Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-64224 In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix double free in rvu_rep_rsrc_init() rvu_rep_rsrc_init() alloca… Linux Kernel 6.18.34 / 7.0.11+ Fix from $1,9502026-07-24 HIGH 7.8 CVE-2026-64226 In the Linux kernel, the following vulnerability has been resolved: sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path In scx_root_… Linux Kernel 6.12.92 / 6.18.34+ Fix from $1,9502026-07-24 HIGH 8.1 CVE-2026-64223 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: consume only present negotiated TTLM maps ieee80211_tid_to_link… Linux Kernel 6.12.92 / 6.18.34+ Fix from $1,9502026-07-24 HIGH 7.0 CVE-2026-64222 In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on AQ init failure otx2_pool_aq_… Linux Kernel 5.10.259 / 5.15.210+ Fix from $1,9502026-07-24 MEDIUM 5.5 CVE-2026-64220 In the Linux kernel, the following vulnerability has been resolved: device property: set fwnode->secondary to NULL in fwnode_init() If a firmware n… Linux Kernel 5.15.209 / 6.1.175+ Fix from $1,6002026-07-24 MEDIUM 5.5 CVE-2026-64215 In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table Check the return… Linux Kernel 7.0.11+ Fix from $1,6002026-07-24 MEDIUM 5.5 CVE-2026-64214 In the Linux kernel, the following vulnerability has been resolved: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work… Linux Kernel 6.1.175 / 6.6.142+ Fix from $1,6002026-07-24 HIGH 7.8 CVE-2026-64221 In the Linux kernel, the following vulnerability has been resolved: spi: ti-qspi: fix use-after-free after DMA setup failure The driver falls back … Linux Kernel 5.10.258 / 5.15.209+ Fix from $1,9502026-07-24 HIGH 7.0 CVE-2026-64219 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_t… Linux Kernel 5.15.209 / 6.1.175+ Fix from $1,9502026-07-24 HIGH 7.8 CVE-2026-64218 In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: fix report_work leak on backbone_gw purge batadv_bla_purge_bac… Linux Kernel 5.10.258 / 5.15.209+ Fix from $1,9502026-07-24 HIGH 7.8 CVE-2026-64217 In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter() Fix netfs_extract_user_it… Linux Kernel 6.6.142 / 6.12.92+ Fix from $1,9502026-07-24 CRITICAL 9.8 CVE-2026-64216 In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_ab… Linux Kernel 6.18.34 / 7.0.11+ Fix from $2,3002026-07-24 HIGH 7.1 CVE-2026-64209 In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config swing_tb… Linux Kernel 7.0.11+ Fix from $1,9502026-07-24 MEDIUM 5.5 CVE-2026-64213 In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Add lock protection to lm90_alert Sashiko reports: lm90_alert() … Linux Kernel 6.18.34 / 7.0.11+ Fix from $1,6002026-07-24 MEDIUM 5.5 CVE-2026-64212 In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it In iwl_… Linux Kernel 6.18.34 / 7.0.11+ Fix from $1,6002026-07-24 MEDIUM 5.5 CVE-2026-64211 In the Linux kernel, the following vulnerability has been resolved: srcu: Don't queue workqueue handlers to never-online CPUs While an srcu_struct … Linux Kernel 7.0.11+ Fix from $1,6002026-07-24 HIGH 7.5 CVE-2026-64210 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ During napi poll, when the affini… Linux Kernel 7.0.11+ Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-64208 In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks Change the… Linux Kernel 6.18.34 / 7.0.11+ Fix from $1,9502026-07-24 HIGH 8.1 CVE-2026-8789 The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce ver… No fix yet Fix from $1,9502026-07-24 MEDIUM 6.1 CVE-2026-8308 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services W… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.5 CVE-2026-66007 Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadat… Datasets after 5.0.0 Fix from $1,6002026-07-24 MEDIUM 5.3 CVE-2026-66006 lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthe… Lakefs after 1.83.0 Fix from $1,6002026-07-24 MEDIUM 6.3 CVE-2026-66005 Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attac… Patch available Fix from $1,6002026-07-24 MEDIUM 5.3 CVE-2026-66004 BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitr… Patch available Fix from $1,6002026-07-24 CRITICAL 9.8 CVE-2026-58630 Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. Azure App Service For Linux No fix yet Fix from $2,3002026-07-24 CRITICAL 9.8 CVE-2026-58586 Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses… No fix yet Fix from $2,3002026-07-24 CRITICAL 10.0 CVE-2026-57106 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. Purview Data Governance No fix yet Fix from $2,3002026-07-24 CRITICAL 10.0 CVE-2026-56163 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo… Azure Kubernetes Service No fix yet Fix from $2,3002026-07-24 HIGH 8.7 CVE-2026-55732 Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and … No fix yet Fix from $1,9502026-07-24 MEDIUM 6.6 CVE-2026-55731 Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4… No fix yet Fix from $1,6002026-07-24