86,884 indexed
CVECVE vulnerabilities
86,884 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 201–250 of 86,884 · page 5 of 1738
| ID | Title | Summary |
|---|---|---|
| CVE-2026-98123 | CVE-2026-98123 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration sctp_verify_asconf() w… |
| CVE-2026-98122 | CVE-2026-98122 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() vxlan_mdb_is_valid_source(),… |
| CVE-2026-98121 | CVE-2026-98121 | In the Linux kernel, the following vulnerability has been resolved: watchdog: msc313e: Fix NULL pointer dereference in PM callbacks msc313e_wdt_probe() doesn… |
| CVE-2026-98120 | CVE-2026-98120 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix subreq ref leak Fix a subrequest ref leak in netfs_unbuffered_write() in the e… |
| CVE-2026-9812 | CVE-2026-9812 CVSS 6.5 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified r… |
| CVE-2026-98119 | CVE-2026-98119 | In the Linux kernel, the following vulnerability has been resolved: netfs: break unbuffered write when netfs_alloc_subrequest() fails syzbot reported a null-… |
| CVE-2026-98118 | CVE-2026-98118 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix readahead synchronisation issues by loading all folios upfront There are some … |
| CVE-2026-98117 | CVE-2026-98117 | In the Linux kernel, the following vulnerability has been resolved: cachefiles: Fix potential UAF/KASAN warning Currently, trace_cachefiles_coherency() is be… |
| CVE-2026-98116 | CVE-2026-98116 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF snd_pcm_hw_params(… |
| CVE-2026-98115 | CVE-2026-98115 CVSS 8.8linux | In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely drain sessions during logoff SMB3 multichannel allows requests for one sess… |
| CVE-2026-98114 | CVE-2026-98114 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: propagate DACL parsing errors parse_dacl() silently accepts truncated ACEs and all… |
| CVE-2026-98113 | CVE-2026-98113 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: rate limit unmapped SID errors A client can include many structurally valid but un… |
| CVE-2026-98112 | CVE-2026-98112 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix listener task lifetime on netdev events The listener thread exits when its lis… |
| CVE-2026-98111 | CVE-2026-98111 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: validate version TLV value lengths btintel_parse_version_tlv() verifi… |
| CVE-2026-98110 | CVE-2026-98110 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: bound firmware ID by TLV length The firmware ID is treated as a NUL-t… |
| CVE-2026-9811 | CVE-2026-9811 CVSS 5.4 | A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects… |
| CVE-2026-98109 | CVE-2026-98109 CVSS 4.7linux | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix race condition during device registration In hci_register_dev(),… |
| CVE-2026-98108 | CVE-2026-98108 CVSS 7.5 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan l2cap_new_connection(… |
| CVE-2026-98107 | CVE-2026-98107 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect l2cap_chan_connect() tri… |
| CVE-2026-98106 | CVE-2026-98106 | In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: Prevent double migration of device pages A device-private folio migrated to … |
| CVE-2026-98105 | CVE-2026-98105 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: oa_tc6: Improve the error recovery When oversubscribed traffic causes lot … |
| CVE-2026-98104 | CVE-2026-98104 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted gen_new_kid() fal… |
| CVE-2026-98103 | CVE-2026-98103 | In the Linux kernel, the following vulnerability has been resolved: igmp: convert struct ip_sf_list to RCU Commit 23d2b94043ca ("igmp: Add ip_mc_list lock in… |
| CVE-2026-98102 | CVE-2026-98102 | In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src() When removing a source filter wh… |
| CVE-2026-98101 | CVE-2026-98101 | In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source() pmc->sflist is read lockles… |
| CVE-2026-9810 | CVE-2026-9810 CVSS 9.8 | The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, a… |
| CVE-2026-98099 | CVE-2026-98099 | In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: use rcu_assign_pointer() for __rcu list updates Several places in net/ipv6/m… |
| CVE-2026-98098 | CVE-2026-98098 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix NULL deref in tipc_named_node_up() on empty publication list User-space applica… |
| CVE-2026-98097 | CVE-2026-98097 | In the Linux kernel, the following vulnerability has been resolved: tipc: Dont send random pad bytes in RESET/ACTIVATE messages The interface name is passed … |
| CVE-2026-98096 | CVE-2026-98096 CVSS 7.4 | In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: restore network header before routing and forwarding ipv6_srh_rcv() runs with s… |
| CVE-2026-98095 | CVE-2026-98095 | In the Linux kernel, the following vulnerability has been resolved: af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header(). syzbot reporte… |
| CVE-2026-98094 | CVE-2026-98094 | In the Linux kernel, the following vulnerability has been resolved: staging: fbtft: make dirty_lock IRQ-safe fbtft_mkdirty() can be reached from the fbcon re… |
| CVE-2026-98093 | CVE-2026-98093 | In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl_micfil: balance mclk enable/disable hw_params() enables mclk unconditionally an… |
| CVE-2026-98092 | CVE-2026-98092 | In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() acp6x_pdm_dma_close() does not fr… |
| CVE-2026-98091 | CVE-2026-98091 | In the Linux kernel, the following vulnerability has been resolved: btrfs: detach failed sprout device from transaction update list When creating the first m… |
| CVE-2026-98090 | CVE-2026-98090 | In the Linux kernel, the following vulnerability has been resolved: btrfs: restore active device pointers after failed sprout btrfs_init_new_device() switche… |
| CVE-2026-9809 | CVE-2026-9809 CVSS 7.6 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative det… |
| CVE-2026-98089 | CVE-2026-98089 | In the Linux kernel, the following vulnerability has been resolved: bonding: alb: fix uninitialized transport header access in alb_determine_nd() alb_determi… |
| CVE-2026-98088 | CVE-2026-98088 | In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() … |
| CVE-2026-98087 | CVE-2026-98087 | In the Linux kernel, the following vulnerability has been resolved: sched/rt,dl: Skip migrate-disabled tasks when picking a push candidate A migrate_disable(… |
| CVE-2026-98086 | CVE-2026-98086 | In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: do not touch legacy_rmidi before it exists snd_ump_parse_endpoint() sets ump->… |
| CVE-2026-98085 | CVE-2026-98085 | In the Linux kernel, the following vulnerability has been resolved: bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge Nicholas Carlini reported a … |
| CVE-2026-98084 | CVE-2026-98084 | In the Linux kernel, the following vulnerability has been resolved: bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks When processing calls t… |
| CVE-2026-98083 | CVE-2026-98083 CVSS 7.0 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix transaction use-after-free in raid stripe insertion If allocation of a RAID st… |
| CVE-2026-98082 | CVE-2026-98082 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix the possible bioc_list memory leak during error There are two possible ways to… |
| CVE-2026-98081 | CVE-2026-98081 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: finish active block group cleanup if call_zone_finish() fails do_zone_finis… |
| CVE-2026-98080 | CVE-2026-98080 | In the Linux kernel, the following vulnerability has been resolved: btrfs: do not force reloc root creation during qgroup_account_snapshot() [BUG] When runni… |
| CVE-2026-9808 | CVE-2026-9808 CVSS 7.1 | An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-s… |
| CVE-2026-98079 | CVE-2026-98079 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zstd: fix lost wakeup when waiting for a workspace A writer can sleep forever in z… |
| CVE-2026-98078 | CVE-2026-98078 | In the Linux kernel, the following vulnerability has been resolved: ipvs: fix reversed sequence option serialization hton_seq() expects the host-order source… |