| CVE-2026-19519 |
Claircore: claircore: denial of service via unchecked type assertion in rpm header parser |
11.08.2026 |
|
| CVE-2026-73156 |
cti-transmute Sunburst and Treemap Tooltips Allow Cross-Site Scripting via Crafted Conversion Data |
11.08.2026 |
|
| CVE-2026-19418 |
TYPO3 CMS - Broken Access Control in Backend and Install Tool |
11.08.2026 |
|
| CVE-2026-73140 |
cti-transmute Evaluation Report Exports Expose Private Comments and Author Information |
11.08.2026 |
|
| CVE-2026-73155 |
cti-transmute Missing Authorization Allows Reactions to Private Comments |
11.08.2026 |
|
| CVE-2026-16053 |
Path Traversal |
11.08.2026 |
8.5 |
| CVE-2026-19391 |
Insights-core: insights-core: incomplete credential redaction exposes sssd bind passwords and pacemaker fence credentials in uploaded archives |
11.08.2026 |
|
| CVE-2026-19517 |
|
11.08.2026 |
6.5 |
| CVE-2026-19518 |
|
11.08.2026 |
6.5 |
| CVE-2026-13716 |
Path Traversal: '.../...//' in Crafty Controller |
11.08.2026 |
9.1 |
| CVE-2026-14548 |
Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API Token Update |
11.08.2026 |
|
| CVE-2026-14549 |
Ray Enterprise Translation <= 1.7.3 - Subscriber+ Language Addition and Deletion |
11.08.2026 |
|
| CVE-2026-12052 |
Out-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the response |
11.08.2026 |
5.2 |
| CVE-2026-18348 |
Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL plugins |
11.08.2026 |
4.1 |
| CVE-2026-4757 |
|
11.08.2026 |
7.2 |
| CVE-2026-5303 |
|
11.08.2026 |
5.7 |
| CVE-2026-5304 |
|
11.08.2026 |
5.7 |
| CVE-2026-6181 |
|
11.08.2026 |
5.9 |
| CVE-2026-6505 |
|
11.08.2026 |
5.1 |
| CVE-2026-8158 |
|
11.08.2026 |
5.3 |
| CVE-2026-11894 |
Double-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error paths |
11.08.2026 |
5.9 |
| CVE-2026-12051 |
NULL pointer dereference in USB DFU device_next download handler (handle_download) |
11.08.2026 |
4.6 |
| CVE-2026-19516 |
CVE-2026-19516 CVE Record |
11.08.2026 |
9.1 |
| CVE-2026-11893 |
Double free / use-after-free in Bouffalo Lab HCI driver send() error paths (hci_bflb) |
11.08.2026 |
5.9 |
| CVE-2026-11985 |
Cross-thread FPU register leak on ARM when FPU enabled without register sharing |
11.08.2026 |
3.6 |
| CVE-2026-16974 |
Kirki - Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode |
11.08.2026 |
6.4 |
| CVE-2026-19425 |
Win Men Intermational|Travel Agency Management System - SQL Injection |
11.08.2026 |
9.8 |
| CVE-2026-24329 |
Wildfly-core: wildfly core: denial of service via malformed payload injection by an authenticated administrative user. |
11.08.2026 |
|
| CVE-2026-24330 |
Wildfly-core: wildfly: arbitrary file read via malicious archive deployment |
11.08.2026 |
|
| CVE-2026-19424 |
Inventec Appliances|Chiline Cloud - Insecure Direct Object Reference |
11.08.2026 |
7.5 |
| CVE-2026-8917 |
|
11.08.2026 |
|
| CVE-2026-34265 |
Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform |
11.08.2026 |
9.8 |
| CVE-2026-40130 |
Memory Corruption vulnerability in SAPSPrint Service |
11.08.2026 |
5.3 |
| CVE-2026-44758 |
Code Injection vulnerability in Manufacturing Integration and Intelligence |
11.08.2026 |
9.1 |
| CVE-2026-44762 |
Security Misconfiguration in SAP Data Services Management Console |
11.08.2026 |
3.7 |
| CVE-2026-44763 |
Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence |
11.08.2026 |
7.6 |
| CVE-2026-44764 |
Missing Authorization Check in SAP Manufacturing Integration and Intelligence |
11.08.2026 |
7.3 |
| CVE-2026-44765 |
Missing Authorization Check in SAP Manufacturing Integration and Intelligence |
11.08.2026 |
7.3 |
| CVE-2026-58230 |
Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
11.08.2026 |
7 |
| CVE-2026-58235 |
Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services) |
11.08.2026 |
6.3 |
| CVE-2026-58236 |
OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform |
11.08.2026 |
5.5 |
| CVE-2026-58237 |
Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
11.08.2026 |
5.9 |
| CVE-2026-58238 |
Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
11.08.2026 |
5.9 |
| CVE-2026-58239 |
Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
11.08.2026 |
3.7 |
| CVE-2026-58241 |
Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) |
11.08.2026 |
4.2 |
| CVE-2026-58243 |
Privilege Escalation vulnerability in SAP ABAP Developer Tools |
11.08.2026 |
8.8 |
| CVE-2026-58244 |
Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII) |
11.08.2026 |
4.3 |
| CVE-2026-58245 |
Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning) |
11.08.2026 |
3.8 |
| CVE-2026-58247 |
Memory Corruption vulnerability in SAP ABAP Platform |
11.08.2026 |
5.3 |
| CVE-2026-58248 |
XML External Entity Injection in SAP BusinessObjects Business Intelligence |
11.08.2026 |
6.5 |
| CVE-2026-66760 |
Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
11.08.2026 |
6.4 |
| CVE-2026-66761 |
Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
11.08.2026 |
4.3 |
| CVE-2026-66763 |
Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server) |
11.08.2026 |
7.9 |
| CVE-2026-66764 |
Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items) |
11.08.2026 |
4.3 |
| CVE-2026-66770 |
SQL Injection vulnerability in SAP Social Intelligence |
11.08.2026 |
6.3 |
| CVE-2026-66771 |
Cross Site Scripting (XSS) vulnerability in SAPUI5 |
11.08.2026 |
6.1 |
| CVE-2026-66772 |
Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools) |
11.08.2026 |
4.3 |
| CVE-2026-66773 |
Server-controlled `__next` URL is not checking cross-origin |
11.08.2026 |
5.9 |
| CVE-2026-66774 |
Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
11.08.2026 |
3.7 |
| CVE-2026-66775 |
Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
11.08.2026 |
4.3 |
| CVE-2026-66776 |
Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
11.08.2026 |
5.9 |
| CVE-2026-66777 |
Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
11.08.2026 |
5.9 |
| CVE-2026-66778 |
Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
11.08.2026 |
5.3 |
| CVE-2026-66779 |
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP |
11.08.2026 |
6.3 |
| CVE-2026-11811 |
Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoS |
10.08.2026 |
3.7 |
| CVE-2026-11812 |
UpdateHub: race condition on shared context causes out-of-bounds write and DoS |
10.08.2026 |
2.5 |
| CVE-2026-8718 |
Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLS |
10.08.2026 |
8.4 |
| CVE-2025-30237 |
Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices |
10.08.2026 |
|
| CVE-2025-30238 |
Privilege Escalation via Improper Authorization in User Management in multiple TP-Link Aginet Devices |
10.08.2026 |
|
| CVE-2025-30239 |
Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Devices |
10.08.2026 |
|
| CVE-2025-30240 |
Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-Link Aginet Devices |
10.08.2026 |
|
| CVE-2025-30241 |
OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices |
10.08.2026 |
|
| CVE-2026-48161 |
react18-use was vulnerable to malicious code execution via compromised commits |
10.08.2026 |
|
| CVE-2025-32736 |
PingFederate Administrative Console CSRF weaknesses |
10.08.2026 |
|
| CVE-2026-72917 |
AnythingLLM: Password recovery accepts one recovery code twice after whitespace normalization |
10.08.2026 |
5.9 |
| CVE-2026-72918 |
Rocket.Chat: Insecure implementation of websocket notifications |
10.08.2026 |
5.4 |
| CVE-2026-72919 |
Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams |
10.08.2026 |
4.3 |
| CVE-2026-6426 |
Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access |
10.08.2026 |
|
| CVE-2026-72914 |
Mastodon: Exhausting data by an unauthenticated request to the admin retention API |
10.08.2026 |
7.5 |
| CVE-2026-72915 |
Mastodon: Personally-identifying information disclosure due to incorrect access control validation |
10.08.2026 |
7.5 |
| CVE-2026-72916 |
Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses |
10.08.2026 |
|
| CVE-2026-48160 |
react-tracked was vulnerable to malicious code execution via compromised commits |
