Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

911
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 1,948 CVEs

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently infers zerocopy stat...

Vendor: Linux
Product: Linux
Published: May 21, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr->daddr, recompresses, then pulls the old header and pushes ...

Vendor: Linux
Product: Linux
Published: May 21, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the l...

Vendor: Linux
Product: Linux
Published: May 21, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Disallow re-exporting imported GEM objects Prevent re-exporting of imported GEM buffers by adding a custom prime_handle_to_fd callback that checks if the object is imported and returns -EOPNOTSUPP if so. Re-exporting ...

Vendor: Linux
Product: Linux
Published: May 21, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free dlfb_ops_mmap() uses remap_pfn_range() to map vmalloc framebuffer pages to userspace but sets no vm_ops on the VMA. This means the kernel cannot track active mmap...

Vendor: Linux
Product: Linux
Published: May 21, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked When red qdisc has children (eg qfq qdisc) whose peek() callback is qdisc_peek_dequeued(), we could get a kernel panic. When the parent of such qdi...

Vendor: Linux
Product: Linux
Published: May 21, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler t7xx_port_enum_msg_handler() uses the modem-supplied port_count field as a loop bound over port_msg->data[] without checking that the mes...

Vendor: Linux
Product: Linux
Published: May 21, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But we fail to pr...

Vendor: Linux
Product: Linux
Published: May 21, 2026
Source: NVD
CVE-2026-8632 HIGH - 7.8

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via operating system command injection.

Vendor: hp
Product: linux_imaging_and_printing
Published: May 20, 2026
Source: NVD
CVE-2026-8631 CRITICAL - 9.8

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.

Vendor: hp
Product: linux_imaging_and_printing
Published: May 20, 2026
Source: NVD
CVE-2026-9123 HIGH - 7.5

Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9117 HIGH - 7.5

Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9111 HIGH - 8.8

Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-24217 HIGH - 8.8

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: BioNeMo Framework
Published: May 20, 2026
Source: NVD
CVE-2026-24216 HIGH - 7.8

NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: BioNeMo Framework
Published: May 20, 2026
Source: NVD
CVE-2026-46430 MEDIUM - 4.3

Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS

Vendor: go
Product: github.com/xyproto/algernon
Published: May 20, 2026
Source: GitHub
CVE-2026-44933 HIGH - 7.8

`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed path to execute host binaries (like `/bin/bash`) with root priv...

Vendor: SUSE
Product: SUSE Linux Enterprise, openSUSE
Published: May 20, 2026
Source: NVD

Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power 64 LE, zLinux (zSeries), AIX, Solaris x64, Solaris Sparc 64 allows Privilege Escalation, Target Programs with Elevated Privileges. This issue affects Automic Au...

Published: May 19, 2026
Source: NVD
CVE-2026-43493 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them by checking for that value and filtering out EINPROGRESS notifications.

Vendor: Linux
Product: Linux
Published: May 19, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming reports an integer underflow in mpi_read_raw_from_sgl() when subtracting "lzeros" from the unsigned "nbytes". For this to happen, the sc...

Vendor: Linux
Product: Linux
Published: May 19, 2026
Source: NVD