Total CVEs

150,703

Critical Severity

4,956

High Severity

17,517

Last 7 Days

2,051
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,701 - 1,720 of 47,108 CVEs
CVE-2026-64260 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid queue->stopped races and set/read that value under lock There are several readers of queue->stopped that check the value under lock, but fuse_uring_commit_fetch() did not and actually the value was not set ...

Vendor: Linux
Product: Linux
Published: Jul 25, 2026
Source: NVD
CVE-2026-64259 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: make a fuse_req on SQE commit only findable after memcpy Bad userspace might try to trick us and send commit SQEs request unique / commit-id of requests that are not even send to fuse-server (io_uring_cmd_done() not ca...

Vendor: Linux
Product: Linux
Published: Jul 25, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref If a copy into the userspace ring buffer fails, a request will be terminated and fuse_uring_req_end() will set ent->fuse_req to NULL but it will lea...

Vendor: Linux
Product: Linux
Published: Jul 25, 2026
Source: NVD
CVE-2026-64257 CRITICAL - 9.1

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[0] length exception to respons...

Vendor: Linux
Product: Linux
Published: Jul 25, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: xfs: don't wrap around quota ids in dqiterate LOLLM noticed that q_id is an unsigned 32-bit variable. If it happens to be set to XFS_DQ_ID_MAX due to a filesystem that actually has a dquot for ID_MAX, then this addition will...

Vendor: Linux
Product: Linux
Published: Jul 25, 2026
Source: NVD
CVE-2026-16766 CRITICAL - 9.8

Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. Any web application that passes user-controlled options such as the page_size, orientation or margins ...

Vendor: RRWO
Product: Catalyst::View::Wkhtmltopdf
Published: Jul 25, 2026
Source: NVD
CVE-2026-15425 MEDIUM - 6.4

The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up to, and including, 28.0 due to insufficient input sanitization and output escaping. This makes it possible for authentic...

Vendor: yoast
Product: Yoast SEO – Advanced SEO with real-time guidance and built-in AI
Published: Jul 25, 2026
Source: NVD
CVE-2026-14955 MEDIUM - 6.5

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read ...

Vendor: Themehigh
Product: Checkout Field Editor for WooCommerce (Pro)
Published: Jul 25, 2026
Source: NVD
CVE-2026-10818 HIGH - 8.1

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the ...

Vendor: WPForms
Product: WPForms Pro
Published: Jul 25, 2026
Source: NVD
CVE-2026-66374 HIGH - 8.1

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

Vendor: nic
Product: Knot Resolver
Published: Jul 25, 2026
Source: NVD
CVE-2026-66373 HIGH - 7.5

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. ...

Vendor: Redis
Product: Redis
Published: Jul 25, 2026
Source: NVD
CVE-2026-66339 MEDIUM - 6.5

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, lead...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 24, 2026
Source: NVD
CVE-2026-66338 MEDIUM - 5.4

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend prox...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 24, 2026
Source: NVD
CVE-2026-66337 MEDIUM - 6.5

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client appl...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 24, 2026
Source: NVD
CVE-2026-61892 HIGH - 8.8

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

Vendor: Weintek
Product: cMT3092X firmware, EasyWeb
Published: Jul 24, 2026
Source: NVD
CVE-2026-61886 MEDIUM - 6.5

Weintek cMT3092X HMI stores user account passwords in plaintext.

Vendor: Weintek
Product: cMT3092X firmware, EasyWeb
Published: Jul 24, 2026
Source: NVD
CVE-2026-60135 MEDIUM - 6.5

An attacker can modify data that should be restricted to read‑only access.

Vendor: Weintek
Product: cMT3092X firmware, EasyWeb
Published: Jul 24, 2026
Source: NVD
CVE-2026-60134 HIGH - 8.8

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

Vendor: Weintek
Product: cMT3092X firmware, EasyWeb
Published: Jul 24, 2026
Source: NVD
CVE-2026-16280 CRITICAL - 9.8

An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memor...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jul 24, 2026
Source: NVD
CVE-2026-61884 CRITICAL - 9.8

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid admi...

Vendor: Tycon Systems
Product: TPDIN-Monitor-WEB2
Published: Jul 24, 2026
Source: NVD