10.08.2026 |
|
| CVE-2026-72909 |
ERPNext: Broken Access Control on certain endpoints |
10.08.2026 |
|
| CVE-2026-72910 |
ERPNext: Unauthorised modification of master data due to missing validation |
10.08.2026 |
7.1 |
| CVE-2026-72911 |
ERPNext: Possibility of server-side template injection due to missing validation |
10.08.2026 |
9.9 |
| CVE-2026-72912 |
CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URL |
10.08.2026 |
4.3 |
| CVE-2026-72913 |
Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequences |
10.08.2026 |
|
| CVE-2026-11809 |
UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadata |
10.08.2026 |
3.7 |
| CVE-2026-13717 |
Rhoai maas: llm-d: maas/llm-d inference gateway: default allowedroutes.namespaces.from: all allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs) |
10.08.2026 |
|
| CVE-2026-14450 |
Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication |
10.08.2026 |
|
| CVE-2026-15467 |
Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass protected environment variable filtering, allowing trust_remote_code policy override |
11.08.2026 |
|
| CVE-2026-15581 |
Trustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-rbac-proxy, exposing unauthenticated quarkus api cluster-wide |
11.08.2026 |
|
| CVE-2026-16456 |
Odh-model-controller: odh-model-controller: cross-namespace secret read via nim account crd confused deputy |
11.08.2026 |
|
| CVE-2026-18608 |
Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflow.org */*, and clusterrole/binding crud cluster-wide |
11.08.2026 |
|
| CVE-2026-18611 |
Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/rand) for db and s3 credentials |
11.08.2026 |
|
| CVE-2026-18617 |
Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextraparams enables local infile file exfiltration from operator pod |
11.08.2026 |
|
| CVE-2026-18618 |
Ml-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — directly reachable on listener |
11.08.2026 |
|
| CVE-2026-18620 |
Data-sciences-pipeline: user-controlled serviceaccount for workflow pods without authorization check — confused deputy |
11.08.2026 |
|
| CVE-2026-18621 |
Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypassing all v2 security hardening |
11.08.2026 |
|
| CVE-2026-18941 |
Feast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant instances deployed without authentication |
11.08.2026 |
|
| CVE-2026-18942 |
Feast-operator: feast: feast apply cronjob runs user python with feature-server sa — tenant code to sa token escalation |
10.08.2026 |
|
| CVE-2026-18947 |
Feast: feast: authorization bypass in /materialize endpoints enables dos via unauthorized full re-materialization |
11.08.2026 |
|
| CVE-2026-18948 |
Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry server |
11.08.2026 |
|
| CVE-2026-18949 |
Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac management resources |
11.08.2026 |
|
| CVE-2026-18950 |
Odh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchecked roleref in rolebinding creation |
11.08.2026 |
|
| CVE-2026-18951 |
Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainjobs crud into standard edit clusterrole |
11.08.2026 |
|
| CVE-2026-18982 |
Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/admin clusterroles |
11.08.2026 |
|
| CVE-2026-19411 |
Shim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns null |
10.08.2026 |
|
| CVE-2026-63622 |
Libvirt: swtpm privilege escalation via symlink following |
10.08.2026 |
|
| CVE-2026-72903 |
Tabby: Windows SFTP path traversal allows a malicious server to write files outside the selected download directory |
10.08.2026 |
8.1 |
| CVE-2026-72904 |
Firecrawl: Arbitrary file read via JSON Schema $ref expansion |
10.08.2026 |
|
| CVE-2026-72905 |
|
10.08.2026 |
|
| CVE-2026-72906 |
ERPNext: Unauthorised triggering of automated emails due to missing validation |
10.08.2026 |
4.3 |
| CVE-2026-72907 |
ERPNext: Broken Access Control on certain endpoint |
10.08.2026 |
6.5 |
| CVE-2026-72908 |
ERPNext: Possibility of SQL injection due to missing validation |
10.08.2026 |
6.5 |
| CVE-2026-11810 |
NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS) |
10.08.2026 |
7.5 |
| CVE-2026-73035 |
npm-check-updates 23.0.2 Terminal Injection via Unsanitized Escape Sequences |
10.08.2026 |
|
| CVE-2026-72743 |
SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html |
10.08.2026 |
|
| CVE-2026-73030 |
unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape |
10.08.2026 |
|
| CVE-2026-73033 |
Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php |
10.08.2026 |
|
| CVE-2026-69118 |
Cachet 2.4.1 Authenticated Server-Side Template Injection RCE |
10.08.2026 |
|
| CVE-2026-72901 |
Dokploy: Remote Code Execution via volume-backup |
10.08.2026 |
9.9 |
| CVE-2026-72902 |
Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById |
10.08.2026 |
9.9 |
| CVE-2025-13293 |
Backdoor / default root credentials |
10.08.2026 |
|
| CVE-2025-13294 |
Unauthenticated SQL Injection |
10.08.2026 |
|
| CVE-2025-15680 |
Information Disclosure via UART |
10.08.2026 |
|
| CVE-2025-15681 |
Insufficient Webserver Authentication |
10.08.2026 |
|
| CVE-2025-15682 |
Unauthenticated Resource Exhaustion |
10.08.2026 |
|
| CVE-2025-15683 |
Multiple Unauthenticated Denial-of-Service Conditions |
10.08.2026 |
|
| CVE-2026-44401 |
Typemill CMS 2.x Persistent XSS via Markdown javascript URI |
10.08.2026 |
|
| CVE-2026-69114 |
Spacebar Server Cross-Channel Message Deletion via Permission Check Bypass |
10.08.2026 |
|
| CVE-2026-69116 |
FlyEnv < 4.18.0 Cross-Site Scripting via v-html |
10.08.2026 |
|
| CVE-2026-72880 |
Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath` |
10.08.2026 |
9.9 |
| CVE-2026-72881 |
Dokploy: Command Injection via database credentials in backup/restore commands |
10.08.2026 |
|
| CVE-2026-72882 |
Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers |
10.08.2026 |
9.9 |
| CVE-2026-72883 |
Dokploy: WebSocket Terminal Missing Service-Level Access Control |
10.08.2026 |
8.8 |
| CVE-2026-72884 |
Dokploy: Command Injection via Compose Custom Command |
10.08.2026 |
|
| CVE-2026-72885 |
Dokploy: Authenticated Command Injection in Dokploy Dockerfile Builder |
10.08.2026 |
|
| CVE-2026-72886 |
Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632) |
10.08.2026 |
9.9 |
| CVE-2026-14886 |
Vault Enterprise vulnerable to cross-namespace entity deletion |
10.08.2026 |
8.2 |
| CVE-2026-69112 |
Hugging Face Accelerate 1.14.0 Path Traversal and DoS via weight_map |
10.08.2026 |
|
| CVE-2026-71965 |
CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature |
10.08.2026 |
|
| CVE-2026-71966 |
CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer |
10.08.2026 |
|
| CVE-2026-72873 |
Dokploy: Cross-tenant Git provider secrets are disclosed to low-privileged service readers via `application.one` |
10.08.2026 |
6.5 |
| CVE-2026-72874 |
Dokploy: Command Injection via Unescaped Git URL in Clone Commands |
10.08.2026 |
|
| CVE-2026-72875 |
Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile |
10.08.2026 |
8.8 |
| CVE-2026-72876 |
Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* |
10.08.2026 |
9.9 |
| CVE-2026-72877 |
Dokploy: Command Injection via dockerImage in buildRemoteDocker |
10.08.2026 |
9.6 |
| CVE-2026-72878 |
Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments |
10.08.2026 |
9.6 |
| CVE-2026-72879 |
Dokploy: Command Injection via Registry Credentials in Swarm Upload |
10.08.2026 |
|
| CVE-2026-59091 |
Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file |
11.08.2026 |
|
| CVE-2026-6368 |
wordexp with WRDE_APPEND can return or use invalid memory |
10.08.2026 |
|
| CVE-2026-6791 |
Potential stack-based buffer clash during tilde expansion in wordexp |
10.08.2026 |
|
| CVE-2026-71964 |
CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload |
10.08.2026 |
|
| CVE-2026-72864 |
Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers) |
10.08.2026 |
9.9 |
| CVE-2026-72865 |
Dokploy: OS Command Injection via compose `composePath` |
10.08.2026 |
9.9 |
