table size |
25.09.2026 |
|
| CVE-2026-98137 |
ntfs: treat any nonzero dio zero-range return as an error |
25.09.2026 |
|
| CVE-2026-98138 |
ntfs: do not mark the volume clean in sync_fs when errors were recorded |
25.09.2026 |
|
| CVE-2026-98139 |
ntfs: only count successfully cleared runs when freeing clusters |
25.09.2026 |
|
| CVE-2026-98140 |
ntfs: fix kmap_local leak in write_mft_record_nolock() error paths |
25.09.2026 |
|
| CVE-2026-98141 |
ntfs: propagate reparse index insertion failure |
25.09.2026 |
|
| CVE-2026-98142 |
drm/cirrus-qemu: Validate BAR0 size during probe |
25.09.2026 |
|
| CVE-2026-98143 |
accel: ethosu: Don't read the U65 rounding mode as a storage mode |
25.09.2026 |
7.8 |
| CVE-2026-98144 |
accel/amdxdna: put the chained BO when its mapping fails |
25.09.2026 |
|
| CVE-2026-98145 |
accel/amdxdna: reject a command chain that carries no commands |
25.09.2026 |
|
| CVE-2026-98146 |
accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain |
25.09.2026 |
|
| CVE-2026-98147 |
printk: Don't WARN on kthread_run failure. |
25.09.2026 |
|
| CVE-2026-98148 |
drm/gud: validate GUD_ROTATION_0 is present in supported rotations |
25.09.2026 |
|
| CVE-2026-98149 |
bpf: Fix percpu map update indexing with sparse CPU IDs |
25.09.2026 |
|
| CVE-2026-98150 |
bpf: Fix BPF_F_CPU validation for sparse CPU IDs |
25.09.2026 |
7 |
| CVE-2026-98151 |
bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic |
25.09.2026 |
|
| CVE-2026-98152 |
nvmet-rdma: fix queue leak when connect backlog is exceeded |
25.09.2026 |
|
| CVE-2026-98153 |
nvme: fix racy access to FDP placement id array |
25.09.2026 |
|
| CVE-2026-98154 |
nvme-rdma: fix -EIO cleanup order in queue_rq |
25.09.2026 |
7 |
| CVE-2026-98155 |
accel/qaic: Address potential out-of-bounds read in resp_worker() |
25.09.2026 |
|
| CVE-2026-98156 |
drm/virtio: use the DMA API for resource backing on Xen |
25.09.2026 |
7.8 |
| CVE-2026-98157 |
EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation |
25.09.2026 |
|
| CVE-2026-98158 |
ppp_async: drop the errored frame instead of resetting its headroom |
25.09.2026 |
|
| CVE-2026-98159 |
wifi: mt76: mt7921: validate CLC firmware records |
25.09.2026 |
|
| CVE-2026-27867 |
CROSS-SITE SCRIPTING (XSS) VIA THE CMDCOOKIE PARAMETER REGESTA SMART HD-PLC OF TELDAT |
25.09.2026 |
|
| CVE-2026-97228 |
Rapid7 Bulk Export MCP — GraphQL Query Injection in Export Status Lookup |
25.09.2026 |
2.7 |
| CVE-2026-97522 |
mptcp: fix bad accounting in __mptcp_subflow_push_pending() |
25.09.2026 |
|
| CVE-2026-97523 |
mptcp: close race between scheduler and state change |
25.09.2026 |
7.5 |
| CVE-2026-97524 |
mptcp: avoid unneeded actions on subflow reset |
25.09.2026 |
7.5 |
| CVE-2026-97525 |
x86/mm/pat: Allocate split page tables as kernel page tables |
25.09.2026 |
8.2 |
| CVE-2026-97526 |
s390/pai: Support CPU hotplug for PMU PAI |
25.09.2026 |
|
| CVE-2026-97527 |
scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock |
25.09.2026 |
8.8 |
| CVE-2026-97528 |
scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error |
25.09.2026 |
8.8 |
| CVE-2026-97529 |
scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[] |
25.09.2026 |
|
| CVE-2026-97530 |
scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature |
25.09.2026 |
|
| CVE-2026-97531 |
scsi: qla2xxx: Skip vport under deletion in report ID acquisition |
25.09.2026 |
7.5 |
| CVE-2026-97532 |
scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path |
25.09.2026 |
|
| CVE-2026-97533 |
x86/mm/pat: Acquire init_mm read lock on attribute changes to avoid UAF |
25.09.2026 |
|
| CVE-2026-97534 |
f2fs: accurately adjust free_sections during free_segment_range |
25.09.2026 |
|
| CVE-2026-97535 |
scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size |
25.09.2026 |
|
| CVE-2026-97536 |
scsi: qla2xxx: Fix use-after-free of qpair work on queue teardown |
25.09.2026 |
7.5 |
| CVE-2026-97537 |
scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking |
25.09.2026 |
|
| CVE-2026-97538 |
hwmon: (asus_rog_ryujin) Validate HID report lengths |
25.09.2026 |
|
| CVE-2026-97539 |
usb: xusbatm: don't rely on id table pointer arithmetic |
25.09.2026 |
|
| CVE-2026-97540 |
net: usb: pegasus: don't rely on id table pointer arithmetic |
25.09.2026 |
|
| CVE-2026-97541 |
wifi: ath9k_htc: don't store usb_device_id |
25.09.2026 |
|
| CVE-2026-97542 |
xfs: bail out on bitmap errors in xrep_agfl_fill |
25.09.2026 |
|
| CVE-2026-97543 |
xfs: destroy seen inode bitmap when we fail to add a dirpath |
25.09.2026 |
|
| CVE-2026-97544 |
xfs: don't leak dqacct if rhashtable insertion fails |
25.09.2026 |
|
| CVE-2026-97545 |
xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails |
25.09.2026 |
|
| CVE-2026-97546 |
xfs: don't spin forever on zero-length dirents when salvaging them |
25.09.2026 |
|
| CVE-2026-97547 |
xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN |
25.09.2026 |
|
| CVE-2026-97548 |
xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions |
25.09.2026 |
7.8 |
| CVE-2026-97549 |
