Total CVEs

150,703

Critical Severity

4,956

High Severity

17,517

Last 7 Days

2,022
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,801 - 1,820 of 47,108 CVEs
CVE-2026-64216 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it is wanting to unlock and compares that to rreq->no_unlock_folio so that it doesn't...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table Check the return value of kzalloc() to prevent a NULL pointer dereference on allocation failure. Patchwork: https://patchwork.freedesktop.org/patch/721342/

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() A kernel panic is observed when handling machine check exceptions from real mode. BUG: Unable to handle kernel data access on read at 0xc0...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Add lock protection to lm90_alert Sashiko reports: lm90_alert() executes in the smbus alert context and calls lm90_update_confreg() to disable the hardware alert line, without acquiring hwmon_lock. Concurrently, sy...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it In iwl_mld_remove_link, the link->fw_id is saved at the beginning of the function so we have it after we freed the link. But the link pointer can be ...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: srcu: Don't queue workqueue handlers to never-online CPUs While an srcu_struct structure is in the midst of switching from CPU-0 to all-CPUs state, it can attempt to invoke callbacks for CPUs that have never been online. Wor...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD
CVE-2026-64210 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ During napi poll, when the affinity changes and there's still XSK work to be done, we trigger an ICOSQ interrupt on the new CPU. However, this triggering on the ICOSQ is done unpr...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config swing_tbl and pre_emphasis_tbl are 4x4 arrays (valid indices 0-3), but the boundary check uses "> 4" instead of ">= 4", allowing inde...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD
CVE-2026-64208 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks Change the krb5 crypto library to provide facilities to precheck the length of the message about to be decrypted or verified. Fix AF_RXRPC to make use of this t...

Vendor: Linux
Product: Linux
Published: Jul 24, 2026
Source: NVD

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without t...

Vendor: Red Hat
Product: Red Hat Certificate System 10, Red Hat Certificate System 11, Red Hat Certificate System 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 24, 2026
Source: NVD

Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its flatten() helper when validation issues contain attacker-controlled object keys such as toString, valueOf, or hasOwnProperty. The issue is reachable through normal record() validation. record() inten...

Vendor: npm
Product: valibot
Published: Jul 24, 2026
Source: GitHub
CVE-2026-59940 CRITICAL - 9.8

seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization

Vendor: npm
Product: seroval
Published: Jul 24, 2026
Source: GitHub
CVE-2026-59949 MEDIUM - 6.5

LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges

Vendor: maven
Product: at.yawk.lz4:lz4-java
Published: Jul 24, 2026
Source: GitHub

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

Vendor: pip
Product: onnx
Published: Jul 24, 2026
Source: GitHub
CVE-2026-8789 HIGH - 8.1

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated a...

Published: Jul 24, 2026
Source: NVD
CVE-2026-8308 MEDIUM - 6.1

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2.

Published: Jul 24, 2026
Source: NVD
CVE-2026-7007 MEDIUM - 4.6

The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.c) before completing a mount. The validator checked the magic number, block size, revision and feature flags, but did not verify that the on-disk fields s_blocks_per_group and s_in...

Published: Jul 24, 2026
Source: NVD
CVE-2026-66007 MEDIUM - 6.5

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with directory traversal ...

Vendor: huggingface
Product: datasets
Published: Jul 24, 2026
Source: NVD
CVE-2026-66006 MEDIUM - 5.3

lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup completion. Attackers can POST to this endpoint to mod...

Vendor: treeverse
Product: lakeFS
Published: Jul 24, 2026
Source: NVD
CVE-2026-66005 MEDIUM - 6.3

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard that reflects arb...

Vendor: janhq
Product: jan
Published: Jul 24, 2026
Source: NVD