Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-72186 In the Linux kernel, the following vulnerability has been resolved: ntfs: make system files immutable to prevent corruption When a system file such… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72185 In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() When ntfs… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72139 In the Linux kernel, the following vulnerability has been resolved: tcp: defer md5sig_info kfree past RCU grace period in tcp_connect The md5+ao re… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72137 In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_keepalive: avoid double free on send error nat_keepalive_send() frees… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72130 In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject short AUTH_RECEIVE buffers nvmet_execute_auth_receive() trus… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72129 In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data with a nonzero offset nvmet_rdma_use_inline_sg()… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72098 In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation There's a buffer overflow in … No fix yet Fix from $5,7502026-08-15 CRITICAL 9.3 CVE-2026-72085 In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free unsubmitted command instead of double-putting it scsi… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72084 In the Linux kernel, the following vulnerability has been resolved: scsi: target: Bound PR-OUT TransportID parsing to the received buffer core_scsi… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72083 In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE core_scs… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72069 In the Linux kernel, the following vulnerability has been resolved: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() rt_spin_unlock… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72065 In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by the NIC Validate the packet l… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72064 In the Linux kernel, the following vulnerability has been resolved: net: mana: Sync page pool RX frags for CPU MANA allocates RX buffers from page … No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72046 In the Linux kernel, the following vulnerability has been resolved: gve: fix header buffer corruption with header-split and HW-GRO The DQO RX datap… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72041 In the Linux kernel, the following vulnerability has been resolved: espintcp: use sk_msg_free_partial to fix partial send sk_msg_free_partial() ens… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72033 In the Linux kernel, the following vulnerability has been resolved: orangefs: keep the readdir entry size 64-bit in fill_from_part() fill_from_part… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72020 In the Linux kernel, the following vulnerability has been resolved: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new Commit 9a05475cebdd ("ipvs… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-72014 In the Linux kernel, the following vulnerability has been resolved: drbd: reject data replies with an out-of-range payload size recv_dless_read() r… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-68477 In the Linux kernel, the following vulnerability has been resolved: ipvs: fix more places with wrong ipv6 transport offsets Sashiko reports for mor… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-68476 In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after head reallocation __ip_vs_get_out_rt() calls skb_e… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.1 CVE-2026-68457 In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for FSCTL mutations SET_SPARSE, SET_ZERO_DATA and… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-15341 The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and incl… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-15303 The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_sto… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.1 CVE-2026-14484 The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pat… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.2 CVE-2026-67365 Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (… No fix yet Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-17186 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special eleme… Db2 Mirror For I after 7.6 Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-17184 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path. Db2 Mirror For I after 7.6 Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-17182 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improp… Db2 Mirror For I after 7.6 Fix from $5,7502026-08-14 CRITICAL 10.0 CVE-2026-73678 MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attacke… No fix yet Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-50027 mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are… No fix yet Fix from $5,7502026-08-14