Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

757
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,141 - 1,160 of 27,228 CVEs
CVE-2026-41702 HIGH - 7.8

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installe...

Vendor: VMware
Product: Fusion
Published: May 15, 2026
Source: NVD
CVE-2026-43490 HIGH - 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inherit_dacl() walks the parent directory DACL loaded from the security descriptor xattr. It verifies that each ACE contains the fixed SID header before using it, but does not verify th...

Vendor: Linux
Product: Linux
Published: May 15, 2026
Source: NVD
CVE-2026-28761 HIGH - 8.1

Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected product, unexpected operations may be done.

Vendor: Fujitsu Japan Limited
Product: Musetheque V4 Information Disclosure for IPKNOWLEDGE
Published: May 15, 2026
Source: NVD
CVE-2026-24662 MEDIUM - 5.4

Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script may be executed on a user's web browser when viewing the administration page showing the informa...

Vendor: Fujitsu Japan Limited
Product: Musetheque V4 Information Disclosure for IPKNOWLEDGE
Published: May 15, 2026
Source: NVD

Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability

Published: May 15, 2026
Source: NVD

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

Published: May 15, 2026
Source: NVD

A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the global variable amdgv_cmd in an unlocked ioctl handler could be exploited by an attacker to trigger a heap-based buffer overflow, potentially resulting in denial-of-service within the v...

Vendor: AMD
Product: AMD Radeon™ PRO V620, AMD Radeon™ PRO V710, AMD Instinct™ MI250, AMD Instinct™ MI308X, AMD Instinct™ MI300A, AMD Instinct™ MI300X, AMD Instinct™ MI325X, AMD Instinct™ MI210
Published: May 15, 2026
Source: NVD

Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the installation directory to be run with elevated privileges potentially leading to arbitrary code execution.

Vendor: AMD
Product: AMD Radeon™ RX 7000 Series Graphics Products
Published: May 15, 2026
Source: NVD
CVE-2024-36333 HIGH - 7.8

A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

Vendor: amd
Product: radeon_software
Published: May 15, 2026
Source: NVD

Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perform unauthorized access to the register space of the JPEG cores assigned a victim VM/process, potentially gaining arbitrary read/write access to the victim VM/process data.

Vendor: AMD
Product: AMD Radeon™ RX 7000 Series Graphics Products, AMD Radeon™ PRO W7000 Series Graphics Products, AMD Instinct™ MI308X, AMD Instinct™ MI325X, AMD Instinct™ MI300X, AMD Instinct™ MI300A
Published: May 15, 2026
Source: NVD

An out of bounds read in the remote management firmware could allow a privileged attacker read a limited section of memory outside of established bounds potentially resulting in loss of confidentiality or availability.

Vendor: AMD
Product: AMD Instinct™ MI300X, AMD Instinct™ MI300A, AMD Instinct™ MI325X, AMD Instinct™ MI308X
Published: May 15, 2026
Source: NVD

Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When started the metasploitPostgreSQL service would start the postgres.exe child process which would in turn load an OpenSSL configuration file from a static ...

Published: May 15, 2026
Source: NVD
CVE-2026-2652 HIGH - 8.6

A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI permission middleware only enforces authentication on `/gate...

Vendor: lfprojects
Product: mlflow
Published: May 15, 2026
Source: NVD

Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_COPY_VF_CHIPLET_REGS to write invalid data to a remote Die, potentially resulting in unexpected behavior.

Published: May 15, 2026
Source: NVD

Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) to access these shared resources from another Guest VM, potentially resulting in the loss of confidentiality, integrity, or availability.

Published: May 15, 2026
Source: NVD

Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FW SR-IOV command to cause out-of-bounds read, potentially resulting in SOC Driver memory contents exposure or an exception

Published: May 15, 2026
Source: NVD

Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_CHECK_TA_COMPAT to cause incorrect shared memory mapping, potentially resulting in unexpected behavior.

Published: May 15, 2026
Source: NVD

Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via remote code execution.

Vendor: AMD
Product: AMD Instinct™ MI250, AMD Instinct™ MI308X, AMD Instinct™ MI300A, AMD Instinct™ MI300X, AMD Instinct™ MI325X, AMD Instinct™ MI210, AMD Radeon™ PRO V620, AMD Radeon™ PRO V710
Published: May 15, 2026
Source: NVD

Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an input value to a function without sufficient privileges and successfully write data, potentially resulting in loss of integrity of availability.

Vendor: AMD
Product: MI-25, AMD Instinct™ MI250, AMD Instinct™ MI210, AMD Radeon™ PRO V520, AMD Radeon™ PRO V620
Published: May 15, 2026
Source: NVD

Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege to abuse the unprotected PMIC interface to create a permanent denial of service condition or affect the integrity of the memory module.

Published: May 15, 2026
Source: NVD