xfs: fix under-reservation of blocks when repairing sf directories |
25.09.2026 |
|
| CVE-2026-97550 |
xfs: fix unit conversions in per_binval computation |
25.09.2026 |
|
| CVE-2026-97551 |
xfs: initialise args->total for parent pointer updates |
25.09.2026 |
|
| CVE-2026-97552 |
xfs: initialise error in xfs_defer_finish_one() |
25.09.2026 |
|
| CVE-2026-97553 |
xfs: lock the healthmon when inserting unmount event |
25.09.2026 |
|
| CVE-2026-97554 |
smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr() |
25.09.2026 |
|
| CVE-2026-97555 |
smb: client: fix heap overflow in DACL owner/group rewrite |
25.09.2026 |
8.8 |
| CVE-2026-97556 |
smb: client: avoid leaking refcount when cifs_sb_tlink() fails |
25.09.2026 |
|
| CVE-2026-97557 |
smb: client: avoid leaking refcount in cifs_queue_oplock_break() |
25.09.2026 |
7.5 |
| CVE-2026-97558 |
smb: client: fix cifsFileInfo reference leak in deferred close |
25.09.2026 |
|
| CVE-2026-97559 |
smb: client: fail DACL rewrite when the new DACL exceeds 64K |
25.09.2026 |
|
| CVE-2026-97560 |
smb: client: fix one-byte OOB read in smb2_parse_native_symlink() |
25.09.2026 |
|
| CVE-2026-97561 |
smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid |
25.09.2026 |
|
| CVE-2026-97562 |
smb: client: pin DFS superblock in iterator callback |
25.09.2026 |
7.5 |
| CVE-2026-97563 |
smb: client: reject out-of-bounds DataOffset in CIFSSMBRead() |
25.09.2026 |
|
| CVE-2026-97564 |
smb: client: reject userspace cifs.idmap descriptions |
25.09.2026 |
|
| CVE-2026-97565 |
smb: client: reject short READ responses in CIFSSMBRead() |
25.09.2026 |
|
| CVE-2026-97566 |
mptcp: pm: kernel: drop pending ADD_ADDR when removing ID0 |
25.09.2026 |
|
| CVE-2026-97567 |
mptcp: prevent race between disconnect() and rtx |
25.09.2026 |
|
| CVE-2026-97568 |
mptcp: syncookies: remember the request backup flag |
25.09.2026 |
|
| CVE-2026-97569 |
bnxt_en: Prevent queue stop with deferred completions |
25.09.2026 |
|
| CVE-2026-97570 |
bnxt_en: Bound SW TPA IDs to prevent crashes |
25.09.2026 |
8.1 |
| CVE-2026-97571 |
bnxt_en: Propagate TPA buffer allocation failures in bnxt_queue_mem_alloc() |
25.09.2026 |
|
| CVE-2026-97572 |
bnxt_en: Propagate RX ring init failures in bnxt_init_nic() |
25.09.2026 |
|
| CVE-2026-97573 |
bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() |
25.09.2026 |
8.1 |
| CVE-2026-97574 |
bnxt_en: Don't free the live ring's TPA state on queue restart failure |
25.09.2026 |
|
| CVE-2026-97575 |
media: v4l2-ctrls: validate AV1 tile counts |
25.09.2026 |
7.8 |
| CVE-2026-97576 |
media: v4l2-ctrls: validate HEVC tile counts |
25.09.2026 |
7.8 |
| CVE-2026-97577 |
media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity |
25.09.2026 |
7.8 |
| CVE-2026-97578 |
media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer |
25.09.2026 |
7.8 |
| CVE-2026-97579 |
media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity |
25.09.2026 |
7.8 |
| CVE-2026-97580 |
media: rkvdec: bound HEVC tile loops and PPS id to the array capacity |
25.09.2026 |
7.8 |
| CVE-2026-97581 |
media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity |
25.09.2026 |
|
| CVE-2026-97582 |
hwmon: (gpio-fan) Fix use-after-free in alarm work |
25.09.2026 |
|
| CVE-2026-97583 |
afs: Clear stale peer app data after address list changes |
25.09.2026 |
7.5 |
| CVE-2026-97584 |
afs: Fix incorrect free in candidate cleanup in afs_lookup_server() |
25.09.2026 |
7.8 |
| CVE-2026-97585 |
afs: Fix double-unmap of directory block |
25.09.2026 |
|
| CVE-2026-97586 |
afs: Fix missing kunmap in afs_dir_search_bucket() |
25.09.2026 |
|
| CVE-2026-97587 |
perf: RISC-V: store available counter mask as bitmap |
25.09.2026 |
|
| CVE-2026-97588 |
s390/crypto: Map EBUSY to EIO when key conversion fails repeatedly |
25.09.2026 |
|
| CVE-2026-97589 |
s390/crypto: Fix wrong return code to engine in asynch callbacks |
25.09.2026 |
7 |
| CVE-2026-97590 |
s390/crypto: Fix missing scrub of temp buffers with PAES algorithm |
25.09.2026 |
|
| CVE-2026-97591 |
s390/crypto: Fix handling of EBUSY in PHMAC when req is pushed to crypto engine |
25.09.2026 |
|
| CVE-2026-97592 |
s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm |
25.09.2026 |
|
| CVE-2026-97593 |
iommu/s390: Fix NULL dereference in iova_to_phys() with ZPCI_TABLE_TYPE_RFX |
25.09.2026 |
|
| CVE-2026-97594 |
landlock: Fix use-after-free of the source's parent directory |
25.09.2026 |
7.8 |
| CVE-2026-97595 |
mac802154: fix use-after-free of sdata via queued RX frames |
25.09.2026 |
7.5 |
| CVE-2026-97596 |
ipvs: reject invalid states in connection template sync records |
25.09.2026 |
|
| CVE-2026-97597 |
ipv6: flowlabel: cap duplicate leases per socket |
25.09.2026 |
|
| CVE-2026-97598 |
ipv4: fib: bound automatic table ID allocation |
25.09.2026 |
|
| CVE-2026-97599 |
ieee802154: hwsim: serialize pib updates to fix double-free |
25.09.2026 |
|
| CVE-2026-97600 |
ieee802154: cc2520: fix FIFOP work use-after-free |
25.09.2026 |
|
| CVE-2026-97601 |
ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink |
