Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,443
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,441 - 3,460 of 33,646 CVEs
CVE-2026-26379 MEDIUM - 6.5

Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzing server response times.

Vendor: koha
Product: koha
Published: Jun 03, 2026
Source: NVD
CVE-2026-26378 MEDIUM - 5.4

Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice features

Vendor: koha
Product: koha
Published: Jun 03, 2026
Source: NVD
CVE-2026-46273 HIGH - 8.6

In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power systems do not support segmentation offload when the MSS is less than 224 bytes. Attempting to send such packets causes the adapter to freeze, stoppin...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46272 MEDIUM - 4.7

In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etr: Fix race condition between sysfs and perf mode When trying to run perf and sysfs mode simultaneously, the WARN_ON() in tmc_etr_enable_hw() is triggered sometimes: WARNING: CPU: 42 PID: 3911571 at drivers/hwtr...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46271 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link In case of multi-link connection, WCN7850 firmware crashes due to WoW offloads enabled on both primary and secondary links. Change to do it only on primary link to fix it. Teste...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46270 HIGH - 8.4

In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_supply_changed() Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `power_supply` handle, means that the `power_supply` hand...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46269 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: pinctrl: canaan: k230: Fix NULL pointer dereference when parsing devicetree When probing the k230 pinctrl driver, the kernel triggers a NULL pointer dereference. The crash trace showed: [ 0.732084] Unable to handle kernel NULL ...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46268 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: PCI/P2PDMA: Fix p2pmem_alloc_mmap() warning condition Commit b7e282378773 has already changed the initial page refcount of p2pdma page from one to zero, however, in p2pmem_alloc_mmap() it uses "VM_WARN_ON_ONCE_PAGE(!page_ref_...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46267 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freeing context llc_shdlc_deinit() purges SHDLC skb queues and frees the llc_shdlc structure while its timers and state machine work may still be active. Timer callbacks can schedule s...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46266 CRITICAL - 9.1

In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reported that simply having one RAW socket on protocol IPPROTO_RAW (255) was dangerous. socket(AF_INET, SOCK_RAW, 255); A malicious incoming ICMP packet c...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46265 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix WQ_MEM_RECLAIM warning When sunrpc is used, if a reset triggered, our wq may lead the following trace: workqueue: WQ_MEM_RECLAIM xprtiod:xprt_rdma_connect_worker [rpcrdma] is flushing !WQ_MEM_RECLAIM hns_roce_irq_wo...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46264 HIGH - 8.8

In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of devm_add_action_or_reset() failure the provided cleanup action will be run immediately on the not yet initialized kobject. This may lead to errors like: [ ] kobject: '(null)�...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46263 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds stream encoder index v3 eng_id can be negative and that stream_enc_regs[] can be indexed out of bounds. eng_id is used directly as an index into stream_enc_regs[], which has only 5 entries. When...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46262 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl_xcvr: Revert fix missing lock in fsl_xcvr_mode_put() This reverts commit f51424872760 ("ASoC: fsl_xcvr: fix missing lock in fsl_xcvr_mode_put()"). The original patch attempted to acquire the card->controls_...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46261 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: spi: wpcm-fiu: Fix potential NULL pointer dereference in wpcm_fiu_probe() platform_get_resource_byname() can return NULL, which would cause a crash when passed the pointer to resource_size(). Move the fiu->memory_size assignme...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46260 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bound access in fib6_add_rt2node(). syzbot reported out-of-bound read in fib6_add_rt2node(). [0] When IPv6 route is created with RTA_NH_ID, struct fib6_info does not have the trailing struct fib6_nh. The cited c...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46259 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: procfs: fix missing RCU protection when reading real_parent in do_task_stat() When reading /proc/[pid]/stat, do_task_stat() accesses task->real_parent without proper RCU protection, which leads to: cpu 0 ...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46258 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: gpio: cdev: Avoid NULL dereference in linehandle_create() In linehandle_create(), there is a statement like this: retain_and_null_ptr(lh); Soon after, there is a debug printout that dereferences "lh", which will crash...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46257 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/timer-sp804: Fix an Oops when read_current_timer is called on ARM32 platforms where the SP804 is not registered as the sched_clock. On SP804, the delay timer shares the same clkevt instance with sched_clock. On...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46256 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: prevent direct reclaim recursion into NFS via nfs_writepages LOCALIO is an NFS loopback mount optimization that avoids using the network for READ, WRITE and COMMIT if the NFS client and server are determined to be on ...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD