Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Linux Kernel CRITICAL 9.1
CVE-2026-64269

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the …

Fix: 5.15.212 / 6.1.178+
Fix from $2,300 2026-07-25
Linux Kernel CRITICAL 9.8
CVE-2026-64268

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniba…

Fix: 5.10.261 / 5.15.212+
Fix from $2,300 2026-07-25
Linux Kernel MEDIUM 5.5
CVE-2026-64267

In the Linux kernel, the following vulnerability has been resolved: fuse: avoid 32-bit prune notification count wrap FUSE_NOTIFY_PRUNE validates th…

Fix: 6.18.39 / 7.1.4+
Fix from $1,600 2026-07-25
Linux Kernel MEDIUM 5.5
CVE-2026-64264

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix EFAULT clobber in fuse_uring_commit copy_from_user() returns th…

Fix: 6.18.39 / 7.1.4+
Fix from $1,600 2026-07-25
Linux Kernel MEDIUM 5.5
CVE-2026-64263

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix moving cancelled entry to ent_in_userspace list fuse_uring_canc…

Fix: 6.18.39 / 7.1.4+
Fix from $1,600 2026-07-25
Linux Kernel MEDIUM 5.5
CVE-2026-64262

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: end fuse_req on io-uring cancel task work When io_uring delivers ta…

Fix: 6.18.39 / 7.1.4+
Fix from $1,600 2026-07-25
Linux Kernel HIGH 7.8
CVE-2026-64266

In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before returning from fuse_ref_folio() fuse_ref_folio() u…

Fix: 5.10.261 / 5.15.212+
Fix from $1,950 2026-07-25
Linux Kernel HIGH 7.8
CVE-2026-64265

In the Linux kernel, the following vulnerability has been resolved: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req When fuse_res…

Fix: 6.12.96 / 6.18.39+
Fix from $1,950 2026-07-25
Linux Kernel HIGH 7.8
CVE-2026-64261

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues fuse_uring_asy…

Fix: 6.18.39 / 7.1.4+
Fix from $1,950 2026-07-25
Linux Kernel HIGH 7.8
CVE-2026-64260

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid queue->stopped races and set/read that value under lock There…

Fix: 6.18.39 / 7.1.4+
Fix from $1,950 2026-07-25
Linux Kernel HIGH 7.8
CVE-2026-64259

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: make a fuse_req on SQE commit only findable after memcpy Bad usersp…

Fix: 6.18.39 / 7.1.4+
Fix from $1,950 2026-07-25
Linux Kernel MEDIUM 5.5
CVE-2026-64258

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref …

Fix: 6.18.39 / 7.1.4+
Fix from $1,600 2026-07-25
Linux Kernel CRITICAL 9.1
CVE-2026-64257

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06…

Fix: 5.11 / 5.16+
Fix from $2,300 2026-07-25
Linux Kernel MEDIUM 5.5
CVE-2026-64256

In the Linux kernel, the following vulnerability has been resolved: xfs: don't wrap around quota ids in dqiterate LOLLM noticed that q_id is an uns…

Fix: 6.12.96 / 6.18.39+
Fix from $1,600 2026-07-25
Unclassified CRITICAL 9.8
CVE-2026-16766

Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly t…

No fix yet
Fix from $2,300 2026-07-25
Unclassified MEDIUM 6.4
CVE-2026-15425

The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug …

No fix yet
Fix from $1,600 2026-07-25
Unclassified MEDIUM 6.5
CVE-2026-14955

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7…

No fix yet
Fix from $1,600 2026-07-25
Unclassified HIGH 8.1
CVE-2026-10818

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_…

No fix yet
Fix from $1,950 2026-07-25
Unclassified HIGH 8.1
CVE-2026-66374

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

No fix yet
Fix from $1,950 2026-07-25
Unclassified HIGH 7.5
CVE-2026-66373

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where…

Patch available
Fix from $1,950 2026-07-25
Unclassified MEDIUM 6.5
CVE-2026-66339

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.4
CVE-2026-66338

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs vio…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-66337

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when …

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 8.8
CVE-2026-61892

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-61886

Weintek cMT3092X HMI stores user account passwords in plaintext.

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-60135

An attacker can modify data that should be restricted to read‑only access.

No fix yet
Fix from $1,600 2026-07-24
Ddk CRITICAL 9.8
CVE-2026-16280

An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 …

Fix: 26.1+
Fix from $2,300 2026-07-24
Unclassified HIGH 8.8
CVE-2026-60134

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

No fix yet
Fix from $1,950 2026-07-24
Unclassified CRITICAL 9.8
CVE-2026-61884

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. B…

No fix yet
Fix from $2,300 2026-07-24
Nltk HIGH 7.8
CVE-2025-71408

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker…

Fix: 3.9.3+
Fix from $1,950 2026-07-24