92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,401–3,450 of 92,816 · page 69 of 1857

IDTitleSummary
CVE-2026-92532CVE-2026-92532Unrestricted file upload vulnerability in the BugTracker.NET attachment functionality. An authenticated user with administrator privileges could modify the app…
CVE-2026-92531CVE-2026-92531Operating system command injection vulnerability in the SVN integration component of BugTracker.NET. The application incorporates the value of the field corres…
CVE-2026-92530CVE-2026-92530
CVSS 4.3gitlab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain co…
CVE-2026-9253CVE-2026-9253
CVSS 7.2
The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter …
CVE-2026-92529CVE-2026-92529
CVSS 4.3gitlab
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain condi…
CVE-2026-92527CVE-2026-92527
CVSS 6.3
A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. T…
CVE-2026-92526CVE-2026-92526
CVSS 6.3
A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulati…
CVE-2026-92525CVE-2026-92525
CVSS 7.1
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] For a user QP, qp->sq.q…
CVE-2026-92524CVE-2026-92524In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() When its_irq_gic_domain_al…
CVE-2026-92523CVE-2026-92523In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: validate dynamic counter attribute length RDMA_NLDEV_ATTR_STAT_HWCOUNTERS is …
CVE-2026-92522CVE-2026-92522
CVSS 7.3
In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds The IOAPIC hotplug lookup parses both …
CVE-2026-92521CVE-2026-92521In the Linux kernel, the following vulnerability has been resolved: ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root acpi_pci_root_add()…
CVE-2026-92520CVE-2026-92520In the Linux kernel, the following vulnerability has been resolved: bpf: Zero queue and stack outputs on lock failure Queue and stack pop/peek helpers accept…
CVE-2026-9252CVE-2026-9252Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-92519CVE-2026-92519In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix memory leak in bpf_jit_free When bpf_int_jit_compile() is called for subp…
CVE-2026-92518CVE-2026-92518
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix kernel stack corruption in tailcall with CFI When CONFIG_CFI_CLANG is ena…
CVE-2026-92517CVE-2026-92517In the Linux kernel, the following vulnerability has been resolved: bpf, riscv: Fix extable handling for arena load_acquire emit_atomic_ld_st() returns 1 to …
CVE-2026-92516CVE-2026-92516In the Linux kernel, the following vulnerability has been resolved: bpf: Fix offset warn check for bpf_res_spin_lock Sashiko pointed out correctly that the c…
CVE-2026-92515CVE-2026-92515In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve unique-field state across nested structs btf_find_struct_field() initialize…
CVE-2026-92514CVE-2026-92514In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Fix CEQ tasklet use-after-free on removal Each CEQ interrupt handler only sch…
CVE-2026-92513CVE-2026-92513In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: drain QP references after partial table insertion mana_table_store_ud_qp() …
CVE-2026-92512CVE-2026-92512In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix use after free in ib_query_qp() When querying a QP via the netlink flow th…
CVE-2026-92511CVE-2026-92511
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destroy_cq_user() When accessing a CQ via t…
CVE-2026-92510CVE-2026-92510
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destroy_srq_user() When accessing a SRQ via…
CVE-2026-9251CVE-2026-9251
CVSS 5.4devolutions
Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-en…
CVE-2026-92509CVE-2026-92509In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in counter_release() When accessing a counter via…
CVE-2026-92508CVE-2026-92508
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_free_cq() When accessing a CQ via the netli…
CVE-2026-92507CVE-2026-92507
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_dealloc_pd_user() When accessing a PD via t…
CVE-2026-92506CVE-2026-92506In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix requested device removal race scmi_protocol_device_unrequest() dr…
CVE-2026-92505CVE-2026-92505In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix undefined behavior in devid_write debugfs function When for_each_pci_segme…
CVE-2026-92504CVE-2026-92504
CVSS 7.0
In the Linux kernel, the following vulnerability has been resolved: thermal: intel: int3400: clean up ODVP on probe failures evaluate_odvp() creates per-ODVP…
CVE-2026-92503CVE-2026-92503In the Linux kernel, the following vulnerability has been resolved: ext4: fix ABBA deadlock in ext4_xattr_inode_cache_find() Syzbot/stress-ng reported an ABB…
CVE-2026-92502CVE-2026-92502In the Linux kernel, the following vulnerability has been resolved: ext4: clear stale xarray tags on folios skipped during writeback In data=journal mode, th…
CVE-2026-92501CVE-2026-92501In the Linux kernel, the following vulnerability has been resolved: ext4: drain in-flight DIO before buffered write fallback generic/746 started failing inte…
CVE-2026-92500CVE-2026-92500In the Linux kernel, the following vulnerability has been resolved: ext4: use fsdata to track inline data write state and fix race Instead of checking the li…
CVE-2026-9250CVE-2026-9250Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-92499CVE-2026-92499In the Linux kernel, the following vulnerability has been resolved: ext4: validate readdir offset before accessing dirent A corrupted directory can trigger t…
CVE-2026-92498CVE-2026-92498In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: avoid buffer overreads in WMI event handlers The following WMI event handle…
CVE-2026-92497CVE-2026-92497In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() Currently, in ath12k_wmi_op_rx(…
CVE-2026-92496CVE-2026-92496In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() Currently, in ath11k_wmi_tl…
CVE-2026-92495CVE-2026-92495In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap bnxt_re_mmap() rejects VM_WRITE f…
CVE-2026-92494CVE-2026-92494In the Linux kernel, the following vulnerability has been resolved: ext4: fix buffer_head leak in ext4_init_orphan_info ext4_init_orphan_info() reads orphan …
CVE-2026-92493CVE-2026-92493In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active The crash issue m…
CVE-2026-92492CVE-2026-92492In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks cpufreq_cpu_get() retu…
CVE-2026-92491CVE-2026-92491In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Roll back partial protocol table registration scmi_protocol_table_reg…
CVE-2026-92490CVE-2026-92490In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unrequest devices if driver registration fails scmi_driver_register()…
CVE-2026-9249CVE-2026-9249
CVSS 3.1devolutions
Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password chang…
CVE-2026-92489CVE-2026-92489
CVSS 9.8
In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from lo…
CVE-2026-92488CVE-2026-92488
CVSS 7.0
In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: complete object teardown when the destroy command fails erdma_destroy_qp(), e…
CVE-2026-92487CVE-2026-92487In the Linux kernel, the following vulnerability has been resolved: exfat: fix valid_size extension over a shared writable mapping When a shared writable map…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.