| CVE-2026-72866 |
WebSocket Terminal Auth Bypass |
10.08.2026 |
8.8 |
| CVE-2026-72867 |
Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts) |
10.08.2026 |
9.9 |
| CVE-2026-72868 |
Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection |
10.08.2026 |
9.9 |
| CVE-2026-72869 |
Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE |
10.08.2026 |
9.9 |
| CVE-2026-72870 |
Dokploy: Command Injection via Docker Credentials in buildRemoteDocker |
10.08.2026 |
|
| CVE-2026-72871 |
Dokploy: Unauthenticated Git Provider Injection via GitHub OAuth Callback |
10.08.2026 |
7.5 |
| CVE-2026-72872 |
Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone` |
10.08.2026 |
9.9 |
| CVE-2026-12339 |
Authenticated Arbitrary File Write Vulnerability in multiple devices |
10.08.2026 |
|
| CVE-2026-68870 |
Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope guard bypass resolves another team's Connection or Variable |
10.08.2026 |
|
| CVE-2026-68871 |
Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or Variable |
10.08.2026 |
|
| CVE-2026-68872 |
Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard bypass resolves another team's Connection or Variable |
10.08.2026 |
|
| CVE-2026-71962 |
Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download |
10.08.2026 |
|
| CVE-2026-71967 |
OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session |
10.08.2026 |
|
| CVE-2026-71968 |
OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENT |
10.08.2026 |
|
| CVE-2026-71969 |
OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations |
10.08.2026 |
|
| CVE-2026-72863 |
Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker host |
10.08.2026 |
9.9 |
| CVE-2026-16626 |
JasperReports Server: XXE Injection Vulnerability (Unauthenticated) |
11.08.2026 |
|
| CVE-2026-48159 |
use-reducer-async was vulnerable to malicious code execution via compromised commits |
11.08.2026 |
|
| CVE-2026-72739 |
Dokploy: Command Injection via Compose Shell Execution |
10.08.2026 |
6.5 |
| CVE-2026-72740 |
Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan` |
10.08.2026 |
9.9 |
| CVE-2026-72862 |
Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE |
10.08.2026 |
9.9 |
| CVE-2026-72898 |
Metabase SQL injection via password reset endpoint |
11.08.2026 |
|
| CVE-2026-72899 |
Metabase SQL injection via public card or dashboard |
11.08.2026 |
10 |
| CVE-2026-72900 |
Metabase information exposure |
10.08.2026 |
6.5 |
| CVE-2026-10754 |
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls. |
10.08.2026 |
|
| CVE-2026-70622 |
tar-rs 0.4.11 - 0.4.46 Symlink Escape via append_dir_all() |
11.08.2026 |
|
| CVE-2026-72735 |
Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution |
10.08.2026 |
9.9 |
| CVE-2026-72736 |
Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCE |
10.08.2026 |
9.9 |
| CVE-2026-72737 |
Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups |
10.08.2026 |
9.6 |
| CVE-2026-72738 |
Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter |
10.08.2026 |
9.9 |
| CVE-2026-72732 |
Discourse: Templates endpoint exposes hidden tag names |
10.08.2026 |
4.3 |
| CVE-2026-72733 |
Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restore |
10.08.2026 |
9.9 |
| CVE-2026-72734 |
Dokploy: Cross-organization authorization bypass in server.remove allows deletion of another organization's server registration |
11.08.2026 |
8.4 |
| CVE-2026-12624 |
Vault vulnerable to LIST authorization bypass via trailing-slash strip |
10.08.2026 |
4.3 |
| CVE-2026-22651 |
|
10.08.2026 |
|
| CVE-2026-22652 |
|
10.08.2026 |
|
| CVE-2026-22653 |
|
10.08.2026 |
|
| CVE-2026-22654 |
|
10.08.2026 |
|
| CVE-2026-22655 |
|
10.08.2026 |
|
| CVE-2026-22656 |
|
10.08.2026 |
|
| CVE-2026-22657 |
|
10.08.2026 |
|
| CVE-2026-22658 |
|
10.08.2026 |
|
| CVE-2026-23675 |
|
10.08.2026 |
|
| CVE-2026-23676 |
|
10.08.2026 |
|
| CVE-2026-23677 |
|
10.08.2026 |
|
| CVE-2026-23690 |
|
10.08.2026 |
|
| CVE-2026-23691 |
|
10.08.2026 |
|
| CVE-2026-23692 |
|
10.08.2026 |
|
| CVE-2026-23765 |
|
10.08.2026 |
|
| CVE-2026-24438 |
|
10.08.2026 |
|
| CVE-2026-25074 |
|
10.08.2026 |
|
| CVE-2026-25549 |
|
10.08.2026 |
|
| CVE-2026-26229 |
|
10.08.2026 |
|
| CVE-2026-26348 |
|
10.08.2026 |
|
| CVE-2026-26349 |
|
10.08.2026 |
|
| CVE-2026-28533 |
|
10.08.2026 |
|
| CVE-2026-28534 |
|
10.08.2026 |
|
| CVE-2026-28998 |
|
10.08.2026 |
|
| CVE-2026-28999 |
|
10.08.2026 |
|
| CVE-2026-29010 |
|
10.08.2026 |
|
| CVE-2026-29011 |
|
10.08.2026 |
|
| CVE-2026-29012 |
|
10.08.2026 |
|
| CVE-2026-29024 |
|
10.08.2026 |
|
| CVE-2026-29025 |
|
10.08.2026 |
|
| CVE-2026-29026 |
|
10.08.2026 |
|
| CVE-2026-29027 |
|
10.08.2026 |
|
| CVE-2026-29028 |
|
10.08.2026 |
|
| CVE-2026-29029 |
|
10.08.2026 |
|
| CVE-2026-29030 |
|
10.08.2026 |
|
| CVE-2026-29031 |
|
10.08.2026 |
|
| CVE-2026-29032 |
|
10.08.2026 |
|
| CVE-2026-29033 |
|
10.08.2026 |
|
| CVE-2026-29517 |
|
10.08.2026 |
|
| CVE-2026-34423 |
|
10.08.2026 |
|
| CVE-2026-35005 |
|
10.08.2026 |
|
| CVE-2026-35006 |
|
10.08.2026 |
|
| CVE-2026-35026 |
|
10.08.2026 |
|
| CVE-2026-35027 |
|
10.08.2026 |
|
| CVE-2026-35028 |
|
10.08.2026 |
|
| CVE-2026-40512 |
|
10.08.2026 |
|
| CVE-2026-63623 |
Libvirt: information disclosure via world-readable storage volume images during clone/convert |
10.08.2026 |
|
| CVE-2026-71576 |
Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserted evt.source() for leaf-hub identity in all status handlers |
10.08.2026 |
|
| CVE-2026-71577 |
Multicluster-global-hub: multicluster-global-hub: spec-topic read acl leaks bootstrap kubeconfigs to all managed hubs during migration |
11.08.2026 |
|
| CVE-2026-56619 |
HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) |
10.08.2026 |
5.4 |
| CVE-2026-72727 |
Discourse: Stored XSS in the moderation review queue |
10.08.2026 |
|
| CVE-2026-72728 |
Discourse: Onebox iframe origin allowlist enforces URL authority boundary |
10.08.2026 |
6.3 |
| CVE-2026-72729 |
Discourse: Stored XSS in discourse-local-dates plugin |
11.08.2026 |
|
| CVE-2026-72730 |
Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor |
10.08.2026 |
8.7 |
| CVE-2026-72731 |
Discourse: Strip SQL comments and use non-recursive parameter interpolation in Data Explorer |
10.08.2026 |
7.1 |
| CVE-2026-48048 |
XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests |
10.08.2026 |
7.5 |
| CVE-2026-48158 |
use-context-selector was vulnerable to malicious code execution via compromised commits |
11.08.2026 |
|
| CVE-2026-56620 |
HCL BigFix Mobile is vulnerable to information disclosure |
10.08.2026 |
4.3 |
| CVE-2026-72720 |
Discourse: HTML injection in PrettyText.format_for_email from cooked-attribute reparsing |
10.08.2026 |
6.4 |
| CVE-2026-72721 |
Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison |
10.08.2026 |
5.3 |
| CVE-2026-72722 |
Discourse: Duplicate lookup reveals restricted topic titles through canonicalized URLs |
10.08.2026 |
4.3 |
| CVE-2026-72723 |
Discourse: Anonymous sidebar serialization exposes descriptions of category-restricted tags |
10.08.2026 |
5.3 |
| CVE-2026-72724 |
Discourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Threat ID Mismatch |
11.08.2026 |
4.3 |
| CVE-2026-72725 |
Discourse: Stored XSS in staff action logs injects staff UI |
10.08.2026 |
5.4 |
| CVE-2026-72726 |
Discourse: Unauthorized eavesdropping on private AI bot conversations. |
10.08.2026 |
6.5 |
| CVE-2026-47754 |
unauthenticated path traversal in Metacat 2.x |
10.08.2026 |
9.3 |
| CVE-2026-66738 |
SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite |
10.08.2026 |
|
| CVE-2026-72718 |
goose: Arbitrary command execution in goose CLI via `goose review` via git core.fsmonitor |
10.08.2026 |
|
| CVE-2026-72719 |
Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter |
10.08.2026 |
6.7 |
| CVE-2026-18412 |
The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability |
10.08.2026 |
|
| CVE-2026-19433 |
Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact save and vCard export |
10.08.2026 |
|
| CVE-2026-72759 |