25.09.2026 |
|
| CVE-2026-97602 |
inet: frags: invalidate queues before flushing them |
25.09.2026 |
7.8 |
| CVE-2026-97603 |
idpf: disable DIM work before freeing q_vectors |
25.09.2026 |
|
| CVE-2026-97604 |
fbdev: vfb: defer cleanup until the last reference |
25.09.2026 |
|
| CVE-2026-97605 |
erofs: preserve LZMA decoders on resize failure |
25.09.2026 |
|
| CVE-2026-97606 |
fs: autofs: fix memory leak in autofs_fill_super() |
25.09.2026 |
|
| CVE-2026-97607 |
vdpa: ifcvf: Put device on unsupported feature error |
25.09.2026 |
|
| CVE-2026-97608 |
netfilter: nf_log: unregister loggers before per-net teardown |
25.09.2026 |
7 |
| CVE-2026-97609 |
netfilter: cttimeout: prevent UAF during module unload |
25.09.2026 |
7 |
| CVE-2026-97610 |
netfs: Fix uninitialized return value in netfs_unbuffered_write() |
25.09.2026 |
|
| CVE-2026-97611 |
net: openvswitch: fix use-after-free of the flow table mask array |
25.09.2026 |
7.8 |
| CVE-2026-97612 |
net: mpls: clear inner_protocol when the last label is popped |
25.09.2026 |
7.8 |
| CVE-2026-97613 |
net: mana: Reserve extra CQ slot for the fence completion CQE |
25.09.2026 |
|
| CVE-2026-97614 |
net: dsa: tag_brcm: legacy FCS: request needed tailroom |
25.09.2026 |
|
| CVE-2026-97615 |
net: bridge: use option bits for CFM/MRP frame handlers |
25.09.2026 |
|
| CVE-2026-97616 |
net/sched: act_api: release all action references on NEWACTION failure |
25.09.2026 |
|
| CVE-2026-97617 |
ring-buffer: Check resize_disabled before publishing the new subbuf order |
25.09.2026 |
|
| CVE-2026-97618 |
io_uring/net: don't overconsume buffers when using MSG_TRUNC |
25.09.2026 |
|
| CVE-2026-97619 |
io_uring/rw: end write accounting from ->ki_complete |
25.09.2026 |
|
| CVE-2026-97620 |
drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches |
25.09.2026 |
|
| CVE-2026-97621 |
drm/rockchip: analogix_dp: fix unchecked bound endpoint name length |
25.09.2026 |
|
| CVE-2026-97899 |
drm/i915: Fix memory leak in query_perf_config_list() |
25.09.2026 |
|
| CVE-2026-97900 |
drm/drm_exec: fix up contended obj when num_objects is 0 |
25.09.2026 |
|
| CVE-2026-97901 |
genetlink: pin family module during policy dump |
25.09.2026 |
|
| CVE-2026-97902 |
fs: don't return -EINVAL for successful nested thaw |
25.09.2026 |
|
| CVE-2026-97903 |
exit: hold a reference to thread_pid across proc_flush_pid |
25.09.2026 |
7.8 |
| CVE-2026-97904 |
cpufreq: initialize policy rwsem before sysfs publication |
25.09.2026 |
|
| CVE-2026-97905 |
cpufreq: zero-initialize policy cpumask before sysfs publication |
25.09.2026 |
|
| CVE-2026-97906 |
bootconfig: Fix integer overflow in initrd size check |
25.09.2026 |
|
| CVE-2026-97907 |
Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 |
25.09.2026 |
|
| CVE-2026-97908 |
Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev |
25.09.2026 |
|
| CVE-2026-97909 |
ASoC: sti: initialize IRQ lock before requesting IRQ |
25.09.2026 |
|
| CVE-2026-97910 |
ASoC: sprd: validate compress buffer sizes against fixed allocations |
25.09.2026 |
7.8 |
| CVE-2026-97911 |
accel: ethosu: Ensure SRAM region size matches job |
25.09.2026 |
7.8 |
| CVE-2026-97912 |
accel: ethosu: Ensure SRAM size is 0 on mapping failure |
25.09.2026 |
|
| CVE-2026-97913 |
accel: ethosu: Ensure cmd stream ends with a stop op |
25.09.2026 |
|
| CVE-2026-97914 |
accel: ethosu: Fix ethosu_job_open() return value |
25.09.2026 |
|
| CVE-2026-97915 |
accel/ivpu: Limit firmware log name prints to field size |
25.09.2026 |
|
| CVE-2026-97916 |
accel/ivpu: Validate firmware log buffer metadata |
25.09.2026 |
|
| CVE-2026-97917 |
accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr |
25.09.2026 |
|
| CVE-2026-97918 |
tracing: Undo the registration when enabling the histogram trigger fails |
25.09.2026 |
|
| CVE-2026-97919 |
tracing: Take the reference before publishing the named histogram trigger |
25.09.2026 |
|
| CVE-2026-97920 |
tracing: Keep the entry count when the histogram stats allocation fails |
25.09.2026 |
|
| CVE-2026-97921 |
tracing: Free histogram the field rejected for a bad modifier |
25.09.2026 |
|
| CVE-2026-97922 |
tracing: Free histogram var refs regardless of how often they are referenced |
25.09.2026 |
|
| CVE-2026-97923 |
tracing: Free histogram the var ref when its initialization fails |
25.09.2026 |
|
| CVE-2026-97924 |
tracing/user_events: Don't destroy fields when event removal fails |
25.09.2026 |
|
| CVE-2026-97925 |
tick/broadcast: Plug clockevents replacement race |
25.09.2026 |
|
| CVE-2026-97926 |
ufs: validate cylinder group metadata before caching it |
25.09.2026 |
7 |
| CVE-2026-97927 |
ufs: create the root dentry after loading cylinder metadata |
25.09.2026 |
|
| CVE-2026-97928 |
drm/amdgpu: skip the VMID 0 flush for VRAM |
25.09.2026 |
|
| CVE-2026-97929 |
ALSA: usbusx2y: validate URB actual_length in interrupt callback |
25.09.2026 |
|
| CVE-2026-97930 |
ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf |
25.09.2026 |
|
| CVE-2026-97931 |
ALSA: us122l: Prevent write upgrades for read mappings |
