Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 9.8
CVE-2026-55971
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to u…
Thrift
0.24.0+
CRITICAL 9.1
CVE-2026-48144
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.…
Thrift
0.24.0+
CRITICAL 9.8
CVE-2026-64535
In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: Fix potential UAF when ddgst mismatch
Shivam Kumar found via vulnera…
No fix yet
CRITICAL 9.8
CVE-2026-64534
In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path
In nv…
No fix yet
CRITICAL 9.0
CVE-2026-14289
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection i…
No fix yet
CRITICAL 9.8
CVE-2026-13714
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload fun…
No fix yet
CRITICAL 9.1
CVE-2026-13597
The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it disc…
No fix yet
CRITICAL 9.1
CVE-2026-13332
The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user session…
No fix yet
CRITICAL 9.8
CVE-2026-12394
The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to regi…
No fix yet
CRITICAL 9.8
CVE-2026-64530
In the Linux kernel, the following vulnerability has been resolved:
net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
tcf_classify() …
Mitigation only
CRITICAL 9.3
CVE-2026-66013
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to upd…
No fix yet
CRITICAL 10.0
CVE-2026-66012
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (mo…
Patch available
CRITICAL 9.8
CVE-2026-64523
In the Linux kernel, the following vulnerability has been resolved:
net/handshake: Take a long-lived file reference at submit
handshake_nl_accept_d…
Mitigation only
CRITICAL 9.8
CVE-2026-64459
In the Linux kernel, the following vulnerability has been resolved:
tcp: restore RCU grace period in tcp_ao_destroy_sock
Commit 51e547e8c89c ("tcp:…
No fix yet
CRITICAL 9.1
CVE-2026-64450
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix out-of-bounds read in broadcast Gap ACK blocks
A broadcast PROTOCOL/S…
No fix yet
CRITICAL 9.8
CVE-2026-64439
In the Linux kernel, the following vulnerability has been resolved:
crypto: krb5 - filter out async aead implementations at alloc
krb5_aead_encrypt…
No fix yet
CRITICAL 9.8
CVE-2026-64410
In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: IPIP tunnel hardware offload is not yet support
No driver…
Mitigation only
CRITICAL 9.8
CVE-2026-64399
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
The FSCTL_DUPL…
No fix yet
CRITICAL 9.8
CVE-2026-64397
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: serialize QUERY_DIRECTORY requests per file
smb2_query_dir() stores a po…
No fix yet
CRITICAL 9.1
CVE-2026-64393
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: run set info with opener credentials
SMB2 SET_INFO handlers call path-ba…
No fix yet
CRITICAL 9.1
CVE-2026-64392
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: use opener credentials for delete-on-close
Delete-on-close can be comple…
No fix yet
CRITICAL 9.8
CVE-2026-64391
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: use opener credentials for ADS I/O
Alternate data streams are stored as …
No fix yet
CRITICAL 9.8
CVE-2026-64387
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix query directory replay double-free
A response-bearing attempt …
No fix yet
CRITICAL 9.8
CVE-2026-64386
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix query_info() replay double-free
A response-bearing attempt can…
Mitigation only
CRITICAL 9.8
CVE-2026-64385
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_ioctl() replay
A response-bearing attempt …
No fix yet
CRITICAL 9.8
CVE-2026-64384
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix change notify replay double-free
A response-bearing attempt ca…
No fix yet
CRITICAL 9.8
CVE-2026-64383
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_flush() replay
SMB2_flush() keeps its resp…
No fix yet
CRITICAL 9.8
CVE-2026-64355
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject fragmented frames in devmap
Devmap broadcast redirects clone the pa…
No fix yet
CRITICAL 9.1
CVE-2026-64320
In the Linux kernel, the following vulnerability has been resolved:
nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
nvmet_exe…
No fix yet
CRITICAL 9.1
CVE-2026-64319
In the Linux kernel, the following vulnerability has been resolved:
nvmet-auth: validate reply message payload bounds against transfer length
nvmet…
No fix yet