cti-transmute Conversion History Authorization Bypass Leads to Sensitive Data Disclosure After Conversion Deletion |
10.08.2026 |
|
| CVE-2026-72760 |
cti-transmute Following List Exposes User Email Addresses to Authenticated Users |
10.08.2026 |
|
| CVE-2026-72761 |
Webhook SSRF guard bypassed by IPv6 transition addresses (NAT64/6to4/Teredo pass is_global check) in vulnerability-lookup |
10.08.2026 |
|
| CVE-2026-18503 |
Super-linear CPU usage for unbounded input to csv.Sniffer.sniff() |
10.08.2026 |
|
| CVE-2026-59112 |
Signature validation vulnerability affecting DigiDoc applications |
10.08.2026 |
|
| CVE-2026-63105 |
ReadyEcommerce < 4.5.2 Stored XSS via Chat and Support Ticket Systems |
10.08.2026 |
|
| CVE-2026-63106 |
ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php |
10.08.2026 |
|
| CVE-2026-71959 |
Bitwarden Server < 2026.7.2 Audit Log Injection via POST /collect |
10.08.2026 |
|
| CVE-2026-72751 |
Stored Cross-Site Scripting in CTI-Transmute Conversion Graph via Malicious STIX/MISP Content |
10.08.2026 |
|
| CVE-2026-15059 |
systemd-oomd: unprivileged users can terminate arbitrary processes |
10.08.2026 |
5.5 |
| CVE-2026-15060 |
systemd-machined: unprivileged users can terminate arbitrary processes |
10.08.2026 |
4.7 |
| CVE-2026-16742 |
systemd-homed: local privilege escalation via missing home-record signature verification on the authenticate path |
10.08.2026 |
6.7 |
| CVE-2026-18478 |
Stored XSS in Magnolia CMS |
10.08.2026 |
|
| CVE-2026-12984 |
Exposure of Sensitive Information to an Unauthorized Actor in Zyxel's WAH7601 |
10.08.2026 |
8.2 |
| CVE-2026-18370 |
Heap-based buffer overflow in entr |
10.08.2026 |
|
| CVE-2026-13206 |
Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection |
10.08.2026 |
9.8 |
| CVE-2026-6373 |
Sensitive Data Exposure in Zyxel WAH7601 Router |
10.08.2026 |
6.5 |
| CVE-2026-19278 |
Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m role mappings |
11.08.2026 |
|
| CVE-2026-19429 |
Jenkins - FilePath.untarFrom() Symlink Target Validation Bypass and Blank-Name Check Bypass (Arbitrary File Read) |
11.08.2026 |
8.8 |
| CVE-2026-59090 |
Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow |
11.08.2026 |
|
| CVE-2026-59233 |
Missing Authorization in Prospero Flow CRM permission save endpoint allows privilege escalation |
10.08.2026 |
|
| CVE-2026-68093 |
KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug |
10.08.2026 |
|
| CVE-2026-68094 |
sched_ext: Preserve rq tracking across local DSQ dispatch |
10.08.2026 |
|
| CVE-2026-68095 |
fuse-uring: fix race between registration and connection abortion |
10.08.2026 |
|
| CVE-2026-68096 |
audit: fix recursive locking deadlock in audit_dupe_exe() |
10.08.2026 |
|
| CVE-2026-68097 |
ksmbd: validate ACE size against SID sub-authorities |
10.08.2026 |
|
| CVE-2026-68098 |
ksmbd: bound DACL dedup walk to copied ACEs |
10.08.2026 |
|
| CVE-2026-68099 |
ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL |
10.08.2026 |
|
| CVE-2026-68100 |
ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl |
10.08.2026 |
|
| CVE-2026-68101 |
drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx |
10.08.2026 |
|
| CVE-2026-68102 |
drm/amdgpu: fix aperture mapping leak |
10.08.2026 |
|
| CVE-2026-68103 |
drm/amdgpu: reject mapping a reserved doorbell to a new queue |
10.08.2026 |
|
| CVE-2026-68104 |
drm/amdgpu: invoke pm_genpd_remove() before freeing genpd |
10.08.2026 |
|
| CVE-2026-68105 |
drm/amdgpu: Fix kernel panic during driver load failure |
10.08.2026 |
|
| CVE-2026-68106 |
drm/amdgpu: fix division by zero with invalid uvd dimensions |
10.08.2026 |
|
| CVE-2026-68107 |
drm/amdgpu/vcn4: avoid rereading IB param length |
10.08.2026 |
|
| CVE-2026-68108 |
drm/amdgpu/vce: fix integer overflow in image size |
10.08.2026 |
|
| CVE-2026-68109 |
drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON() |
10.08.2026 |
|
| CVE-2026-68110 |
drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() |
10.08.2026 |
|
| CVE-2026-68111 |
drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() |
10.08.2026 |
|
| CVE-2026-68112 |
drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() |
10.08.2026 |
|
| CVE-2026-68113 |
drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() |
10.08.2026 |
|
| CVE-2026-68114 |
drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON() |
10.08.2026 |
|
| CVE-2026-68115 |
drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() |
10.08.2026 |
|
| CVE-2026-68116 |
vxlan: mdb: Fix source list corruption on a failed replace |
10.08.2026 |
|
| CVE-2026-68117 |
tipc: clear sock->sk on the failed-insert path in tipc_sk_create() |
10.08.2026 |
|
| CVE-2026-68118 |
tcp: challenge ACK for non-exact RST in SYN-RECEIVED |
10.08.2026 |
|
| CVE-2026-68119 |
tcp: initialize standalone TCP-AO response padding |
10.08.2026 |
|
| CVE-2026-68120 |
rtase: Workaround for TX hang caused by hardware packet parsing |
10.08.2026 |
|
| CVE-2026-68121 |
pppoe: reload header pointer after dev_hard_header() |
10.08.2026 |
|
| CVE-2026-68122 |
ovpn: fix peer refcount leak in TCP error paths |
10.08.2026 |
|
| CVE-2026-68123 |
openvswitch: fix GSO userspace truncation underflow |
10.08.2026 |
|
| CVE-2026-68124 |
mctp: serial: handle zero-length frames to prevent rx buffer overflow |
10.08.2026 |
|
| CVE-2026-68125 |
mac802154: llsec: reject frames shorter than the authentication tag |
10.08.2026 |
|
| CVE-2026-68126 |
mac802154: hold an interface reference across the scan worker |
10.08.2026 |
|
| CVE-2026-68127 |
ila: reload IPv6 header after pskb_may_pull in checksum adjust |
10.08.2026 |
|
| CVE-2026-68128 |
ice: reject out-of-range ptype in ice_parser_profile_init |
10.08.2026 |
|
| CVE-2026-68129 |
gve: fix Rx queue stall on alloc failure |
10.08.2026 |
|
| CVE-2026-68130 |
ksmbd: defer destroy_previous_session() until after NTLM authentication |
10.08.2026 |
|
| CVE-2026-68131 |
rbd: Reset positive result codes to zero in object map update path |
10.08.2026 |
|
| CVE-2026-68132 |
super: fix emergency thaw deadlock on frozen block devices |
10.08.2026 |
|
| CVE-2026-68133 |
ice: fix PTP Call Trace during PTP release |
10.08.2026 |
|
| CVE-2026-68134 |
ptp: ptp_s390: Add missing facility check |
10.08.2026 |
|
| CVE-2026-68135 |
net: hip04: fix RX buffer leak on build_skb failure |
10.08.2026 |
|
| CVE-2026-68136 |
net: gro: fix double aggregation of flush-marked skbs |
10.08.2026 |
|
| CVE-2026-68137 |
net/x25: fix use-after-free in x25_kill_by_neigh() |
10.08.2026 |
|
| CVE-2026-68138 |
net/sched: serialize qdisc_rtab_list against concurrent get/put |
10.08.2026 |
|
| CVE-2026-68139 |
net/mlx5e: Use sender devcom for MPV master-up |
10.08.2026 |
|
| CVE-2026-68140 |
net/iucv: fix use-after-free of a severed iucv_path |
10.08.2026 |
|
| CVE-2026-68141 |
net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() |
10.08.2026 |
|
| CVE-2026-68142 |
geneve: require CAP_NET_ADMIN in the device netns for changelink |
10.08.2026 |
|
| CVE-2026-68143 |
net: slip: serialize receive against buffer reallocation |
10.08.2026 |
|
| CVE-2026-68144 |
phonet: pep: fix use-after-free in pep_get_sb() |
10.08.2026 |
|
| CVE-2026-68145 |
iomap: fix out-of-bounds bitmap_set() with zero-length range |
10.08.2026 |
|
| CVE-2026-68146 |
ftrace: Add global mutex to serialize trace_parser access |
10.08.2026 |
|
| CVE-2026-68147 |
fscrypt: Avoid dynamic allocation in fscrypt_get_devices() |
10.08.2026 |
|
| CVE-2026-68148 |
fscrypt: Add missing superblock check in find_or_insert_direct_key() |
10.08.2026 |
|
| CVE-2026-68149 |
fs: preserve ACL_DONT_CACHE state in forget_cached_acl() |
10.08.2026 |
|
| CVE-2026-68150 |
fs/super: fix emergency thaw double-unlock of s_umount |
10.08.2026 |
|
| CVE-2026-68151 |
binfmt_elf_fdpic: only honour the first PT_INTERP |
10.08.2026 |
|
| CVE-2026-68152 |
amt: fix use-after-free in AMT delayed works |
10.08.2026 |
|
| CVE-2026-68153 |
libceph: remove debugfs files before client teardown |
10.08.2026 |
|
| CVE-2026-68154 |
libceph: reject zero bucket types in crush_decode |