25.09.2026 |
7 |
| CVE-2026-97932 |
tracing: Don't dereference trace_event_file in deferred trigger free |
25.09.2026 |
|
| CVE-2026-97933 |
tracing: Take trace_array reference when opening a tracer options file |
25.09.2026 |
|
| CVE-2026-97934 |
tracing: Fix memory corruption from a "STACKTRACE" histogram key |
25.09.2026 |
|
| CVE-2026-97935 |
tracing: Set the trace clock before registering the histogram trigger |
25.09.2026 |
|
| CVE-2026-97936 |
tracing: Fix memory corruption from the histogram stacktrace modifier |
25.09.2026 |
|
| CVE-2026-97937 |
ftrace: fork: Initialize function graph state before copy_exec_state() |
25.09.2026 |
7.8 |
| CVE-2026-97938 |
reboot: fix cad_pid use-after-free race |
25.09.2026 |
|
| CVE-2026-97939 |
ipmr: account multicast table and route memory |
25.09.2026 |
|
| CVE-2026-97940 |
ipv6: fix fib6 walker UAF on seq stop |
25.09.2026 |
7.8 |
| CVE-2026-97941 |
mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race |
25.09.2026 |
7.8 |
| CVE-2026-97942 |
x86/alternatives: Exclude text poking against change_page_attr() |
25.09.2026 |
|
| CVE-2026-97943 |
x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF |
25.09.2026 |
|
| CVE-2026-97944 |
x86/cfi: Fix FineIBT hash offset in cfi_get_func_hash() |
25.09.2026 |
|
| CVE-2026-97945 |
x86/mm: Fix user-space data loss with MADV_FREE and THP |
25.09.2026 |
|
| CVE-2026-97946 |
x86/amd_node: Fix PCI device reference counting in amd_smn_init() |
25.09.2026 |
|
| CVE-2026-97947 |
x86/amd_node: Fix potential NULL pointer dereference |
25.09.2026 |
|
| CVE-2026-97948 |
powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver |
25.09.2026 |
|
| CVE-2026-97949 |
configfs: unhash the dentry before dropping the item in rmdir |
25.09.2026 |
|
| CVE-2026-97950 |
configfs: pin the symlink target's dirent instead of chasing ->ci_dentry |
25.09.2026 |
|
| CVE-2026-97951 |
scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands |
25.09.2026 |
|
| CVE-2026-97952 |
sunvdc: unmap LDC cookies when the descriptor send fails |
25.09.2026 |
|
| CVE-2026-97953 |
net: stmmac: fix TX descriptor availability check for TSO traffic |
25.09.2026 |
7 |
| CVE-2026-97954 |
net/rds: fix tcp stream corruption with large pages |
25.09.2026 |
|
| CVE-2026-97955 |
net: mana: restore the XDP program pointer when pre-allocation fails |
25.09.2026 |
|
| CVE-2026-97956 |
net: net_failover: Fix the deadlock in net_failover_slave_name_change() |
25.09.2026 |
|
| CVE-2026-97957 |
net: hinic: fix mailbox segment buffer overflow |
25.09.2026 |
8.8 |
| CVE-2026-97958 |
net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain(). |
25.09.2026 |
|
| CVE-2026-97959 |
net/sched: cls_route: free emptied bucket on filter move |
25.09.2026 |
|
| CVE-2026-97960 |
perf/x86/intel: Prevent drain_pebs() reentry |
25.09.2026 |
|
| CVE-2026-97961 |
perf/core: Allow list_del during perf_event_overflow() |
25.09.2026 |
|
| CVE-2026-97962 |
net/mlx5e: Move representor vnic reporter to eswitch devlink port |
25.09.2026 |
|
| CVE-2026-97963 |
net: stmmac: initialize ptp_lock at probe time |
25.09.2026 |
|
| CVE-2026-97964 |
ppp_synctty: ensure a writeable skb header |
25.09.2026 |
|
| CVE-2026-97965 |
vxlan: initialize _md in vxlan_xmit_one() |
25.09.2026 |
|
| CVE-2026-97966 |
octeontx2-pf: reset HTB scheduler topology before freeing queues |
25.09.2026 |
|
| CVE-2026-97967 |
hwmon: (corsair-cpro) Remove debugfs entries when probe fails |
25.09.2026 |
|
| CVE-2026-97968 |
hwmon: (corsair-cpro) Create debugfs entries after hwmon registration |
25.09.2026 |
|
| CVE-2026-97969 |
watchdog: msc313e: Fix clock leak and spurious timer in settimeout() |
25.09.2026 |
|
| CVE-2026-97970 |
watchdog: msc313e: Avoid division by zero |
25.09.2026 |
|
| CVE-2026-97971 |
nstree: check listing permission before taking a namespace reference |
25.09.2026 |
7.8 |
| CVE-2026-97972 |
net: macb: put the "mdio" child node reference on success |
25.09.2026 |
|
| CVE-2026-97973 |
net: macb: destroy the phylink instance on the probe error path |
25.09.2026 |
|
| CVE-2026-97974 |
ipv6: null-check fib6_node before accessing in __ip6_del_rt_siblings() |
25.09.2026 |
|
| CVE-2026-97975 |
Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del() |
25.09.2026 |
|
| CVE-2026-97976 |
Bluetooth: btintel_pcie: validate packet_len before skb_put_data |
25.09.2026 |
|
| CVE-2026-97977 |
Bluetooth: btusb: Fix UAF of btusb_data by rx_work |
25.09.2026 |
|
| CVE-2026-97978 |
eth: ice: don't dereference pointers from TP_printk() |
25.09.2026 |
|
| CVE-2026-97979 |
ice: add missing xa_destroy for sched_node_ids |
25.09.2026 |
|
| CVE-2026-97980 |
s390/debug: Fix NULL pointer dereference in debug_set_level() |
25.09.2026 |
|
| CVE-2026-97981 |
net: ethernet: cortina: Count dropped frames as NAPI work |
25.09.2026 |
|
| CVE-2026-97982 |
net: ethernet: cortina: Fix budget accounting |
25.09.2026 |
|
| CVE-2026-97983 |
vduse: return compat ioctl results directly |
25.09.2026 |
|
| CVE-2026-97984 |
net: ipv6: Fix UDP length overflow with PMTU discover and big MTU |
