Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2026-64224
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: fix double free in rvu_rep_rsrc_init()
rvu_rep_rsrc_init() alloca…
Linux Kernel
6.18.34 / 7.0.11+
HIGH 7.8
CVE-2026-64226
In the Linux kernel, the following vulnerability has been resolved:
sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path
In scx_root_…
Linux Kernel
6.12.92 / 6.18.34+
HIGH 8.1
CVE-2026-64223
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: consume only present negotiated TTLM maps
ieee80211_tid_to_link…
Linux Kernel
6.12.92 / 6.18.34+
HIGH 7.0
CVE-2026-64222
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: avoid double free of pool->stack on AQ init failure
otx2_pool_aq_…
Linux Kernel
5.10.259 / 5.15.210+
MEDIUM 5.5
CVE-2026-64220
In the Linux kernel, the following vulnerability has been resolved:
device property: set fwnode->secondary to NULL in fwnode_init()
If a firmware n…
Linux Kernel
5.15.209 / 6.1.175+
MEDIUM 5.5
CVE-2026-64215
In the Linux kernel, the following vulnerability has been resolved:
drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table
Check the return…
Linux Kernel
7.0.11+
MEDIUM 5.5
CVE-2026-64214
In the Linux kernel, the following vulnerability has been resolved:
powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work…
Linux Kernel
6.1.175 / 6.6.142+
HIGH 7.8
CVE-2026-64221
In the Linux kernel, the following vulnerability has been resolved:
spi: ti-qspi: fix use-after-free after DMA setup failure
The driver falls back …
Linux Kernel
5.10.258 / 5.15.209+
HIGH 7.0
CVE-2026-64219
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_t…
Linux Kernel
5.15.209 / 6.1.175+
HIGH 7.8
CVE-2026-64218
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: bla: fix report_work leak on backbone_gw purge
batadv_bla_purge_bac…
Linux Kernel
5.10.258 / 5.15.209+
HIGH 7.8
CVE-2026-64217
In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix overrun check in netfs_extract_user_iter()
Fix netfs_extract_user_it…
Linux Kernel
6.6.142 / 6.12.92+
CRITICAL 9.8
CVE-2026-64216
In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()
netfs_unlock_ab…
Linux Kernel
6.18.34 / 7.0.11+
HIGH 7.1
CVE-2026-64209
In the Linux kernel, the following vulnerability has been resolved:
phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config
swing_tb…
Linux Kernel
7.0.11+
MEDIUM 5.5
CVE-2026-64213
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (lm90) Add lock protection to lm90_alert
Sashiko reports:
lm90_alert() …
Linux Kernel
6.18.34 / 7.0.11+
MEDIUM 5.5
CVE-2026-64212
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it
In iwl_…
Linux Kernel
6.18.34 / 7.0.11+
MEDIUM 5.5
CVE-2026-64211
In the Linux kernel, the following vulnerability has been resolved:
srcu: Don't queue workqueue handlers to never-online CPUs
While an srcu_struct …
Linux Kernel
7.0.11+
HIGH 7.5
CVE-2026-64210
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: xsk: Fix unlocked writing to ICOSQ
During napi poll, when the affini…
Linux Kernel
7.0.11+
HIGH 7.5
CVE-2026-64208
In the Linux kernel, the following vulnerability has been resolved:
crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
Change the…
Linux Kernel
6.18.34 / 7.0.11+
HIGH 8.1
CVE-2026-8789
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce ver…
No fix yet
MEDIUM 6.1
CVE-2026-8308
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services W…
No fix yet
MEDIUM 6.5
CVE-2026-66007
Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadat…
Datasets
after 5.0.0
MEDIUM 5.3
CVE-2026-66006
lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthe…
Lakefs
after 1.83.0
MEDIUM 6.3
CVE-2026-66005
Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attac…
Patch available
MEDIUM 5.3
CVE-2026-66004
BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitr…
Patch available
CRITICAL 9.8
CVE-2026-58630
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Azure App Service For Linux
No fix yet
CRITICAL 9.8
CVE-2026-58586
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp.
Image::WebP does not link to the system libwebp. Instead, it uses…
No fix yet
CRITICAL 10.0
CVE-2026-57106
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
Purview Data Governance
No fix yet
CRITICAL 10.0
CVE-2026-56163
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo…
Azure Kubernetes Service
No fix yet
HIGH 8.7
CVE-2026-55732
Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and …
No fix yet
MEDIUM 6.6
CVE-2026-55731
Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4…
No fix yet