10.08.2026 |
|
| CVE-2026-68155 |
libceph: Reject monmaps advertising zero monitors |
10.08.2026 |
|
| CVE-2026-68156 |
libceph: refresh auth->authorizer_buf{,_len} after authorizer update |
10.08.2026 |
|
| CVE-2026-68157 |
libceph: guard missing CRUSH type name lookup |
10.08.2026 |
|
| CVE-2026-68158 |
libceph: Fix multiplication overflow in decode_new_up_state_weight() |
10.08.2026 |
|
| CVE-2026-68159 |
libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE |
10.08.2026 |
|
| CVE-2026-68160 |
ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() |
10.08.2026 |
|
| CVE-2026-68161 |
sctp: close UDP tunnel sockets during netns teardown |
10.08.2026 |
|
| CVE-2026-68162 |
sctp: avoid auth_enable sysctl UAF during netns teardown |
10.08.2026 |
|
| CVE-2026-68163 |
mm/page_vma_mapped: fix device-private PMD handling |
10.08.2026 |
|
| CVE-2026-68164 |
mm/damon/core: disallow overlapping input ranges for damon_set_regions() |
10.08.2026 |
|
| CVE-2026-68165 |
mm/damon/core: validate ranges in damon_set_regions() |
10.08.2026 |
|
| CVE-2026-68166 |
userfaultfd: prevent registration of special VMAs |
10.08.2026 |
|
| CVE-2026-68167 |
btrfs: do not try compression for data reloc inodes |
10.08.2026 |
|
| CVE-2026-68168 |
afs: Fix afs_edit_dir_remove() to get, not find, block 0 |
10.08.2026 |
|
| CVE-2026-68169 |
mptcp: pm: userspace: fix use-after-free in get_local_id |
10.08.2026 |
|
| CVE-2026-68170 |
mptcp: fix stale skb->sk reference on subflow close |
10.08.2026 |
|
| CVE-2026-68171 |
|
11.08.2026 |
|
| CVE-2026-68172 |
arm64: make huge_ptep_get handled unaligned addresses |
10.08.2026 |
|
| CVE-2026-68173 |
ublk: wait on ublk_dev_ready() instead of ub->completion |
10.08.2026 |
|
| CVE-2026-68174 |
tracing: Fix union collision of module and refcnt for dynamic events |
10.08.2026 |
|
| CVE-2026-68175 |
tracing: Fix resource leak on mmiotrace trace_pipe close |
10.08.2026 |
|
| CVE-2026-68176 |
tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev |
10.08.2026 |
|
| CVE-2026-68177 |
tracing: Delay module ref count for "enable_event" trigger |
10.08.2026 |
|
| CVE-2026-68178 |
misc: nsm: pin the module while the device is open |
10.08.2026 |
|
| CVE-2026-68179 |
misc: nsm: only unlock nsm_dev on post-lock error paths |
10.08.2026 |
|
| CVE-2026-68180 |
intel_th: fix MSC output device reference leak |
10.08.2026 |
|
| CVE-2026-68181 |
mei: bus: access mei_device under device_lock on cleanup |
10.08.2026 |
|
| CVE-2026-68182 |
comedi: comedi_parport: deal with premature interrupt |
10.08.2026 |
|
| CVE-2026-68183 |
firmware: stratix10-svc: fix memory leaks and list corruption bugs |
10.08.2026 |
|
| CVE-2026-68184 |
cdrom: fix stack out-of-bounds read in CDROMVOLCTRL |
10.08.2026 |
|
| CVE-2026-68185 |
LoongArch: Move jump_label_init() before parse_early_param() |
10.08.2026 |
|
| CVE-2026-68186 |
binfmt_misc: set have_execfd only once the interpreter is opened |
10.08.2026 |
|
| CVE-2026-68187 |
exec: fix unsigned loop counter wrap in transfer_args_to_stack() |
10.08.2026 |
|
| CVE-2026-68188 |
Bluetooth: RFCOMM: Fix session UAF in set_termios |
10.08.2026 |
|
| CVE-2026-68189 |
Bluetooth: hci_sync: Protect UUID list traversal |
10.08.2026 |
|
| CVE-2026-68190 |
staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() |
10.08.2026 |
|
| CVE-2026-68191 |
wifi: ath12k: fix NULL pointer dereference in rhash table destroy |
10.08.2026 |
|
| CVE-2026-68192 |
wifi: brcmfmac: make release_scratchbuffers idempotent |
10.08.2026 |
|
| CVE-2026-68193 |
wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses |
10.08.2026 |
|
| CVE-2026-68194 |
wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses |
10.08.2026 |
|
| CVE-2026-68195 |
wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses |
10.08.2026 |
|
| CVE-2026-68196 |
wifi: wilc1000: validate assoc response length before subtracting header |
10.08.2026 |
|
| CVE-2026-68197 |
wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper |
10.08.2026 |
|
| CVE-2026-68198 |
wifi: ath6kl: fix use-after-free in aggr_reset_state() |
10.08.2026 |
|
| CVE-2026-68199 |
wifi: ath6kl: fix OOB access from firmware ADDBA window size |
10.08.2026 |
|
| CVE-2026-68200 |
ALSA: timer: don't re-enter an instance callback that is still running |
10.08.2026 |
|
| CVE-2026-68201 |
ALSA: timer: drain a slave's callback before its master detaches it |
10.08.2026 |
|
| CVE-2026-68202 |
ALSA: seq: close a re-opened queue timer in the destructor |
10.08.2026 |
|
| CVE-2026-68203 |
media: vivid: fix cleanup bugs in vivid_init() |
10.08.2026 |
|
| CVE-2026-68204 |
media: vivid: check for vb2_is_busy() when toggling caps |
10.08.2026 |
|
| CVE-2026-68205 |
media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() |
10.08.2026 |
|
| CVE-2026-68206 |
media: v4l2-ctrls: validate HEVC active reference counts |
10.08.2026 |
|
| CVE-2026-68207 |
media: ti: vpe: unwind v4l2 device registration on probe error |
10.08.2026 |
|
| CVE-2026-68208 |
media: ti: vpe: Fix the error code of devm_kzalloc() in vip_probe_slice() |
10.08.2026 |
|
| CVE-2026-68209 |
media: sun4i-csi: Return queued buffers on start_streaming() failure |
10.08.2026 |
|
| CVE-2026-68210 |
media: stm32: dcmi: unregister notifier on probe failure |
10.08.2026 |
|
| CVE-2026-68211 |
media: stm32-dcmipp: Return queued buffers on start_streaming() failure |
10.08.2026 |
|
| CVE-2026-68212 |
media: saa7134: Fix a possible memory leak in saa7134_video_init1 |
10.08.2026 |
|
| CVE-2026-68213 |
media: rtl2832_sdr: Return queued buffers on start_streaming() failure |
10.08.2026 |
|
| CVE-2026-68214 |
media: rtl2832: fix use-after-free in rtl2832_remove() |
10.08.2026 |
|
| CVE-2026-68215 |
media: radio-si476x: Unregister v4l2_device on probe failure |
10.08.2026 |
|
| CVE-2026-68216 |
media: pwc: Return queued buffers on start_streaming() failure |
10.08.2026 |
|
| CVE-2026-68217 |
media: pwc: Drain fill_buf on start_streaming() failure |
10.08.2026 |
|
| CVE-2026-68218 |
media: pci: dm1105: Free allocated workqueue |
10.08.2026 |
|
| CVE-2026-68219 |
media: nxp: imx8-isi: Fix potential out-of-bounds issues |
10.08.2026 |
|
| CVE-2026-68220 |
media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe |
10.08.2026 |
|
| CVE-2026-68221 |
media: nuvoton: npcm-video: fix memory leaks in probe and remove |
10.08.2026 |
|
| CVE-2026-68222 |
media: msi2500: Return queued buffers on start_streaming() failure |
10.08.2026 |
|
| CVE-2026-68223 |
media: meson: vdec: Fix memory leak in error path of vdec_open |
10.08.2026 |
|
| CVE-2026-68224 |
media: mali-c55: Fix possible ERR_PTR in enable_streams |
10.08.2026 |
|
| CVE-2026-68225 |
media: i2c: alvium: fix critical pointer access in alvium_ctrl_init |
10.08.2026 |
|
| CVE-2026-68226 |
media: cx23885: add ioremap return check and cleanup |
10.08.2026 |
|
| CVE-2026-68227 |
media: cx231xx: fix devres lifetime |
10.08.2026 |
|
| CVE-2026-68228 |
media: chips-media: wave5: Move src_buf Removal to finish_encode |
10.08.2026 |
|
| CVE-2026-68229 |
media: cedrus: skip invalid H.264 reference list entries |
10.08.2026 |
|
| CVE-2026-68230 |
media: amlogic-c3: Add validations for ae and awb config |
10.08.2026 |
|
| CVE-2026-68231 |
media: airspy: Return queued buffers on start_streaming() failure |
10.08.2026 |
|
| CVE-2026-68232 |
drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict |
10.08.2026 |
|
| CVE-2026-68233 |
drm/vc4: Shut down BO cache timer before teardown |
10.08.2026 |
|
| CVE-2026-68234 |
drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved |
10.08.2026 |
|
| CVE-2026-68235 |
drm/amd/display: dce100: skip non-DP stream encoders for DP MST |
10.08.2026 |
|
| CVE-2026-68236 |
drm/amd/display: set new_stream to NULL after release |
10.08.2026 |
|
| CVE-2026-68237 |
drm/amdgpu/userq: fix indefinite fence wait during GPU reset |
10.08.2026 |
|
| CVE-2026-68238 |
drm/amdgpu: Release VFCT ACPI table reference |
10.08.2026 |
|
| CVE-2026-68239 |
drm/ttm: Account for NULL and handle pages in ttm_pool_backup |
10.08.2026 |
|