25.09.2026 |
|
| CVE-2026-97985 |
af_unix: Update last skb marker in manage_oob(). |
25.09.2026 |
|
| CVE-2026-97986 |
virtio_input: stop callbacks before unregistering input device |
25.09.2026 |
|
| CVE-2026-97987 |
virtio_input: reset device if input_register_device() fails |
25.09.2026 |
|
| CVE-2026-97988 |
vhost: invalidate vring access on IOTLB transitions |
25.09.2026 |
|
| CVE-2026-97989 |
vduse: validate virtqueue alignment |
25.09.2026 |
|
| CVE-2026-97990 |
vdpa_sim_net: check TX pull result before RX copy |
25.09.2026 |
7.5 |
| CVE-2026-97991 |
vdpa_sim_blk: reject out-of-range sector starts |
25.09.2026 |
7.8 |
| CVE-2026-97992 |
vhost-vdpa: protect config_ctx from being freed under the config callback |
25.09.2026 |
|
| CVE-2026-97993 |
vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx |
25.09.2026 |
|
| CVE-2026-97994 |
vhost/vdpa: reject VRING_NUM larger than device max |
25.09.2026 |
|
| CVE-2026-97995 |
virtio_console: do not free control-out buffers on remove |
25.09.2026 |
|
| CVE-2026-97996 |
virtio: fix use-after-free in unregister_virtio_device() |
25.09.2026 |
|
| CVE-2026-97997 |
virtio_ring: fix stale descriptor flags after a failed packed add |
25.09.2026 |
|
| CVE-2026-97998 |
netfilter: nfnetlink_log: cope with concurrent instance destruction |
25.09.2026 |
|
| CVE-2026-98000 |
hwmon: Fix potential UAF in pec_store |
25.09.2026 |
|
| CVE-2026-98001 |
hwmon: (ltc4282) Make sure clk_init_data is fully initialized |
25.09.2026 |
|
| CVE-2026-98002 |
iommu/amd: Fix ineffective error check in nested domain allocation |
25.09.2026 |
7.8 |
| CVE-2026-98003 |
iommu/amd: Do not reallocate GA log buffers on resume |
25.09.2026 |
|
| CVE-2026-98004 |
iommu/riscv: Serialize command queue publishing |
25.09.2026 |
|
| CVE-2026-98005 |
erofs: delimit inode_share cache key components |
25.09.2026 |
|
| CVE-2026-98006 |
ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev |
25.09.2026 |
|
| CVE-2026-98007 |
bpf: Reject non-scalar bpf_loop iteration counts |
25.09.2026 |
|
| CVE-2026-98008 |
net: macb: fix NULL pointer dereference on unbind with fixed-link |
25.09.2026 |
|
| CVE-2026-98009 |
net/sched: ets: clamp quantum in parse and fallback paths |
25.09.2026 |
|
| CVE-2026-98010 |
net/sched: drr: clamp quantum in change class |
25.09.2026 |
|
| CVE-2026-98011 |
net/sched: hhf: clamp quantum in change and init paths |
25.09.2026 |
|
| CVE-2026-98012 |
net/sched: sfq: clamp quantum in change path |
25.09.2026 |
|
| CVE-2026-98013 |
net/sched: fq_pie: clamp quantum in change path |
25.09.2026 |
|
| CVE-2026-98014 |
net/mlx5: E-Switch, prevent mc_list repopulation during vport disable |
25.09.2026 |
|
| CVE-2026-98015 |
net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put |
25.09.2026 |
|
| CVE-2026-98016 |
net/mlx5e: Fix use-after-free race in sample_restore_put() |
25.09.2026 |
|
| CVE-2026-98017 |
net/sched: defer qdisc freeing after failed creation |
25.09.2026 |
7.8 |
| CVE-2026-98018 |
net: mctp: i3c: serialize probe with bus removal |
25.09.2026 |
|
| CVE-2026-98019 |
bpf: mark a NULL call argument precise |
25.09.2026 |
|
| CVE-2026-98020 |
pds_core: fix cmd_regs access racing BAR unmap on reset |
25.09.2026 |
|
| CVE-2026-98021 |
net: reject oversized tx_queue_len at netlink parse time |
25.09.2026 |
|
| CVE-2026-98022 |
net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations |
25.09.2026 |
|
| CVE-2026-98023 |
vxlan: reject dynamic fdb entries that reference a nexthop id |
25.09.2026 |
7.8 |
| CVE-2026-98024 |
s390/ism: folio_put() after error |
25.09.2026 |
|
| CVE-2026-98025 |
net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow |
25.09.2026 |
|
| CVE-2026-98026 |
net: bridge: mcast: properly convert mglist to rcu |
25.09.2026 |
|
| CVE-2026-98027 |
net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size |
25.09.2026 |
7 |
| CVE-2026-98028 |
eth: nfp: drop the replaced rule from the list when reprogramming fails |
25.09.2026 |
|
| CVE-2026-98029 |
eth: nfp: bound the ntuple rule dump by the caller's buffer size |
25.09.2026 |
7 |
| CVE-2026-98030 |
net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size |
25.09.2026 |
7 |
| CVE-2026-98031 |
nexthop: Initialize extack in remove_nh_grp_entry() |
25.09.2026 |
|
| CVE-2026-98032 |
tracing: Fix subbuf resize races with trace_pipe_raw readers |
25.09.2026 |
|
| CVE-2026-98033 |
bpf: Preserve inner map identity in callback frames |
25.09.2026 |
|
| CVE-2026-98034 |
bpf: Mark NULL kptr stores precise |
25.09.2026 |
|
| CVE-2026-98035 |
bpf: Cancel special fields when recycling rhtab elements |
25.09.2026 |
|
| CVE-2026-98036 |
bpf: Preserve special fields in recycled rhtab elements |
25.09.2026 |
|
| CVE-2026-98037 |
bpf: Reject untrusted allocated-object pointers |
25.09.2026 |
|
| CVE-2026-98038 |
bpf: Keep refcount_acquire nullable for borrowed RCU kptrs |
25.09.2026 |
|
| CVE-2026-98039 |
bpf: Require MEM_PERCPU for percpu kptr stores |
25.09.2026 |
|
| CVE-2026-98040 |
bpf: Mark the zero register precise for a register-form NULL check |
