Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-68154 In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode CRUSH bucket type 0 is reserv… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68144 In the Linux kernel, the following vulnerability has been resolved: phonet: pep: fix use-after-free in pep_get_sb() pep_get_sb() doesn't consider t… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68137 In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free in x25_kill_by_neigh() x25_kill_by_neigh() walks th… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68136 In the Linux kernel, the following vulnerability has been resolved: net: gro: fix double aggregation of flush-marked skbs Commit 0ab03f353d36 ("net… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68127 In the Linux kernel, the following vulnerability has been resolved: ila: reload IPv6 header after pskb_may_pull in checksum adjust ila_csum_adjust_… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.6 CVE-2026-68124 In the Linux kernel, the following vulnerability has been resolved: mctp: serial: handle zero-length frames to prevent rx buffer overflow The MCTP … No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68123 In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix GSO userspace truncation underflow OVS_ACTION_ATTR_TRUNC curre… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68117 In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() When tipc_sk… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-59090 A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user … Enterprise Linux No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-13206 Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command … No fix yet Fix from $2,3002026-08-10 CRITICAL 9.1 CVE-2026-68083 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_create The SMB2 open lookup i… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-72593 A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager func… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-72592 An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on … No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-72590 An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-72589 An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system … No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-72580 An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute arbitrary system commands on X… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-72577 Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground … No fix yet Fix from $2,3002026-08-10 CRITICAL 9.1 CVE-2026-72575 An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, create, update, and delete usergr… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.1 CVE-2026-72569 A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-72567 An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or … No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-72565 A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read ar… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.6 CVE-2026-72564 An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in … No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-55799 Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fi… Ranger 2.9.0+ Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-44416 Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgra… Ranger 2.9.0+ Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-42537 Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. Ranger 2.9.0+ Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-40920 Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe… Ranger 2.9.0+ Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-32227 SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the… Ranger 2.9.0+ Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-28672 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger… Ranger after 2.8.0 Fix from $2,3002026-08-10 CRITICAL 10.0 CVE-2026-66915 Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the aja… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-19089 The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left … No fix yet Fix from $2,3002026-08-10