| CVE-2026-68240 |
drm/gpusvm: publish dpagemap early to avoid device mapping leak on error |
10.08.2026 |
|
| CVE-2026-68241 |
drm/i915/mst: limit DP MST ESI service loop |
10.08.2026 |
|
| CVE-2026-68242 |
drm/i915/gt: Fix NULL deref on sched_engine alloc failure |
10.08.2026 |
|
| CVE-2026-68243 |
drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU |
10.08.2026 |
|
| CVE-2026-68244 |
drm/i915/gem: Do not leak siblings[] on proto context error |
10.08.2026 |
|
| CVE-2026-68245 |
drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() |
10.08.2026 |
|
| CVE-2026-68246 |
drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() |
10.08.2026 |
|
| CVE-2026-68247 |
drm/i915/bios: range check LFP Data Block panel_type2 |
10.08.2026 |
|
| CVE-2026-68248 |
drm/i915: Return NULL on error in active_instance |
10.08.2026 |
|
| CVE-2026-68249 |
drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() |
10.08.2026 |
|
| CVE-2026-68250 |
drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() |
10.08.2026 |
|
| CVE-2026-68251 |
drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() |
10.08.2026 |
|
| CVE-2026-68252 |
drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() |
10.08.2026 |
|
| CVE-2026-68253 |
drm/i915/hdcp: check streams[] bounds before overflow |
10.08.2026 |
|
| CVE-2026-68254 |
drm/i915/vrr: require valid min/max vfreq for VRR |
10.08.2026 |
|
| CVE-2026-68255 |
drm/virtio: bound EDID block reads to the response buffer |
10.08.2026 |
|
| CVE-2026-68256 |
drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference |
10.08.2026 |
|
| CVE-2026-68257 |
drm/amdkfd: fix 32-bit overflow in CWSR total size calculation |
10.08.2026 |
|
| CVE-2026-68258 |
drm/amdkfd: Check bounds on CRIU restore queue type and mqd size |
10.08.2026 |
|
| CVE-2026-68259 |
drm/amdkfd: Check bounds in allocate_event_notification_slot |
10.08.2026 |
|
| CVE-2026-68260 |
drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM |
10.08.2026 |
|
| CVE-2026-68261 |
drm/imagination: fix error checking of pvr_vm_context_lookup() |
10.08.2026 |
|
| CVE-2026-68262 |
drm/imagination: Fix user array stride in pvr_set_uobj_array() |
10.08.2026 |
|
| CVE-2026-68263 |
drm/imagination: Fix double call to drm_sched_entity_fini() |
10.08.2026 |
|
| CVE-2026-68264 |
drm/xe/pt: Reset current_op in xe_pt_update_ops_init() |
10.08.2026 |
|
| CVE-2026-68265 |
drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC |
10.08.2026 |
|
| CVE-2026-68266 |
drm/xe: Hold a dma-buf reference for imported BOs |
10.08.2026 |
|
| CVE-2026-68267 |
drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists |
10.08.2026 |
|
| CVE-2026-68268 |
drm/xe: Return error on non-migratable faults requiring devmem |
10.08.2026 |
|
| CVE-2026-68269 |
drm/i915/gem: Add missing nospec on parallel submit slot |
10.08.2026 |
|
| CVE-2026-68270 |
drm/sysfb: Avoid possible truncation with calculating visible size |
10.08.2026 |
|
| CVE-2026-68271 |
drm/nouveau: fix reversed error cleanup order in ucopy functions |
10.08.2026 |
|
| CVE-2026-68272 |
drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 |
10.08.2026 |
|
| CVE-2026-68273 |
drm/amdgpu: Fix context pstate override handling |
10.08.2026 |
|
| CVE-2026-68274 |
drm/xe/guc: Fix buffer overflow in steered register list allocation |
10.08.2026 |
|
| CVE-2026-68275 |
drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO |
10.08.2026 |
|
| CVE-2026-68276 |
drm/amdgpu/gfx: fix cleaner shader IB buffer overflow |
10.08.2026 |
|
| CVE-2026-68277 |
drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers |
10.08.2026 |
|
| CVE-2026-68278 |
drm/dp/mst: fix buffer overflows in sideband chunk accumulation |
10.08.2026 |
|
| CVE-2026-68279 |
drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers |
10.08.2026 |
|
| CVE-2026-68280 |
drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() |
10.08.2026 |
|
| CVE-2026-68281 |
drm/imagination: Count paired job fence as dependency in prepare_job() |
10.08.2026 |
|
| CVE-2026-68282 |
drm/rockchip: analogix_dp: Add missing error check for platform_get_resource() |
10.08.2026 |
|
| CVE-2026-68283 |
tracing: Fix use-after-free freeing trigger private data |
10.08.2026 |
|
| CVE-2026-68284 |
bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() |
10.08.2026 |
|
| CVE-2026-68285 |
LoongArch: BPF: Fix memory leak in bpf_jit_free() |
10.08.2026 |
|
| CVE-2026-68286 |
drop_monitor: perform u64_stats updates under IRQ-disabled section |
10.08.2026 |
|
| CVE-2026-68287 |
drop_monitor: fix size calculations for 64-bit attributes |
10.08.2026 |
|
| CVE-2026-68288 |
net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD |
10.08.2026 |
|
| CVE-2026-68289 |
tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() |
10.08.2026 |
|
| CVE-2026-68290 |
rds: tcp: unregister sysctl before tearing down listen socket |
10.08.2026 |
|
| CVE-2026-68291 |
idpf: fix max_vport related crash on allocation error during init |
10.08.2026 |
|
| CVE-2026-68292 |
ice: prevent tstamp ring allocation for non-PF VSI types |
10.08.2026 |
|
| CVE-2026-68293 |
net/mlx5: Fix MCIA register buffer overflow on 32 dword reads |
10.08.2026 |
|
| CVE-2026-68294 |
net: qrtr: restrict socket creation to the initial network namespace |
10.08.2026 |
|
| CVE-2026-68295 |
LoongArch: BPF: Zero-extend signed ALU32 div/mod results |
10.08.2026 |
|
| CVE-2026-68296 |
net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM |
10.08.2026 |
|
| CVE-2026-68297 |
tipc: fix u16 MTU truncation in media and bearer MTU validation |
10.08.2026 |
|
| CVE-2026-68298 |
drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create() |
10.08.2026 |
|
| CVE-2026-68299 |
vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets |
10.08.2026 |
|
| CVE-2026-68300 |
sctp: auth: verify auth requirement when auth_chunk is NULL |
10.08.2026 |
|
| CVE-2026-68301 |
net: hsr: fix memory leak on slave unregistration by removing synced VLANs |
10.08.2026 |
|
| CVE-2026-68302 |
amt: re-read skb header pointers after every pull |
10.08.2026 |
|
| CVE-2026-68303 |
drm/vc4: hvs/v3d: Fix null dereference in unbind |
10.08.2026 |
|
| CVE-2026-68304 |
wifi: brcmfmac: fix 802.1X-SHA256 call trace warning |
10.08.2026 |
|
| CVE-2026-68305 |
drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers |
10.08.2026 |
|
| CVE-2026-68306 |
wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() |
10.08.2026 |
|
| CVE-2026-68307 |
wifi: mt76: mt7925: fix crash in reset link replay |
10.08.2026 |
|
| CVE-2026-68308 |
wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() |
10.08.2026 |
|
| CVE-2026-68309 |
wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() |
10.08.2026 |
|
| CVE-2026-68310 |
wifi: mt76: mt7915: guard HE capability lookups |
10.08.2026 |
|
| CVE-2026-68311 |
wifi: mt76: mt7925: guard link STA in decap offload |
10.08.2026 |
|
| CVE-2026-68312 |
cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths |
10.08.2026 |
|
| CVE-2026-68313 |
tipc: fix infinite loop in __tipc_nl_compat_dumpit |
10.08.2026 |
|
| CVE-2026-68314 |
net: mctp i3c: clean up notifier and buses if driver register fails |
10.08.2026 |
|
| CVE-2026-68315 |
sctp: validate stream count in sctp_process_strreset_inreq() |
10.08.2026 |
|
| CVE-2026-68316 |
accel: ethosu: Fix element size accounting for cmd stream validation |
10.08.2026 |
|
| CVE-2026-68317 |
pds_core: fix auxiliary device add/del races |
10.08.2026 |
|
| CVE-2026-68318 |
pds_core: fix use-after-free on workqueue during remove |
10.08.2026 |
|
| CVE-2026-68319 |
pds_core: fix deadlock between reset thread and remove |
10.08.2026 |
|
| CVE-2026-68320 |
sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid |
10.08.2026 |
|
| CVE-2026-68321 |
net: txgbe: fix FDIR filter leak on remove |
10.08.2026 |
|
| CVE-2026-68322 |
rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled |
10.08.2026 |
|
| CVE-2026-68323 |
tipc: serialize udp bearer replicast list updates |
10.08.2026 |
|
| CVE-2026-68324 |
iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() |
