Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-68120 In the Linux kernel, the following vulnerability has been resolved: rtase: Workaround for TX hang caused by hardware packet parsing The hardware pe… No fix yet Fix from $1,9502026-08-10 HIGH 7.5 CVE-2026-68119 In the Linux kernel, the following vulnerability has been resolved: tcp: initialize standalone TCP-AO response padding tcp_v4_send_ack() and tcp_v6… No fix yet Fix from $1,9502026-08-10 HIGH 8.2 CVE-2026-68118 In the Linux kernel, the following vulnerability has been resolved: tcp: challenge ACK for non-exact RST in SYN-RECEIVED The SYN-RECEIVED request-s… No fix yet Fix from $1,9502026-08-10 CRITICAL 9.8 CVE-2026-68117 In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() When tipc_sk… No fix yet Fix from $2,3002026-08-10 HIGH 7.9 CVE-2026-68116 In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix source list corruption on a failed replace When replacing the s… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-68108 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image size Fix a security vulnerability… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-68107 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param length Reuse the parameter length ret… No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-68106 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix division by zero with invalid uvd dimensions When width or heig… No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-68104 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: invoke pm_genpd_remove() before freeing genpd Call pm_genpd_remove(… No fix yet Fix from $1,9502026-08-10 HIGH 7.1 CVE-2026-68103 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject mapping a reserved doorbell to a new queue When creating an … No fix yet Fix from $1,9502026-08-10 HIGH 8.1 CVE-2026-68100 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl set_ntacl_dacl()… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-68098 In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound DACL dedup walk to copied ACEs set_ntacl_dacl() can stop copying A… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-68097 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ACE size against SID sub-authorities set_ntacl_dacl() validates… No fix yet Fix from $1,9502026-08-10 HIGH 7.5 CVE-2026-68096 In the Linux kernel, the following vulnerability has been resolved: audit: fix recursive locking deadlock in audit_dupe_exe() A deadlock occurs in … No fix yet Fix from $1,9502026-08-10 HIGH 8.7 CVE-2026-59233 Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role… Patch available Fix from $1,9502026-08-10 CRITICAL 9.9 CVE-2026-59090 A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user … Enterprise Linux No fix yet Fix from $2,3002026-08-10 HIGH 8.8 CVE-2026-19429 Jenkins FilePath.untarFrom() does not validate symlink targets in extracted TAR archives, even in versions patched for CVE-2026-33001 and CVE-2026-70… No fix yet Fix from $1,9502026-08-10 MEDIUM 6.8 CVE-2026-19278 A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the sy… No fix yet Fix from $1,6002026-08-10 CRITICAL 9.8 CVE-2026-13206 Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command … No fix yet Fix from $2,3002026-08-10 HIGH 8.2 CVE-2026-12984 Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. This issue affects WAH7601: th… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-68091 In the Linux kernel, the following vulnerability has been resolved: HID: wacom: stop hardware after post-start probe failures wacom_parse_and_regis… No fix yet Fix from $1,9502026-08-10 HIGH 8.0 CVE-2026-68085 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled HCI_UAR… No fix yet Fix from $1,9502026-08-10 CRITICAL 9.1 CVE-2026-68083 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_create The SMB2 open lookup i… No fix yet Fix from $2,3002026-08-10 MEDIUM 5.5 CVE-2026-59088 A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to… Enterprise Linux No fix yet Fix from $1,6002026-08-10 HIGH 7.6 CVE-2026-72594 A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary… No fix yet Fix from $1,9502026-08-10 CRITICAL 9.8 CVE-2026-72593 A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager func… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-72592 An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on … No fix yet Fix from $2,3002026-08-10 HIGH 7.7 CVE-2026-72591 A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP reques… No fix yet Fix from $1,9502026-08-10 CRITICAL 9.8 CVE-2026-72590 An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-72589 An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system … No fix yet Fix from $2,3002026-08-10