Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-55971 Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to u… Thrift 0.24.0+ Fix from $2,3002026-07-27 CRITICAL 9.1 CVE-2026-48144 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.… Thrift 0.24.0+ Fix from $2,3002026-07-27 CRITICAL 9.8 CVE-2026-64535 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnera… No fix yet Fix from $2,3002026-07-27 CRITICAL 9.8 CVE-2026-64534 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nv… No fix yet Fix from $2,3002026-07-27 CRITICAL 9.0 CVE-2026-14289 The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection i… No fix yet Fix from $2,3002026-07-27 CRITICAL 9.8 CVE-2026-13714 The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload fun… No fix yet Fix from $2,3002026-07-27 CRITICAL 9.1 CVE-2026-13597 The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it disc… No fix yet Fix from $2,3002026-07-27 CRITICAL 9.1 CVE-2026-13332 The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user session… No fix yet Fix from $2,3002026-07-27 CRITICAL 9.8 CVE-2026-12394 The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to regi… No fix yet Fix from $2,3002026-07-27 CRITICAL 9.8 CVE-2026-64530 In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() … Mitigation only Fix from $2,3002026-07-26 CRITICAL 9.3 CVE-2026-66013 OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to upd… No fix yet Fix from $2,3002026-07-25 CRITICAL 10.0 CVE-2026-66012 SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (mo… Patch available Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64523 In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-lived file reference at submit handshake_nl_accept_d… Mitigation only Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64459 In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grace period in tcp_ao_destroy_sock Commit 51e547e8c89c ("tcp:… No fix yet Fix from $2,3002026-07-25 CRITICAL 9.1 CVE-2026-64450 In the Linux kernel, the following vulnerability has been resolved: tipc: fix out-of-bounds read in broadcast Gap ACK blocks A broadcast PROTOCOL/S… No fix yet Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64439 In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - filter out async aead implementations at alloc krb5_aead_encrypt… No fix yet Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64410 In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: IPIP tunnel hardware offload is not yet support No driver… Mitigation only Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64399 In the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE The FSCTL_DUPL… No fix yet Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64397 In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a po… No fix yet Fix from $2,3002026-07-25 CRITICAL 9.1 CVE-2026-64393 In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SMB2 SET_INFO handlers call path-ba… No fix yet Fix from $2,3002026-07-25 CRITICAL 9.1 CVE-2026-64392 In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-close Delete-on-close can be comple… No fix yet Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64391 In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as … No fix yet Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64387 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free A response-bearing attempt … No fix yet Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64386 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A response-bearing attempt can… Mitigation only Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64385 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt … No fix yet Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64384 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt ca… No fix yet Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64383 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its resp… No fix yet Fix from $2,3002026-07-25 CRITICAL 9.8 CVE-2026-64355 In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the pa… No fix yet Fix from $2,3002026-07-25 CRITICAL 9.1 CVE-2026-64320 In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_exe… No fix yet Fix from $2,3002026-07-25 CRITICAL 9.1 CVE-2026-64319 In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet… No fix yet Fix from $2,3002026-07-25