10.08.2026 |
|
| CVE-2026-68325 |
iommu/amd: Bound the early ACPI HID map |
10.08.2026 |
|
| CVE-2026-68326 |
wifi: mwifiex: bound uAP association event IEs to the event buffer |
10.08.2026 |
|
| CVE-2026-68327 |
wan: wanxl: Only reset hardware after BAR mapping |
10.08.2026 |
|
| CVE-2026-68328 |
nfp: Check resource mutex allocation |
10.08.2026 |
|
| CVE-2026-68329 |
iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() |
10.08.2026 |
|
| CVE-2026-68330 |
net: airoha: Fix DMA direction for NPU mailbox buffer |
10.08.2026 |
|
| CVE-2026-68331 |
dpaa2-eth: put MAC endpoint device on disconnect |
10.08.2026 |
|
| CVE-2026-68332 |
net: airoha: Fix potential use-after-free in airoha_ppe_deinit() |
10.08.2026 |
|
| CVE-2026-68333 |
dpaa2-switch: put MAC endpoint device on disconnect |
10.08.2026 |
|
| CVE-2026-68334 |
rxrpc: fix io_thread race in rxrpc_wake_up_io_thread() |
10.08.2026 |
|
| CVE-2026-68335 |
rds: drop incoming messages that cross network namespace boundaries |
10.08.2026 |
|
| CVE-2026-68336 |
bonding: fix devconf_all NULL dereference when IPv6 is disabled |
10.08.2026 |
|
| CVE-2026-68337 |
bpf: Reject redirect helpers without a bpf_net_context |
10.08.2026 |
|
| CVE-2026-68338 |
net/packet: avoid fanout hook re-registration after unregister |
10.08.2026 |
|
| CVE-2026-68339 |
Bluetooth: btusb: validate Realtek vendor event length |
10.08.2026 |
|
| CVE-2026-68340 |
hwmon: occ: validate poll response sensor blocks |
10.08.2026 |
|
| CVE-2026-68341 |
ovpn: fix use after free in unlock_ovpn() |
10.08.2026 |
|
| CVE-2026-68342 |
ovpn: avoid putting unrelated P2P peer on socket release |
10.08.2026 |
|
| CVE-2026-68343 |
smb: client: validate DFS referral PathConsumed |
10.08.2026 |
|
| CVE-2026-68344 |
usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect |
10.08.2026 |
|
| CVE-2026-68345 |
arm_mpam: guard MBWU state before adding it to garbage |
10.08.2026 |
|
| CVE-2026-68346 |
ALSA: hda: cs35l41: validate and free ACPI mute object |
10.08.2026 |
|
| CVE-2026-68347 |
iommu/amd: Fix IRQ unsafe locking in gdom allocation |
10.08.2026 |
|
| CVE-2026-68348 |
ASoC: tas2781: bound firmware description string parsing |
10.08.2026 |
|
| CVE-2026-68349 |
wifi: carl9170: fix buffer overflow in rx_stream failover path |
10.08.2026 |
|
| CVE-2026-68350 |
wifi: carl9170: fix OOB read from off-by-two in TX status handler |
10.08.2026 |
|
| CVE-2026-68351 |
wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read |
10.08.2026 |
|
| CVE-2026-68352 |
wifi: ath6kl: fix OOB read from firmware IE lengths in connect event |
10.08.2026 |
|
| CVE-2026-68353 |
wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler |
10.08.2026 |
|
| CVE-2026-68354 |
firewire: net: Fix fragmented datagram reassembly |
10.08.2026 |
|
| CVE-2026-68355 |
wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() |
10.08.2026 |
|
| CVE-2026-68356 |
watchdog: airoha: Prevent division by zero when clock frequency is zero |
10.08.2026 |
|
| CVE-2026-68357 |
watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() |
10.08.2026 |
|
| CVE-2026-68358 |
hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop |
10.08.2026 |
|
| CVE-2026-68359 |
hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop |
10.08.2026 |
|
| CVE-2026-68360 |
hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop |
10.08.2026 |
|
| CVE-2026-68361 |
hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop |
10.08.2026 |
|
| CVE-2026-68362 |
wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin |
10.08.2026 |
|
| CVE-2026-68363 |
wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request |
10.08.2026 |
|
| CVE-2026-68364 |
drm/amd/display: Fix ISM dc_lock deadlock during suspend |
10.08.2026 |
|
| CVE-2026-68365 |
USB: serial: io_edgeport: cap received transmit credits |
10.08.2026 |
|
| CVE-2026-68366 |
usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer |
10.08.2026 |
|
| CVE-2026-68367 |
usb: gadget: f_tcm: synchronize delayed set_alt with teardown |
10.08.2026 |
|
| CVE-2026-68368 |
usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() |
10.08.2026 |
|
| CVE-2026-68369 |
usb: gadget: printer: fix infinite loop in printer_read() |
10.08.2026 |
|
| CVE-2026-68370 |
usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback |
10.08.2026 |
|
| CVE-2026-68371 |
usb: musb: omap2430: Do not put borrowed of_node in probe |
10.08.2026 |
|
| CVE-2026-68372 |
usb: core: port: Deattach Type-C connector on component unbind |
10.08.2026 |
|
| CVE-2026-68373 |
wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() |
10.08.2026 |
|
| CVE-2026-68374 |
usb: core: sysfs: add lock to bos_descriptors_read() |
10.08.2026 |
|
| CVE-2026-68375 |
bnxt_en: Handle partially initialized auxiliary devices |
10.08.2026 |
|
| CVE-2026-68376 |
sctp: fix auth_hmacs array size in struct sctp_cookie |
10.08.2026 |
|
| CVE-2026-68377 |
net/sched: act_tunnel_key: Defer dst_release to RCU callback |
10.08.2026 |
|
| CVE-2026-68378 |
dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() |
10.08.2026 |
|
| CVE-2026-68379 |
tcp: fix TIME_WAIT socket reference leak on PSP policy failure |
10.08.2026 |
|
| CVE-2026-68380 |
accel/amdxdna: Fix use-after-free of mm_struct in job scheduler |
10.08.2026 |
|
| CVE-2026-68381 |
ksmbd: pin conn during async oplock break notification |
10.08.2026 |
|
| CVE-2026-68382 |
drm/xe/guc: Hold device ref until queue teardown completes |
10.08.2026 |
|
| CVE-2026-68383 |
drm/xe/guc: Keep scheduler timeline name alive |
10.08.2026 |
|
| CVE-2026-68384 |
drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves |
10.08.2026 |
|
| CVE-2026-68385 |
s390/checksum: Fix csum_partial() without vector facility |
10.08.2026 |
|
| CVE-2026-68386 |
bpf, sockmap: Reject unhashed UDP sockets on sockmap update |
10.08.2026 |
|
| CVE-2026-68387 |
can: raw: add locking for raw flags bitfield |
10.08.2026 |
|
| CVE-2026-68388 |
smb/client: handle overlapping allocated ranges in fallocate |
10.08.2026 |
|
| CVE-2026-68389 |
Bluetooth: hci_qca: Clear memdump state on invalid dump size |
10.08.2026 |
|
| CVE-2026-68390 |
Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups |
10.08.2026 |
|
| CVE-2026-68391 |
Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds |
10.08.2026 |
|
| CVE-2026-68392 |
Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync |
10.08.2026 |
|
| CVE-2026-68393 |
Bluetooth: hci_sync: extend conn_hash lookup critical sections |
10.08.2026 |
|
| CVE-2026-68394 |
Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update |
10.08.2026 |
|
| CVE-2026-68395 |
ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered |
10.08.2026 |
|
| CVE-2026-68396 |
scsi: core: wake eh reliably when using scsi_schedule_eh |
10.08.2026 |
|
| CVE-2026-68397 |
net/iucv: take a reference on the socket found in afiucv_hs_rcv() |
10.08.2026 |
|
| CVE-2026-68398 |
ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF |
10.08.2026 |
|
| CVE-2026-68399 |
bpf: Fix UAF in sock clone early bailouts |
10.08.2026 |
|
| CVE-2026-68400 |
firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation |
10.08.2026 |
|
| CVE-2026-68401 |
firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() |
10.08.2026 |
|
| CVE-2026-68402 |
wifi: cfg80211: bound element ID read when checking non-inheritance |
10.08.2026 |
|
| CVE-2026-68403 |
wifi: brcmfmac: initialize SDIO data work before cleanup |
10.08.2026 |
|
| CVE-2026-68404 |
wifi: cfg80211: use wiphy work for socket owner autodisconnect |
10.08.2026 |
|
| CVE-2026-68405 |
wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock |
10.08.2026 |
|
| CVE-2026-68406 |
wifi: cfg80211: validate PMSR FTM preamble range |
10.08.2026 |
|
| CVE-2026-68407 |
wifi: nl80211: free RNR data on MBSSID mismatch |
10.08.2026 |
|
| CVE-2026-68408 |
wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock |
10.08.2026 |
|
| CVE-2026-68409 |
wifi: mac80211: defer link RX stats percpu free to RCU |
10.08.2026 |
|
| CVE-2026-68410 |
wifi: libertas: fix memory leak in helper_firmware_cb() |
10.08.2026 |