25.09.2026 |
|
| CVE-2026-98041 |
bpf: Don't predict JMP32 pointer vs zero comparisons |
25.09.2026 |
7 |
| CVE-2026-98042 |
bpf: Don't resurrect a scalar id dropped by collect_linked_regs() |
25.09.2026 |
|
| CVE-2026-98043 |
bpf: Don't infer non-NULL from a pointer with an unbounded offset |
25.09.2026 |
|
| CVE-2026-98044 |
bpf: Reject legacy packet loads from callbacks |
25.09.2026 |
|
| CVE-2026-98045 |
bpf: Mark faultable stack helpers as sleepable |
25.09.2026 |
|
| CVE-2026-98046 |
bpf: Mark bpf_btf_find_by_name_kind() as sleepable |
25.09.2026 |
|
| CVE-2026-98047 |
bpf: Check ancestor frames for rbtree callbacks |
25.09.2026 |
|
| CVE-2026-98048 |
bpf: don't rewrite bpf_fastcall patterns entered by a jump |
25.09.2026 |
|
| CVE-2026-98049 |
bpf: zero extend the result of an arena 32-bit cmpxchg |
25.09.2026 |
|
| CVE-2026-98050 |
mlxsw: spectrum_ptp: Fix napi_gro_receive() call from GC workqueue context |
25.09.2026 |
7.5 |
| CVE-2026-98051 |
net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times |
25.09.2026 |
|
| CVE-2026-98052 |
net: bcmasp: clear txcb->last before writing each descriptor |
25.09.2026 |
7.8 |
| CVE-2026-98053 |
ASoC: Intel: avs: Refactor and fix init_config access |
25.09.2026 |
|
| CVE-2026-98054 |
ASoC: Intel: avs: Fix unbalanced module reference count |
25.09.2026 |
|
| CVE-2026-98055 |
ASoC: Intel: avs: Clean up the bus when fetching ML caps fails |
25.09.2026 |
|
| CVE-2026-98056 |
nvme: remove stale namespaces by NSID range during scan |
25.09.2026 |
7.5 |
| CVE-2026-98057 |
ring-buffer: Add checking nr_subbufs to persistent ring buffer validation |
25.09.2026 |
|
| CVE-2026-98058 |
bpf: Mark syscall helpers as sleepable |
25.09.2026 |
|
| CVE-2026-98059 |
bpf: Mark sched_process_wait argument as nullable |
25.09.2026 |
|
| CVE-2026-98060 |
bpf: Reject resilient lock operations in rbtree callbacks |
25.09.2026 |
|
| CVE-2026-98061 |
bpf: Reject tail calls directly from callback frames |
25.09.2026 |
|
| CVE-2026-98062 |
bpf: Mark signal tracepoint siginfo arguments as scalar |
25.09.2026 |
|
| CVE-2026-98063 |
bpf: Fix NULL-ptr-deref in btf_var_show() |
25.09.2026 |
|
| CVE-2026-98064 |
bpf: Fix NULL-ptr-deref when showing a void BTF type |
25.09.2026 |
|
| CVE-2026-98065 |
bpf: Reject key-less BTF for hash maps |
25.09.2026 |
|
| CVE-2026-98066 |
ALSA: caiaq: Fix potential double-free at error path |
25.09.2026 |
|
| CVE-2026-98067 |
erofs: disable LZ4 rolling decompression for now |
25.09.2026 |
|
| CVE-2026-98068 |
net/rds: don't let rds_conn_shutdown() consume a concurrent drop |
25.09.2026 |
|
| CVE-2026-98069 |
net/rds: acquire the fastpath locks in rds_conn_shutdown() |
25.09.2026 |
8.1 |
| CVE-2026-98070 |
net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() |
25.09.2026 |
8.1 |
| CVE-2026-98071 |
net/rds: clear cp_flags bits individually in rds_conn_path_reset() |
25.09.2026 |
|
| CVE-2026-98072 |
net/rds: use wq_has_sleeper() in release_in_xmit() |
25.09.2026 |
|
| CVE-2026-98073 |
net: Remove conflicting altnames for dying netns in __dev_change_net_namespace(). |
25.09.2026 |
7.8 |
| CVE-2026-98074 |
bonding: do not clear curr_active_slave prematurely when releasing all slaves |
25.09.2026 |
|
| CVE-2026-98075 |
bpf: reject BPF_PSEUDO_FUNC reference to the main program |
25.09.2026 |
|
| CVE-2026-98076 |
tracing/probes: Fix use-after-free on field name/type of events with multiple probes |
25.09.2026 |
|
| CVE-2026-98077 |
netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() |
25.09.2026 |
|
| CVE-2026-98078 |
ipvs: fix reversed sequence option serialization |
25.09.2026 |
|
| CVE-2026-98079 |
btrfs: zstd: fix lost wakeup when waiting for a workspace |
25.09.2026 |
|
| CVE-2026-98080 |
btrfs: do not force reloc root creation during qgroup_account_snapshot() |
25.09.2026 |
|
| CVE-2026-98081 |
btrfs: zoned: finish active block group cleanup if call_zone_finish() fails |
25.09.2026 |
|
| CVE-2026-98082 |
btrfs: fix the possible bioc_list memory leak during error |
25.09.2026 |
|
| CVE-2026-98083 |
btrfs: fix transaction use-after-free in raid stripe insertion |
25.09.2026 |
7 |
| CVE-2026-98084 |
bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks |
25.09.2026 |
|
| CVE-2026-98085 |
bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge |
25.09.2026 |
|
| CVE-2026-98086 |
ALSA: ump: do not touch legacy_rmidi before it exists |
25.09.2026 |
|
| CVE-2026-98087 |
sched/rt,dl: Skip migrate-disabled tasks when picking a push candidate |
25.09.2026 |
|
| CVE-2026-98088 |
scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() |
25.09.2026 |
|
| CVE-2026-98089 |
bonding: alb: fix uninitialized transport header access in alb_determine_nd() |
25.09.2026 |
|
| CVE-2026-98090 |
btrfs: restore active device pointers after failed sprout |
25.09.2026 |
|
| CVE-2026-98091 |
btrfs: detach failed sprout device from transaction update list |
25.09.2026 |
|
| CVE-2026-98092 |
ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() |
25.09.2026 |
|
