92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,801–2,850 of 92,816 · page 57 of 1857
| ID | Title | Summary |
|---|---|---|
| CVE-2026-93313 | CVE-2026-93313 CVSS 6.3 | A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc… |
| CVE-2026-93312 | CVE-2026-93312 CVSS 4.3 | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes… |
| CVE-2026-93311 | CVE-2026-93311 CVSS 4.3 | A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc o… |
| CVE-2026-93310 | CVE-2026-93310 CVSS 5.3 | A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocatio… |
| CVE-2026-9331 | CVE-2026-9331 CVSS 7.1 | The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due … |
| CVE-2026-93309 | CVE-2026-93309 CVSS 4.3 | A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a… |
| CVE-2026-93308 | CVE-2026-93308 CVSS 4.3 | A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing… |
| CVE-2026-93307 | CVE-2026-93307 CVSS 4.3 | A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argumen… |
| CVE-2026-93306 | CVE-2026-93306 CVSS 7.1ibm | IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulne… |
| CVE-2026-93304 | CVE-2026-93304 CVSS 3.7wolfssl | A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the cli… |
| CVE-2026-93303 | CVE-2026-93303 CVSS 7.2 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'form_data' Rich T… |
| CVE-2026-93302 | CVE-2026-93302 CVSS 8.2wolfssl | MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEE… |
| CVE-2026-9330 | CVE-2026-9330 CVSS 8.5ibm | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign… |
| CVE-2026-93296 | CVE-2026-93296 | MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card and the server/feed preview ca… |
| CVE-2026-93295 | CVE-2026-93295 | MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed d… |
| CVE-2026-93292 | CVE-2026-93292 CVSS 8.5 | SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_nam… |
| CVE-2026-93291 | CVE-2026-93291 CVSS 9.4 | Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary co… |
| CVE-2026-93290 | CVE-2026-93290 CVSS 5.5 | Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data. |
| CVE-2026-93289 | CVE-2026-93289 CVSS 7.5 | The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing pro… |
| CVE-2026-93288 | CVE-2026-93288 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state sashiko r… |
| CVE-2026-93287 | CVE-2026-93287 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: reject oversized block transfers in the common path The SMBus block transfer … |
| CVE-2026-93286 | CVE-2026-93286 | In the Linux kernel, the following vulnerability has been resolved: net: appletalk: fix NULL pointer dereference in aarp_send_ddp() aarp_send_ddp() calls ata… |
| CVE-2026-93285 | CVE-2026-93285 | In the Linux kernel, the following vulnerability has been resolved: f2fs: embed f2fs_gc_kthread in f2fs_sb_info Instead of allocating f2fs_gc_kthread dynamic… |
| CVE-2026-93284 | CVE-2026-93284 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: dma-unmap pages before handling migration errors drm_pagemap_migrate_unmap_p… |
| CVE-2026-93283 | CVE-2026-93283 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When device_register() fails in i3c_master_… |
| CVE-2026-93282 | CVE-2026-93282 CVSS 8.1 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE match… |
| CVE-2026-93281 | CVE-2026-93281 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix HE extended capability length check rtw89_mac_check_he_obss_narrow_bw_ru… |
| CVE-2026-93280 | CVE-2026-93280 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes against the fetched size gb_audio_gb_get… |
| CVE-2026-93279 | CVE-2026-93279 | In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown The TX cleanup tasklet c… |
| CVE-2026-93278 | CVE-2026-93278 | In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown cvm_oct_rx_shutdown call… |
| CVE-2026-93277 | CVE-2026-93277 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Validate udata before executing commands The destroy callbacks currently ze… |
| CVE-2026-93276 | CVE-2026-93276 | In the Linux kernel, the following vulnerability has been resolved: phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator… |
| CVE-2026-93275 | CVE-2026-93275 | In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/pt: Fix stop/start with no update If pt_event_stop() is called without PER… |
| CVE-2026-93274 | CVE-2026-93274 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: bcm2835: Don't remove an unregistered GPIO chip If the devm_pinctrl_register() f… |
| CVE-2026-93273 | CVE-2026-93273 | In the Linux kernel, the following vulnerability has been resolved: regulator: tps6594: Fix device node reference leaks in multiphase loop In tps6594_regulat… |
| CVE-2026-93272 | CVE-2026-93272 | In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3 The changes introduc… |
| CVE-2026-93271 | CVE-2026-93271 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate ath11k can receive HT… |
| CVE-2026-93270 | CVE-2026-93270 | In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn The BPF_MOV64_PERCPU_REG insn… |
| CVE-2026-9327 | CVE-2026-9327 CVSS 6.3ibm | IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This… |
| CVE-2026-93269 | CVE-2026-93269 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix circular lock dependency in ext4_ext_migrate Move iput(tmp_inode) after ext4_wr… |
| CVE-2026-93268 | CVE-2026-93268 | In the Linux kernel, the following vulnerability has been resolved: ext4: skip extra isize expansion during mount to prevent deadlock ext4_try_to_expand_extr… |
| CVE-2026-93267 | CVE-2026-93267 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in uverbs_free_dmah() When accessing a dmah via t… |
| CVE-2026-93266 | CVE-2026-93266 | In the Linux kernel, the following vulnerability has been resolved: arm64: RSI: fix field-spanning write warning in attestation token init The challenge is p… |
| CVE-2026-93265 | CVE-2026-93265 CVSS 7.7 | In the Linux kernel, the following vulnerability has been resolved: PCI/pwrctrl: tc9563: Fix parsing the integrated Ethernet MAC Endpoint node DSP3 has an in… |
| CVE-2026-93264 | CVE-2026-93264 | In the Linux kernel, the following vulnerability has been resolved: RDMA/efa: Fix PBL chunk length computation On register MR, when creating the PBL, if it's… |
| CVE-2026-93263 | CVE-2026-93263 | In the Linux kernel, the following vulnerability has been resolved: clk: eswin: Zero-initialize stack-allocated clk_init_data eswin_clk_register_pll() and es… |
| CVE-2026-93262 | CVE-2026-93262 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: md/raid5-ppl: fix use-after-free in ppl_do_flush() The loop in ppl_do_flush() continues i… |
| CVE-2026-93261 | CVE-2026-93261 | In the Linux kernel, the following vulnerability has been resolved: locking/lockdep: Fix NULL pointer dereference in __lock_set_class() register_lock_class()… |
| CVE-2026-93260 | CVE-2026-93260 CVSS 7.4 | In the Linux kernel, the following vulnerability has been resolved: powerpc/xive: propagate IPI init errors to prevent use-after-free When xive_init_ipis() f… |
| CVE-2026-93259 | CVE-2026-93259 | In the Linux kernel, the following vulnerability has been resolved: powerpc/irq: Fix missing r2 clobber in PCREL inline assembly In CONFIG_PPC_KERNEL_PCREL m… |