|
| CVE-2026-68411 |
wifi: mac80211_hwsim: clamp virtio RX length before skb_put |
10.08.2026 |
|
| CVE-2026-68412 |
wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() |
10.08.2026 |
|
| CVE-2026-68413 |
wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() |
10.08.2026 |
|
| CVE-2026-68414 |
wifi: cfg80211: cancel sched scan results work on unregister |
10.08.2026 |
|
| CVE-2026-68415 |
xfrm: clear mode callbacks after failed mode setup |
10.08.2026 |
|
| CVE-2026-68416 |
mtd: fix double free and WARN_ON in add_mtd_device() error paths |
10.08.2026 |
|
| CVE-2026-68417 |
RDMA/siw: publish QP after initialization |
10.08.2026 |
|
| CVE-2026-68418 |
RDMA/irdma: Prevent user-triggered null deref on QP create |
10.08.2026 |
|
| CVE-2026-68419 |
RDMA/irdma: Prevent rereg_mr for non-mem regions |
10.08.2026 |
|
| CVE-2026-68420 |
xfrm: reject optional IPTFS templates in outbound policies |
10.08.2026 |
|
| CVE-2026-68421 |
sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx() |
10.08.2026 |
|
| CVE-2026-68422 |
btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() |
10.08.2026 |
|
| CVE-2026-68423 |
mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy() |
10.08.2026 |
|
| CVE-2026-68424 |
mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy_joins() |
10.08.2026 |
|
| CVE-2026-68425 |
IB/mad: Drop unmatched RMPP responses before reassembly |
10.08.2026 |
|
| CVE-2026-68426 |
xfrm: fix stale skb->prev after async crypto steals a GSO segment |
10.08.2026 |
|
| CVE-2026-68427 |
gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings |
10.08.2026 |
|
| CVE-2026-68428 |
KVM: x86/mmu: Fix use-after-free on vendor module reload |
10.08.2026 |
|
| CVE-2026-6374 |
Hardcoded Credentials in Zyxel WAH7601 Router |
10.08.2026 |
7.3 |
| CVE-2026-72688 |
OpenSignLabs opensignserver - Missing Authentication for Critical Function |
10.08.2026 |
7.5 |
| CVE-2026-72689 |
OpenSignLabs opensignserver - Broken Object Level Authorization |
10.08.2026 |
7.5 |
| CVE-2026-72690 |
Attendize Attendize - Cross-Tenant Authorization Bypass |
10.08.2026 |
5.4 |
| CVE-2026-72691 |
OpenSignLabs opensignserver - Authentication Bypass |
10.08.2026 |
7.5 |
| CVE-2026-72692 |
OpenSignLabs opensignserver - Missing Authorization |
10.08.2026 |
7.5 |
| CVE-2026-68083 |
ksmbd: fix path resolution in ksmbd_vfs_kern_path_create |
10.08.2026 |
|
| CVE-2026-68084 |
staging: vme_user: fix location monitor leak in tsi148 bridge |
10.08.2026 |
|
| CVE-2026-68085 |
Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled |
10.08.2026 |
|
| CVE-2026-68086 |
mm/khugepaged: write all dirty file folios when collapsing |
10.08.2026 |
|
| CVE-2026-68087 |
HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush() |
10.08.2026 |
|
| CVE-2026-68088 |
usb: gadget: function: rndis: add length check to response query |
10.08.2026 |
|
| CVE-2026-68089 |
iio: core: fix uninitialized data in debugfs |
10.08.2026 |
|
| CVE-2026-68090 |
debugobjects: Plug race against a concurrent OOM disable |
10.08.2026 |
|
| CVE-2026-68091 |
HID: wacom: stop hardware after post-start probe failures |
10.08.2026 |
|
| CVE-2026-68092 |
time/jiffies: Register jiffies clocksource before usage |
10.08.2026 |
|
| CVE-2026-59088 |
Gimp: gimp: denial of service via signed integer overflow in fli file processing |
11.08.2026 |
|
| CVE-2026-64941 |
Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR |
10.08.2026 |
|
| CVE-2026-59087 |
Gimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes attacker-controlled length into undersized allocation |
10.08.2026 |
|
| CVE-2026-61899 |
Apache Tapestry: Possible classpath file download through URL manipulation |
10.08.2026 |
|
| CVE-2026-72564 |
fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication |
10.08.2026 |
9.6 |
| CVE-2026-72565 |
Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form Bypass |
10.08.2026 |
9.8 |
| CVE-2026-72566 |
automatisch - Server-Side Request Forgery via HTTP Request Custom Action |
10.08.2026 |
7.7 |
| CVE-2026-72567 |
deepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Write and Delete |
10.08.2026 |
9.8 |
| CVE-2026-72568 |
Redis - Heap Out-of-Bounds Read in Cluster Bus PING Message Handler |
10.08.2026 |
7.1 |
| CVE-2026-72569 |
cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Deletion |
10.08.2026 |
9.1 |
| CVE-2026-72570 |
cube-root directory-serve - Stored Cross-Site Scripting via Malicious Filename |
10.08.2026 |
5.4 |
| CVE-2026-72571 |
mustafaakin cast-localvideo - Unauthenticated Path Traversal via dir Parameter |
10.08.2026 |
7.5 |
| CVE-2026-72572 |
o1lab xmysql - Unauthenticated Path Traversal via name Query Parameter |
10.08.2026 |
7.5 |
| CVE-2026-72573 |
4xmen pm2panel - Authenticated OS Command Injection via id Query Parameter |
10.08.2026 |
8.8 |
| CVE-2026-72574 |
picocms Pico - Host Header Injection Enables Script Source Hijacking |
10.08.2026 |
6.1 |
| CVE-2026-72575 |
daptin - Authentication Bypass via Null Owner Permission Check on usergroup Objects |
10.08.2026 |
9.1 |
| CVE-2026-72576 |
Bludit - Stored Cross-Site Scripting via Malicious SVG Logo Upload |
10.08.2026 |
5.4 |
| CVE-2026-72577 |
NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command Injection |
10.08.2026 |
9.8 |
| CVE-2026-72578 |
FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher |
10.08.2026 |
8.8 |
| CVE-2026-72579 |
NASA HyperCP - OS Command Injection via Malicious HTTP Response from Data Server |
10.08.2026 |
7.5 |
| CVE-2026-72580 |
duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints |
10.08.2026 |
9.8 |
| CVE-2026-72581 |
duhow xiaoai-patch - Server-Side Request Forgery in /auth Endpoint |
10.08.2026 |
8.6 |
| CVE-2026-72582 |
fastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery Endpoint |
10.08.2026 |
7.5 |
| CVE-2026-72583 |
fastschema - Stored Cross-Site Scripting via MIME Type Bypass in File Upload |
10.08.2026 |
5.4 |
| CVE-2026-72584 |
fastschema - TOCTOU Race Condition Bypasses OTP Attempt Limit in Account Recovery |
10.08.2026 |
7.4 |
| CVE-2026-72585 |
Grafana - Incomplete Fix for CVE-2026-21724 Allows Editor Role to Delete Protected Contact Points |
10.08.2026 |
6.5 |
| CVE-2026-72586 |
frangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event Handler |
10.08.2026 |
7.5 |
| CVE-2026-72587 |
Instatic - Cache Poisoning via Unauthenticated Server Island Endpoint |
10.08.2026 |
6.1 |
| CVE-2026-72588 |
bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in Password Recovery |
10.08.2026 |
5.3 |
| CVE-2026-72589 |
alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook Field |
10.08.2026 |
9.8 |
| CVE-2026-72590 |
alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter |
10.08.2026 |
9.8 |
| CVE-2026-72591 |
Koito - Authenticated Server-Side Request Forgery via Album Image URL Parameter |
10.08.2026 |
7.7 |
| CVE-2026-72592 |
dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload |
10.08.2026 |
9.8 |
| CVE-2026-72593 |
dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access |
10.08.2026 |
9.8 |
| CVE-2026-72594 |
lobehub lobe-chat - Stored Cross-Site Scripting via Unrestricted SVG Avatar Upload |
10.08.2026 |
7.6 |
| CVE-2026-28672 |
Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder |
10.08.2026 |
|
| CVE-2026-32227 |
Apache Ranger: SQL Injection vulnerability in lookup functionality |
10.08.2026 |
|
| CVE-2026-40920 |
Apache Ranger: Privilege Escalation via URL Parameter |
10.08.2026 |
|
| CVE-2026-42537 |
Apache Ranger: Remote Code Execution via JDBC URL Injection |
10.08.2026 |
|
| CVE-2026-44416 |
Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation |
10.08.2026 |
|
| CVE-2026-55799 |
Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator |
10.08.2026 |
|
| CVE-2026-66484 |
Path Traversal in GNU cpio |
10.08.2026 |
|
| CVE-2026-66485 |
Uncontrolled Memory Allocation in GNU cpio |
10.08.2026 |
|
| CVE-2026-66486 |
Improper Output Encoding in GNU cpio |
10.08.2026 |
|
| CVE-2026-71394 |
Heap Use of Uninitialized Memory in GNU Emacs for Android |
10.08.2026 |
|