CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-98276
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: lock the socket in sock_gettstamp() sk->sk_flags must only be changed while holding the socket …

Oct 6, 2026
CVE-2026-98261
8.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server use-after-free in cifs_chan_skip_or_disable() When a secondary channel is no longer supported by …

Oct 6, 2026
CVE-2026-98260
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: exec: Cleanup POSIX timers right after de_thread() A per-thread CPU timer holds a reference to …

Oct 6, 2026
CVE-2026-98258
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list Kijo analyzed another …

Oct 6, 2026
CVE-2026-98257
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: rds: ib: use rds_conn_drop() on protocol version mismatch rds_ib_cm_connect_complete() runs from the RDMA-CM event handler …

Oct 6, 2026
CVE-2026-98256
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: signal: Prevent exec() race Hyunwoo debugged the following KASAN UAF splat: BUG: KASAN: slab-use-after-free in …

Oct 6, 2026
CVE-2026-98254
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: swiotlb: use the adjusted address for the highmem page lookup swiotlb_bounce() reads the page frame …

Oct 6, 2026
CVE-2026-98253
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: Serialize join and leave on copy_to_user failure rdma_join_multicast() queues RoCE work that later reads …

Oct 6, 2026
CVE-2026-98252
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() iwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail() making it accessible to …

Oct 6, 2026
CVE-2026-98251
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: openvswitch: avoid reallocating confirmed conntrack labels ovs_ct_get_conn_labels() adds the labels extension when a conntrack entry …

Oct 6, 2026
CVE-2026-98243
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3 The patch "dma-buf: dma-fence: …

Oct 6, 2026
CVE-2026-98241
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm: use full sockets in local error paths xfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as …

Oct 6, 2026
CVE-2026-98239
8.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: lan743x: fix RX checksum use-after-free lan743x_rx_process_buffer() adds each non-first receive buffer to the head …

Oct 6, 2026
CVE-2026-98230
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfrm: use hlist_del_init_rcu for state_cache and state_cache_input Commit 14acf9652e56 ("xfrm: defensively unhash xfrm_state lists in …

Oct 6, 2026
CVE-2026-98229
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfrm: save input state data before secpath resets xfrm_input() stores the current xfrm_state in the …

Oct 6, 2026
CVE-2026-98228
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ On I6500 CPU cores, lld and scd give no ordering …

Oct 6, 2026
CVE-2026-98216
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix the PIO_CRED credit-return mmap hfi1_file_mmap()'s PIO_CRED case must hand user space the single …

Oct 6, 2026
CVE-2026-98197
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove When the fan/pwm 4-5 pins are …

Oct 6, 2026
CVE-2026-98180
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/msm: RCU-free the scheduler-containing ring and VM objects Both struct msm_ringbuffer and struct msm_gem_vm embed …

Oct 6, 2026
CVE-2026-98175
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: cancel reconnect work in clean_demultiplex_info() clean_demultiplex_info() cancels server->echo delayed work but not server->reconnect, …

Oct 6, 2026
CVE-2026-98174
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix rlist race and missing initialization TCP_Server_Info.rlist is allocated via kzalloc which zeros …

Oct 6, 2026
CVE-2026-98173
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free of iface in cifs_try_adding_channels() cifs_try_adding_channels() iterates ses->iface_list with list_for_each_entry_safe_from(), which captures …

Oct 6, 2026
CVE-2026-98171
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Fix several related bounds …

Oct 6, 2026
CVE-2026-98169
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOB read in smb3_enum_snapshots() If snapshot_array_size is smaller than GMT_TOKEN_SIZE, smb3_enum_snapshots() …

Oct 6, 2026
CVE-2026-98166
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/ttm: fix swapped-out resources never leaving their bulk_move range ttm_tt_swapout() returns the number of pages …

Oct 6, 2026
CVE-2026-95594
8.1 HIGH

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions.

Oct 6, 2026
CVE-2026-95526
7.3 HIGH

Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions.

Oct 6, 2026
CVE-2026-94675
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions.

Oct 6, 2026
CVE-2026-66588
7.5 HIGH

Unauthenticated Broken Access Control in The7 <= 14.2.2 versions.

Oct 6, 2026
CVE-2026-62072
8.8 HIGH

Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions.

Oct 6, 2026
CVE-2026-48199
7.5 HIGH

Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions.

Oct 6, 2026
CVE-2026-48197
7.2 HIGH

Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0.

Oct 6, 2026
CVE-2026-42638
7.5 HIGH

Missing Authorization vulnerability in Awesomemotive Easy Digital Downloads easy-digital-downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through …

Oct 6, 2026
CVE-2026-42636
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6 versions.

Oct 6, 2026
CVE-2026-42635
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions.

Oct 6, 2026
CVE-2026-42634
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions.

Oct 6, 2026
CVE-2026-42418
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Socialrocket Social Rocket social-rocket allows Reflected XSS.This issue affects Social Rocket: from n/a …

Oct 6, 2026
CVE-2026-42416
8.5 HIGH

Subscriber SQL Injection in UDesign Core <= 4.15.0 versions.

Oct 6, 2026
CVE-2026-42414
8.5 HIGH

Subscriber SQL Injection in ListingPro <= 2.9.12 versions.

Oct 6, 2026
CVE-2026-42413
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Snapshotify &#8211; All-in-One Backup &amp; Restore &amp; Migrate <= 1.3.2 versions.

Oct 6, 2026
CVE-2026-41562
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions.

Oct 6, 2026
CVE-2026-41561
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions.

Oct 6, 2026
CVE-2026-41560
7.5 HIGH

Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions.

Oct 6, 2026
CVE-2026-41559
7.5 HIGH

Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup &amp; Restore <= 2.1.2 versions.

Oct 6, 2026
CVE-2026-40807
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.6 versions.

Oct 6, 2026
CVE-2026-40806
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions.

Oct 6, 2026
CVE-2026-39796
7.5 HIGH

Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions.

Oct 6, 2026
CVE-2026-39794
7.5 HIGH

Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions.

Oct 6, 2026
CVE-2026-39793
8.8 HIGH

Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.

Oct 6, 2026
CVE-2026-39792
8.6 HIGH

Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions.

Oct 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.