| CVE-2026-98093 |
ASoC: fsl_micfil: balance mclk enable/disable |
25.09.2026 |
|
| CVE-2026-98094 |
staging: fbtft: make dirty_lock IRQ-safe |
25.09.2026 |
|
| CVE-2026-98095 |
af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header(). |
25.09.2026 |
|
| CVE-2026-98096 |
ipv6: sr: restore network header before routing and forwarding |
25.09.2026 |
7.4 |
| CVE-2026-98097 |
tipc: Dont send random pad bytes in RESET/ACTIVATE messages |
25.09.2026 |
|
| CVE-2026-98098 |
tipc: fix NULL deref in tipc_named_node_up() on empty publication list |
25.09.2026 |
|
| CVE-2026-98099 |
ipv6: mcast: use rcu_assign_pointer() for __rcu list updates |
25.09.2026 |
|
| CVE-2026-97898 |
Broken authorization in Akia keyless entry lets an authenticated guest unlock other rooms |
25.09.2026 |
|
| CVE-2026-92106 |
lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS |
25.09.2026 |
|
| CVE-2026-6082 |
Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
25.09.2026 |
|
| CVE-2026-6083 |
Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
25.09.2026 |
|
| CVE-2026-6084 |
Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
25.09.2026 |
|
| CVE-2026-6085 |
Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
25.09.2026 |
|
| CVE-2026-6086 |
Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
25.09.2026 |
|
| CVE-2026-6087 |
Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
25.09.2026 |
|
| CVE-2026-6088 |
Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
25.09.2026 |
|
| CVE-2026-80514 |
wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass |
25.09.2026 |
5.3 |
| CVE-2026-86837 |
Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass |
25.09.2026 |
5.3 |
| CVE-2026-88848 |
MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restriction Bypass |
25.09.2026 |
4.2 |
| CVE-2026-92550 |
Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder |
25.09.2026 |
|
| CVE-2026-92560 |
Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder |
25.09.2026 |
|
| CVE-2026-92564 |
Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing |
25.09.2026 |
|
| CVE-2026-92573 |
Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering |
25.09.2026 |
|
| CVE-2026-97863 |
misp-modules: Shell Command Injection in MISP cisco_firesight_manager_ACL_rule_export Module via Unescaped Attribute Values |
25.09.2026 |
|
| CVE-2026-12037 |
Asset CleanUp: Page Speed Booster <= 1.4.0.5 - Authenticated (Administrator+) Server-Side Request Forgery via 'page_url' Parameter |
25.09.2026 |
5.5 |
| CVE-2026-13179 |
WP Maps <= 4.9.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via shapes_values Parameter |
25.09.2026 |
6.4 |
| CVE-2026-13456 |
WP Maps <= 4.9.8 - Authenticated (Subscriber+) Local File Inclusion via 'page' Parameter |
25.09.2026 |
7.5 |
| CVE-2026-17577 |
SSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' Parameter |
25.09.2026 |
6.1 |
| CVE-2026-17602 |
SSL Zen <= 4.7.42 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'file_name' Parameter |
25.09.2026 |
4.9 |
| CVE-2026-19804 |
s2Member <= 260814 - Unauthenticated Remote Code Execution via 'first_name' Parameter in PayPal Proxy Return |
25.09.2026 |
8.8 |
| CVE-2026-84280 |
Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter |
25.09.2026 |
7.2 |
| CVE-2026-88996 |
WPForms <= 2.0.2 - Reflected Cross-Site Scripting via 'page_title' POST Parameter |
25.09.2026 |
6.1 |
| CVE-2026-89406 |
Modula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters |
25.09.2026 |
7.5 |
| CVE-2026-89426 |
Knit Pay <= 9.6.1.0 - Authenticated (Subscriber+) Privilege Escalation via Gravity Forms Role Field |
25.09.2026 |
8.8 |
| CVE-2026-92608 |
Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 |
25.09.2026 |
|
| CVE-2026-92609 |
Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication |
25.09.2026 |
|
| CVE-2026-92713 |
Modula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter |
25.09.2026 |
8.1 |
| CVE-2026-93654 |
Premium Packages <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter |
25.09.2026 |
7.2 |
| CVE-2026-93656 |
User Profile Builder <= 4.0.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Field |
25.09.2026 |
6.4 |
| CVE-2026-93747 |
wpForo Forum <= 3.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'telegram' Profile Field |
25.09.2026 |
6.4 |
| CVE-2026-93901 |
Optima Express IDX <= 8.7.5 - Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role Assignment |
25.09.2026 |
7.3 |
| CVE-2026-94573 |
Repeater Fields for Elementor Forms <= 2.2.7 - Unauthenticated Stored Cross-Site Scripting via Repeater Field Value |
25.09.2026 |
7.2 |
| CVE-2026-95864 |
Themify Builder <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via 'css[fonts]' Parameter |
25.09.2026 |
7.2 |
| CVE-2026-95866 |
User Profile Builder <= 4.0.2 - Unauthenticated Stored Cross-Site Scripting via Avatar Field |
25.09.2026 |
7.2 |
| CVE-2026-96448 |
Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalation |
25.09.2026 |
|
| CVE-2026-96568 |
Restaurant Menu and Food Ordering <= 2.4.14 - Unauthenticated Stored Cross-Site Scripting via 'phone_number' Parameter |
