CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-80967
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr: initialize mutexes before requesting threaded IRQ pcxhr_probe() requests pcxhr_threaded_irq() before initializing mgr->lock, even …

Sep 11, 2026
CVE-2026-80962
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate geometry fields from on-disk cache_info cache_segs_init() iterates cache_info->n_segs times indexing cache->segments[], which is …

Sep 11, 2026
CVE-2026-80961
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate kset key_num and intra-segment bounds Two more fields decoded from the cache device …

Sep 11, 2026
CVE-2026-80959
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: bound the persisted tail-position offset cache_pos_decode() takes the persisted key_tail and dirty_tail seg_off from …

Sep 11, 2026
CVE-2026-80958
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: clamp the tail kset read to the segment data region The tail-kset read in …

Sep 11, 2026
CVE-2026-80955
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: fix use-after-free and invalid seg operations in kset_replay() In kset_replay, when key->seg_gen is stale …

Sep 11, 2026
CVE-2026-80954
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() i3c_device_get_supported_xfer_mode() uses dev->desc to obtain the master …

Sep 11, 2026
CVE-2026-80953
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: i3c: master: adi: initialize the lock before enabling interrupts adi_i3c_master_probe() requests the IRQ and unmasks …

Sep 11, 2026
CVE-2026-80952
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix info leak and UAF in device unregister path i3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before …

Sep 11, 2026
CVE-2026-80950
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Check that the transfer is valid before accessing it The Renesas I3C driver …

Sep 11, 2026
CVE-2026-80947
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop rtl8xxxu arms rx_urb_wq from the RX completion …

Sep 11, 2026
CVE-2026-80944
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Detach sync cmd buffer on interrupted wait mwifiex synchronous commands keep the caller-provided …

Sep 11, 2026
CVE-2026-80943
7.6 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the …

Sep 11, 2026
CVE-2026-80937
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy mt7915_mcu_get_eeprom() copies a …

Sep 11, 2026
CVE-2026-80936
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel mlo_pm_work on stop mt7925 queues mlo_pm_work with a 5 second delay …

Sep 11, 2026
CVE-2026-80935
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy mt7996_mcu_get_eeprom() derives the …

Sep 11, 2026
CVE-2026-80933
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate default EEPROM firmware size The default EEPROM firmware is parsed and …

Sep 11, 2026
CVE-2026-80932
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: flush works in dependency order virtio_vsock_remove() stops the virtqueues and then flushes each work …

Sep 11, 2026
CVE-2026-80931
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17: reject an oversize length on an I2C block read w1_f19_i2c_master_transfer() is the master_xfer …

Sep 11, 2026
CVE-2026-80929
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] cad_pid is global, and kill_cad_pid() is …

Sep 11, 2026
CVE-2026-80928
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() When inspecting the credentials of another task, objective credentials …

Sep 11, 2026
CVE-2026-54135
7.5 HIGH

AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP …

Sep 11, 2026
CVE-2026-79394
7.5 HIGH

An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships …

Sep 11, 2026
CVE-2026-79393
7.5 HIGH

A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier …

Sep 11, 2026
CVE-2026-71646
7.5 HIGH

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the FastExplorationFSM::optTimerCallback() …

Sep 11, 2026
CVE-2026-62112
7.6 HIGH

Editor SQL Injection in Amelia <= 2.4.9 versions.

Sep 11, 2026
CVE-2026-62109
7.6 HIGH

Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.

Sep 11, 2026
CVE-2026-62107
8.8 HIGH

Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.

Sep 11, 2026
CVE-2026-62106
8.8 HIGH

Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.

Sep 11, 2026
CVE-2026-62102
8.8 HIGH

Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.

Sep 11, 2026
CVE-2026-62089
7.1 HIGH

Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.

Sep 11, 2026
CVE-2026-89099
7.5 HIGH

A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, …

Sep 11, 2026
CVE-2026-78807
7.1 HIGH

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing …

Sep 11, 2026
CVE-2026-67211
7.5 HIGH

OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. …

Sep 11, 2026
CVE-2026-72708
7.5 HIGH

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying …

Sep 11, 2026
CVE-2026-89262
7.5 HIGH

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. …

Sep 11, 2026
CVE-2026-89260
7.5 HIGH

MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request …

Sep 11, 2026
CVE-2026-89066
7.8 HIGH

Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute …

Sep 11, 2026
CVE-2026-89065
7.1 HIGH

Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside …

Sep 11, 2026
CVE-2026-89013
7.5 HIGH

Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a …

Sep 11, 2026
CVE-2026-7863
8.4 HIGH

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS …

Sep 11, 2026
CVE-2026-70341
8.5 HIGH

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Sep 11, 2026
CVE-2026-68497
7.5 HIGH

jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers …

Sep 11, 2026
CVE-2026-8303
7.8 HIGH

Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.

Sep 11, 2026
CVE-2026-8301
7.8 HIGH

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows …

Sep 11, 2026
CVE-2026-87020
8.1 HIGH

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

Sep 11, 2026
CVE-2026-82583
8.3 HIGH

NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in …

Sep 11, 2026
CVE-2026-82578
7.5 HIGH

When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no …

Sep 11, 2026
CVE-2026-78224
8.2 HIGH

The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.

Sep 11, 2026
CVE-2026-38058
8.1 HIGH

The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for …

Sep 11, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.