92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,801–2,850 of 92,816 · page 57 of 1857

IDTitleSummary
CVE-2026-93313CVE-2026-93313
CVSS 6.3
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc…
CVE-2026-93312CVE-2026-93312
CVSS 4.3
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes…
CVE-2026-93311CVE-2026-93311
CVSS 4.3
A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc o…
CVE-2026-93310CVE-2026-93310
CVSS 5.3
A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocatio…
CVE-2026-9331CVE-2026-9331
CVSS 7.1
The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due …
CVE-2026-93309CVE-2026-93309
CVSS 4.3
A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a…
CVE-2026-93308CVE-2026-93308
CVSS 4.3
A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing…
CVE-2026-93307CVE-2026-93307
CVSS 4.3
A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argumen…
CVE-2026-93306CVE-2026-93306
CVSS 7.1ibm
IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulne…
CVE-2026-93304CVE-2026-93304
CVSS 3.7wolfssl
A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the cli…
CVE-2026-93303CVE-2026-93303
CVSS 7.2
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'form_data' Rich T…
CVE-2026-93302CVE-2026-93302
CVSS 8.2wolfssl
MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEE…
CVE-2026-9330CVE-2026-9330
CVSS 8.5ibm
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign…
CVE-2026-93296CVE-2026-93296MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card and the server/feed preview ca…
CVE-2026-93295CVE-2026-93295MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed d…
CVE-2026-93292CVE-2026-93292
CVSS 8.5
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_nam…
CVE-2026-93291CVE-2026-93291
CVSS 9.4
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary co…
CVE-2026-93290CVE-2026-93290
CVSS 5.5
Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.
CVE-2026-93289CVE-2026-93289
CVSS 7.5
The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing pro…
CVE-2026-93288CVE-2026-93288
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state sashiko r…
CVE-2026-93287CVE-2026-93287
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: reject oversized block transfers in the common path The SMBus block transfer …
CVE-2026-93286CVE-2026-93286In the Linux kernel, the following vulnerability has been resolved: net: appletalk: fix NULL pointer dereference in aarp_send_ddp() aarp_send_ddp() calls ata…
CVE-2026-93285CVE-2026-93285In the Linux kernel, the following vulnerability has been resolved: f2fs: embed f2fs_gc_kthread in f2fs_sb_info Instead of allocating f2fs_gc_kthread dynamic…
CVE-2026-93284CVE-2026-93284
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: dma-unmap pages before handling migration errors drm_pagemap_migrate_unmap_p…
CVE-2026-93283CVE-2026-93283In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When device_register() fails in i3c_master_…
CVE-2026-93282CVE-2026-93282
CVSS 8.1
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE match…
CVE-2026-93281CVE-2026-93281In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix HE extended capability length check rtw89_mac_check_he_obss_narrow_bw_ru…
CVE-2026-93280CVE-2026-93280
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes against the fetched size gb_audio_gb_get…
CVE-2026-93279CVE-2026-93279In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown The TX cleanup tasklet c…
CVE-2026-93278CVE-2026-93278In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown cvm_oct_rx_shutdown call…
CVE-2026-93277CVE-2026-93277
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Validate udata before executing commands The destroy callbacks currently ze…
CVE-2026-93276CVE-2026-93276In the Linux kernel, the following vulnerability has been resolved: phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator…
CVE-2026-93275CVE-2026-93275In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/pt: Fix stop/start with no update If pt_event_stop() is called without PER…
CVE-2026-93274CVE-2026-93274In the Linux kernel, the following vulnerability has been resolved: pinctrl: bcm2835: Don't remove an unregistered GPIO chip If the devm_pinctrl_register() f…
CVE-2026-93273CVE-2026-93273In the Linux kernel, the following vulnerability has been resolved: regulator: tps6594: Fix device node reference leaks in multiphase loop In tps6594_regulat…
CVE-2026-93272CVE-2026-93272In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3 The changes introduc…
CVE-2026-93271CVE-2026-93271In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate ath11k can receive HT…
CVE-2026-93270CVE-2026-93270In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn The BPF_MOV64_PERCPU_REG insn…
CVE-2026-9327CVE-2026-9327
CVSS 6.3ibm
IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This…
CVE-2026-93269CVE-2026-93269In the Linux kernel, the following vulnerability has been resolved: ext4: fix circular lock dependency in ext4_ext_migrate Move iput(tmp_inode) after ext4_wr…
CVE-2026-93268CVE-2026-93268In the Linux kernel, the following vulnerability has been resolved: ext4: skip extra isize expansion during mount to prevent deadlock ext4_try_to_expand_extr…
CVE-2026-93267CVE-2026-93267In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in uverbs_free_dmah() When accessing a dmah via t…
CVE-2026-93266CVE-2026-93266In the Linux kernel, the following vulnerability has been resolved: arm64: RSI: fix field-spanning write warning in attestation token init The challenge is p…
CVE-2026-93265CVE-2026-93265
CVSS 7.7
In the Linux kernel, the following vulnerability has been resolved: PCI/pwrctrl: tc9563: Fix parsing the integrated Ethernet MAC Endpoint node DSP3 has an in…
CVE-2026-93264CVE-2026-93264In the Linux kernel, the following vulnerability has been resolved: RDMA/efa: Fix PBL chunk length computation On register MR, when creating the PBL, if it's…
CVE-2026-93263CVE-2026-93263In the Linux kernel, the following vulnerability has been resolved: clk: eswin: Zero-initialize stack-allocated clk_init_data eswin_clk_register_pll() and es…
CVE-2026-93262CVE-2026-93262
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: md/raid5-ppl: fix use-after-free in ppl_do_flush() The loop in ppl_do_flush() continues i…
CVE-2026-93261CVE-2026-93261In the Linux kernel, the following vulnerability has been resolved: locking/lockdep: Fix NULL pointer dereference in __lock_set_class() register_lock_class()…
CVE-2026-93260CVE-2026-93260
CVSS 7.4
In the Linux kernel, the following vulnerability has been resolved: powerpc/xive: propagate IPI init errors to prevent use-after-free When xive_init_ipis() f…
CVE-2026-93259CVE-2026-93259In the Linux kernel, the following vulnerability has been resolved: powerpc/irq: Fix missing r2 clobber in PCREL inline assembly In CONFIG_PPC_KERNEL_PCREL m…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.