25.09.2026 |
7.2 |
| CVE-2026-96752 |
Zero Spam for WordPress <= 5.7.10 - Unauthenticated Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration |
25.09.2026 |
7.2 |
| CVE-2026-93477 |
Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash |
25.09.2026 |
|
| CVE-2026-14281 |
Automation Web Platform <= 4.8.6 - Unauthenticated Privilege Escalation via 'wawp_custom_fields' Parameter |
25.09.2026 |
9.8 |
| CVE-2026-19775 |
OpenStation <= 1.1.7 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via AI Copilot Search Endpoint |
25.09.2026 |
4.3 |
| CVE-2026-83591 |
AMP for WP <= 1.1.16 - Unauthenticated Stored Cross-Site Scripting via Comment Content Regex Transformation |
25.09.2026 |
7.2 |
| CVE-2026-84279 |
Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'output_format' Parameter via Pro Export Print Job |
25.09.2026 |
7.2 |
| CVE-2026-84281 |
Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta |
25.09.2026 |
7.2 |
| CVE-2026-89055 |
Customer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter |
25.09.2026 |
9.1 |
| CVE-2026-92212 |
JetFormBuilder <= 3.6.5.3 - Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field |
25.09.2026 |
6.1 |
| CVE-2026-92746 |
Gutenverse <= 4.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute |
25.09.2026 |
6.4 |
| CVE-2026-92799 |
Online Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data |
25.09.2026 |
5.3 |
| CVE-2026-92829 |
Blog2Social: Social Media Auto Post & Scheduler <= 9.1.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via Multiple AJAX Handlers |
25.09.2026 |
4.3 |
| CVE-2026-93303 |
HT Contact Form <= 2.10.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/Resume |
25.09.2026 |
7.2 |
| CVE-2026-93399 |
Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter |
25.09.2026 |
9.1 |
| CVE-2026-93897 |
GeoDirectory <= 2.8.181 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone') |
25.09.2026 |
6.4 |
| CVE-2026-93899 |
Better Messages <= 3.0.4 - Authenticated (Subscriber+) SQL Injection via 'group_id' Message Meta Parameter |
25.09.2026 |
6.5 |
| CVE-2026-94376 |
Better Messages <= 3.0.4 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Scripting via User Display Name |
25.09.2026 |
6.4 |
| CVE-2026-96039 |
BA Book Everything <= 1.8.27 - Unauthenticated Stored Cross-Site Scripting via first_name Parameter |
25.09.2026 |
7.2 |
| CVE-2026-96766 |
GeoDirectory <= 2.8.183 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'business_hours' Parameter |
25.09.2026 |
6.4 |
| CVE-2026-62062 |
WordPress Elementor Website Builder plugin <= 4.3.1 - Cross Site Request Forgery (CSRF) vulnerability |
25.09.2026 |
8.8 |
| CVE-2026-75553 |
|
25.09.2026 |
|
| CVE-2026-78393 |
Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb Links |
25.09.2026 |
|
| CVE-2026-78394 |
Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter |
25.09.2026 |
|
| CVE-2026-78397 |
Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation |
25.09.2026 |
|
| CVE-2026-97846 |
Keycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-key binding |
25.09.2026 |
|
| CVE-2026-97721 |
Sanluan PublicCMS exportExcel/exportData SysUserAdminController.java CmsContentAdminController authorization |
25.09.2026 |
|
| CVE-2026-97818 |
|
25.09.2026 |
8.6 |
| CVE-2026-97737 |
|
25.09.2026 |
7.4 |
| CVE-2026-97764 |
|
25.09.2026 |
3.7 |
| CVE-2026-97736 |
|
25.09.2026 |
5.4 |
| CVE-2026-97735 |
|
25.09.2026 |
8 |
| CVE-2025-14814 |
CSS & JavaScript Toolbox <= 12.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via cjtoolbox Shortcode |
25.09.2026 |
6.4 |
| CVE-2026-97732 |
|
25.09.2026 |
5.1 |
| CVE-2026-97731 |
|
25.09.2026 |
7.1 |
| CVE-2026-97730 |
|
25.09.2026 |
8.5 |
| CVE-2026-97650 |
ningzichun student-management-system addLog.php echo cross site scripting |
25.09.2026 |
|
| CVE-2026-97724 |
|
25.09.2026 |
|
| CVE-2026-97723 |
|
25.09.2026 |
5.4 |
| CVE-2026-97649 |
ningzichun student-management-system example_lite.sql default credentials |
25.09.2026 |
|
| CVE-2026-95811 |
Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it |
25.09.2026 |
|
| CVE-2026-97647 |
ningzichun student-management-system editLog.php authorization |
25.09.2026 |
|
| CVE-2026-97648 |
ningzichun student-management-system cross-site request forgery |
25.09.2026 |
|
| CVE-2026-53493 |
Containerd has image-pull DoS via crafted OCI index graph amplification |
25.09.2026 |
|
| CVE-2026-85417 |
Incomplete property masking in the SANnav logging subsystem |
25.09.2026 |
|
| CVE-2026-92288 |
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party |
25.09.2026 |
|
| CVE-2026-92289 |
Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret |
25.09.2026 |
|
| CVE-2026-97646 |
ningzichun student-management-system getStudent.php authorization |
25.09.2026 |
|
| CVE-2026-85082 |
Maple Media Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames |
24.09.2026 |
|
| CVE-2026-84283 |
FluteCode Secure Folder 1.2 -Plaintext vault files in shared storage bypass the PIN gate |
24.09.2026 |
|