92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,401–3,450 of 92,816 · page 69 of 1857
| ID | Title | Summary |
|---|---|---|
| CVE-2026-92532 | CVE-2026-92532 | Unrestricted file upload vulnerability in the BugTracker.NET attachment functionality. An authenticated user with administrator privileges could modify the app… |
| CVE-2026-92531 | CVE-2026-92531 | Operating system command injection vulnerability in the SVN integration component of BugTracker.NET. The application incorporates the value of the field corres… |
| CVE-2026-92530 | CVE-2026-92530 CVSS 4.3gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain co… |
| CVE-2026-9253 | CVE-2026-9253 CVSS 7.2 | The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter … |
| CVE-2026-92529 | CVE-2026-92529 CVSS 4.3gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain condi… |
| CVE-2026-92527 | CVE-2026-92527 CVSS 6.3 | A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. T… |
| CVE-2026-92526 | CVE-2026-92526 CVSS 6.3 | A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulati… |
| CVE-2026-92525 | CVE-2026-92525 CVSS 7.1 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] For a user QP, qp->sq.q… |
| CVE-2026-92524 | CVE-2026-92524 | In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() When its_irq_gic_domain_al… |
| CVE-2026-92523 | CVE-2026-92523 | In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: validate dynamic counter attribute length RDMA_NLDEV_ATTR_STAT_HWCOUNTERS is … |
| CVE-2026-92522 | CVE-2026-92522 CVSS 7.3 | In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds The IOAPIC hotplug lookup parses both … |
| CVE-2026-92521 | CVE-2026-92521 | In the Linux kernel, the following vulnerability has been resolved: ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root acpi_pci_root_add()… |
| CVE-2026-92520 | CVE-2026-92520 | In the Linux kernel, the following vulnerability has been resolved: bpf: Zero queue and stack outputs on lock failure Queue and stack pop/peek helpers accept… |
| CVE-2026-9252 | CVE-2026-9252 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-92519 | CVE-2026-92519 | In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix memory leak in bpf_jit_free When bpf_int_jit_compile() is called for subp… |
| CVE-2026-92518 | CVE-2026-92518 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix kernel stack corruption in tailcall with CFI When CONFIG_CFI_CLANG is ena… |
| CVE-2026-92517 | CVE-2026-92517 | In the Linux kernel, the following vulnerability has been resolved: bpf, riscv: Fix extable handling for arena load_acquire emit_atomic_ld_st() returns 1 to … |
| CVE-2026-92516 | CVE-2026-92516 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix offset warn check for bpf_res_spin_lock Sashiko pointed out correctly that the c… |
| CVE-2026-92515 | CVE-2026-92515 | In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve unique-field state across nested structs btf_find_struct_field() initialize… |
| CVE-2026-92514 | CVE-2026-92514 | In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Fix CEQ tasklet use-after-free on removal Each CEQ interrupt handler only sch… |
| CVE-2026-92513 | CVE-2026-92513 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: drain QP references after partial table insertion mana_table_store_ud_qp() … |
| CVE-2026-92512 | CVE-2026-92512 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix use after free in ib_query_qp() When querying a QP via the netlink flow th… |
| CVE-2026-92511 | CVE-2026-92511 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destroy_cq_user() When accessing a CQ via t… |
| CVE-2026-92510 | CVE-2026-92510 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destroy_srq_user() When accessing a SRQ via… |
| CVE-2026-9251 | CVE-2026-9251 CVSS 5.4devolutions | Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-en… |
| CVE-2026-92509 | CVE-2026-92509 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in counter_release() When accessing a counter via… |
| CVE-2026-92508 | CVE-2026-92508 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_free_cq() When accessing a CQ via the netli… |
| CVE-2026-92507 | CVE-2026-92507 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_dealloc_pd_user() When accessing a PD via t… |
| CVE-2026-92506 | CVE-2026-92506 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix requested device removal race scmi_protocol_device_unrequest() dr… |
| CVE-2026-92505 | CVE-2026-92505 | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix undefined behavior in devid_write debugfs function When for_each_pci_segme… |
| CVE-2026-92504 | CVE-2026-92504 CVSS 7.0 | In the Linux kernel, the following vulnerability has been resolved: thermal: intel: int3400: clean up ODVP on probe failures evaluate_odvp() creates per-ODVP… |
| CVE-2026-92503 | CVE-2026-92503 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix ABBA deadlock in ext4_xattr_inode_cache_find() Syzbot/stress-ng reported an ABB… |
| CVE-2026-92502 | CVE-2026-92502 | In the Linux kernel, the following vulnerability has been resolved: ext4: clear stale xarray tags on folios skipped during writeback In data=journal mode, th… |
| CVE-2026-92501 | CVE-2026-92501 | In the Linux kernel, the following vulnerability has been resolved: ext4: drain in-flight DIO before buffered write fallback generic/746 started failing inte… |
| CVE-2026-92500 | CVE-2026-92500 | In the Linux kernel, the following vulnerability has been resolved: ext4: use fsdata to track inline data write state and fix race Instead of checking the li… |
| CVE-2026-9250 | CVE-2026-9250 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-92499 | CVE-2026-92499 | In the Linux kernel, the following vulnerability has been resolved: ext4: validate readdir offset before accessing dirent A corrupted directory can trigger t… |
| CVE-2026-92498 | CVE-2026-92498 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: avoid buffer overreads in WMI event handlers The following WMI event handle… |
| CVE-2026-92497 | CVE-2026-92497 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() Currently, in ath12k_wmi_op_rx(… |
| CVE-2026-92496 | CVE-2026-92496 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() Currently, in ath11k_wmi_tl… |
| CVE-2026-92495 | CVE-2026-92495 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap bnxt_re_mmap() rejects VM_WRITE f… |
| CVE-2026-92494 | CVE-2026-92494 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix buffer_head leak in ext4_init_orphan_info ext4_init_orphan_info() reads orphan … |
| CVE-2026-92493 | CVE-2026-92493 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active The crash issue m… |
| CVE-2026-92492 | CVE-2026-92492 | In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks cpufreq_cpu_get() retu… |
| CVE-2026-92491 | CVE-2026-92491 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Roll back partial protocol table registration scmi_protocol_table_reg… |
| CVE-2026-92490 | CVE-2026-92490 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unrequest devices if driver registration fails scmi_driver_register()… |
| CVE-2026-9249 | CVE-2026-9249 CVSS 3.1devolutions | Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password chang… |
| CVE-2026-92489 | CVE-2026-92489 CVSS 9.8 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from lo… |
| CVE-2026-92488 | CVE-2026-92488 CVSS 7.0 | In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: complete object teardown when the destroy command fails erdma_destroy_qp(), e… |
| CVE-2026-92487 | CVE-2026-92487 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix valid_size extension over a shared writable mapping When a shared writable map… |