Total CVEs

125,862

Critical Severity

2,275

High Severity

7,879

Last 7 Days

1,167
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 441 - 460 of 1,284 CVEs

In the Linux kernel, the following vulnerability has been resolved: apparmor: replace recursive profile removal with iterative approach The profile removal code uses recursion when removing nested profiles, which can lead to kernel stack exhaustion and system crashes. Reproducer: $ pf='a&#...

Vendor: Linux
Product: Linux
Published: Apr 01, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix memory leak in verify_header The function sets `*ns = NULL` on every call, leaking the namespace string allocated in previous iterations when multiple profiles are unpacked. This also breaks namespace consistency che...

Vendor: Linux
Product: Linux
Published: Apr 01, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Only WARN in direct MMUs when overwriting shadow-present SPTE Adjust KVM's sanity check against overwriting a shadow-present SPTE with a another SPTE with a different target PFN to only apply to direct MMUs, i.e...

Vendor: Linux
Product: Linux
Published: Apr 01, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE When installing an emulated MMIO SPTE, do so *after* dropping/zapping the existing SPTE (if it's shadow-present). While commit a54aa15c6bda3 was ri...

Vendor: Linux
Product: Linux
Published: Apr 01, 2026
Source: NVD
CVE-2026-24154 HIGH - 7.6

NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, data tampering, and information dis...

Vendor: NVIDIA
Product: Jetson Xavier Series, Jetson Orin Series and Jetson Thor
Published: Mar 31, 2026
Source: NVD
CVE-2026-24153 MEDIUM - 5.2

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.

Vendor: NVIDIA
Product: Jetson Xavier Series, Jetson Orin Series and Jetson Thor
Published: Mar 31, 2026
Source: NVD
CVE-2026-34155 MEDIUM - 5.3

RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size of 2 GiB cause an integer overflow which results in a signature which covers only the first few bytes of the payload. Given such a bundle with...

Vendor: rauc
Product: rauc
Published: Mar 31, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: rust_binder: call set_notification_done() without proc lock Consider the following sequence of events on a death listener: 1. The remote process dies and sends a BR_DEAD_BINDER message. 2. The local process invokes the BC_CLEAR_DE...

Vendor: Linux
Product: Linux
Published: Mar 29, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: nf_tables: nft_dynset: fix possible stateful expression memleak in error path If cloning the second stateful expression in the element via GFP_ATOMIC fails, then the first stateful expression remains in place without being release...

Vendor: Linux
Product: Linux
Published: Mar 28, 2026
Source: NVD
CVE-2026-34205 CRITICAL - 9.6

Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuration...

Vendor: home-assistant
Product: Home Assistant Operating System, Home Assistant Supervisor
Published: Mar 27, 2026
Source: NVD

Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hosts when an uninstall is triggered for a craft...

Vendor: fleetdm
Product: fleet
Published: Mar 27, 2026
Source: NVD

Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Extensions on Windows, Linux, 64 bit allows authenticated local users to obtain sensitive information via access to log files. This issue affects IDM SCIM Driver: 1.0.0.0000 through 1....

Vendor: OpenText
Product: IDM Driver and Extensions
Published: Mar 27, 2026
Source: NVD

Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's session data via insecure application cache handling. This issue affects Identity Manager: 25.2(v4.10.1).

Vendor: OpenText
Product: Identity Manager
Published: Mar 27, 2026
Source: NVD
CVE-2026-33711 MEDIUM - 7.8

Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As versions prior to 6.23.0 use predictable pa...

Vendor: lxc
Product: incus
Published: Mar 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: icmp: fix NULL pointer dereference in icmp_tag_validation() icmp_tag_validation() unconditionally dereferences the result of rcu_dereference(inet_protos[proto]) without checking for NULL. The inet_protos[] array is sparse -- only ...

Vendor: Linux
Product: Linux
Published: Mar 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths in fingerprints nfnl_osf_add_callback() validates opt_num bounds and string NUL-termination but does not check individual option length fields. A zero-length option causes nf_osf_m...

Vendor: Linux
Product: Linux
Published: Mar 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL deref in mesh_matches_local() mesh_matches_local() unconditionally dereferences ie->mesh_config to compare mesh configuration parameters. When called from mesh_rx_csa_frame(), the parsed action-frame el...

Vendor: Linux
Product: Linux
Published: Mar 26, 2026
Source: NVD
CVE-2026-30976 HIGH - 8.6

Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file readable by the Sonarr process. These include application configuration files (containing API keys and database credentials), Windows ...

Vendor: Sonarr
Product: Sonarr
Published: Mar 25, 2026
Source: NVD

cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allows local users to trigger use-after-free conditions. Attackers with access to the /dev/crypto interface can repeatedly decrement reference counts of con...

Vendor: cryptodev-linux
Product: cryptodev-linux
Published: Mar 25, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU The Xen privcmd driver allows to issue arbitrary hypercalls from user space processes. This is normally no problem, as access is usually limited to root and the hypervisor will deny...

Vendor: Linux
Product: Linux
Published: Mar 25, 2026
Source: NVD