Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,976
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,261 - 4,280 of 34,447 CVEs
CVE-2026-46256 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: prevent direct reclaim recursion into NFS via nfs_writepages LOCALIO is an NFS loopback mount optimization that avoids using the network for READ, WRITE and COMMIT if the NFS client and server are determined to be on ...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46255 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: don't explicitly disable clocks in .remove() The clocks in fsl_edma_engine::muxclk are allocated and enabled with devm_clk_get_enabled(), which automatically cleans these resources up, but these clocks ar...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46254 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: AppArmor: Allow apparmor to handle unaligned dfa tables The dfa tables can originate from kernel or userspace and 8-byte alignment isn't always guaranteed and as such may trigger unaligned memory accesses on various architect...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46253 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: pstore/ram: fix buffer overflow in persistent_ram_save_old() persistent_ram_save_old() can be called multiple times for the same persistent_ram_zone (e.g., via ramoops_pstore_read -> ramoops_get_next_prz for PSTORE_TYPE_DMESG r...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46252 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: regulator: core: fix locking in regulator_resolve_supply() error path If late enabling of a supply regulator fails in regulator_resolve_supply(), the code currently triggers a lockdep warning: WARNING: drivers/regulator/core....

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46251 HIGH - 8.4

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block_group_tree dirty_list corruption When the incompat flag EXTENT_TREE_V2 is set, we unconditionally add the block group tree to the switch_commits list before calling switch_commit_roots, as we do for the tree root ...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46250 HIGH - 7.3

In the Linux kernel, the following vulnerability has been resolved: MIPS: Work around LLVM bug when gp is used as global register variable On MIPS, __current_thread_info is defined as global register variable locating in $gp, and is simply assigned with new address during kernel relocation. This ...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46249 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Fix PF driver crash with kexec kernel booting During a kexec reboot the hardware is not power-cycled, so AF state from the old kernel can persist into the new kernel. When AF and PF drivers are built as modules, the ...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46248 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: clear stale link mapping of ahvif->links_map When an arvif is initialized in non-AP STA mode but MLO connection preparation fails before the arvif is created (arvif->is_created remains false), the error path at...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46247 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gfx3d: add parent to parent request map After commit d228ece36345 ("clk: divider: remove round_rate() in favor of determine_rate()") determining GFX3D clock rate crashes, because the passed parent map doesn�...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46246 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: power: supply: pm8916_lbc: Fix use-after-free for extcon in IRQ handler Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `extcon` handle, means that the `extcon` handle will ...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46245 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dc_link NULL handling in HPD init amdgpu_dm_hpd_init() may see connectors without a valid dc_link. The code already checks dc_link for the polling decision, but later unconditionally dereferences it when sett...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46244 CRITICAL - 9.1

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset traversing all extension headers, but the result is im...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-40290 HIGH - 7.8

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.16.0 and prior to 4.11.0, a user-after-free (UAF) race condition exists in the shared memory teardown logic of FF-A ...

Vendor: OP-TEE
Product: optee_os
Published: Jun 03, 2026
Source: NVD
CVE-2026-39107 MEDIUM - 6.3

A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or encode HTML/JavaScript payloads generated by the AI model. When a user switches to the 'Preview' tab to view AI-generated code, th...

Published: Jun 03, 2026
Source: NVD
CVE-2026-36618 MEDIUM - 4.3

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (unbound 1.22.0), aiding targeted attacks against known vulnerabilities.

Published: Jun 03, 2026
Source: NVD
CVE-2026-36616 MEDIUM - 5.9

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS shared secret, WPS test key, and default PSK embedded in the production firmware binary.

Published: Jun 03, 2026
Source: NVD
CVE-2026-36615 MEDIUM - 4.3

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns internal buffer contents to unauthenticated attackers on the adjacent network.

Published: Jun 03, 2026
Source: NVD
CVE-2026-36613 MEDIUM - 4.3

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents when receiving HTTP POST requests to undefined paths, exposing server state to unauthenticated adjacent network attackers.

Published: Jun 03, 2026
Source: NVD
CVE-2026-36612 MEDIUM - 6.4

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-second lockout after 10 attempts).

Published: Jun 03, 2026
Source: NVD