VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18494 CVEsRSS

CVE-2026-89645Medium· 5.5
3w ago

kernel: btrfs: drop recovered reloc root refs on recovery failure (CVE-2026-89645)

A flaw was found in the btrfs file system in the Linux kernel. During relocation recovery, if an error occurs, such as a memory allocation failure, the system may not properly drop references to relocation roots. This oversight can lead to…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.22%via CSAF
CVE-2026-89644Medium· 5.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix extent map leak in NOCOW direct I/O write btrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an extent map reference that must be dropped on al…

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix extent map leak in NOCOW direct I/O write btrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an extent map reference that must be dropped on al…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89629Medium· 5.5
3w ago

kernel: HID: corsair-void: Check size of status and firmware events before reading them (CVE-2026-89629)

A flaw was found in the Linux kernel, specifically within the `corsair-void` driver for Human Interface Devices (HID). This vulnerability allows an attacker to cause an out-of-bounds read by sending malformed status and firmware events. Th…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.21%via CSAF
CVE-2026-89625High· 7.0
3w ago

In the Linux kernel, the following vulnerability has been resolved: HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind For GHL (Guitar Hero Live) dongles, sony_probe() arms a periodic timer: ghl_magic_poke() (the timer cal…

In the Linux kernel, the following vulnerability has been resolved: HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind For GHL (Guitar Hero Live) dongles, sony_probe() arms a periodic timer: ghl_magic_poke() (the timer cal…

▾ TwilightLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89772High· 7.0
3w ago

kernel: btrfs: write-protect folios during data writeback (CVE-2026-89772)

A flaw was found in the Btrfs filesystem of the Linux kernel. This vulnerability allows a local attacker with write access to a memory-mapped file to modify data while it is being written to disk. This can lead to data corruption, where th…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2026-89770Medium· 5.5
3w ago

kernel: iomap: don't free integrity payload that doesn't exist (CVE-2026-89770)

A flaw was found in the `iomap` component of the Linux kernel. This vulnerability occurs when Protection Information (PI) verification is disabled on a block device, causing `fs_bio_integrity_alloc` to not allocate a bio integrity payload.…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2026-89768Medium· 5.5
3w ago

kernel: fs: fix user path of nested backing files (CVE-2026-89768)

A flaw was found in the Linux kernel's filesystem (fs) component. When using nested overlay filesystems (overlayfs), a local user could exploit an issue where the backing_file_open() function incorrectly derives the path for mapped files. …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89766High· 7.0
3w ago

In the Linux kernel, the following vulnerability has been resolved: pidfd: hold exec_update_lock around namespace ioctl The PIDFD_GET_*_NAMESPACE ioctls in pidfd_ioctl() perform a filesystem credentials ptrace access check before handi…

In the Linux kernel, the following vulnerability has been resolved: pidfd: hold exec_update_lock around namespace ioctl The PIDFD_GET_*_NAMESPACE ioctls in pidfd_ioctl() perform a filesystem credentials ptrace access check before handi…

▾ TwilightLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89759Medium· 5.5
3w ago

kernel: mm/kmemleak: avoid soft lockup when scanning task stacks (CVE-2026-89759)

A flaw was found in the Linux kernel's memory leak detector (kmemleak). When kmemleak_scan() attempts to scan task stacks on systems with a large number of threads, it can hold a CPU for an extended period without allowing other processes …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89757Medium· 5.5
3w ago

kernel: mm/mglru: fix and remove redundant unevictable folio handling (CVE-2026-89757)

A flaw was found in the Linux kernel's memory management unit (MMU), specifically within the multi-generational Least Recently Used (mglru) mechanism. A bug in how the kernel handles unevictable memory pages can lead to these pages remaini…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89745High· 7.0
3w ago

kernel: debugfs: Fix lockdown check for mmap_prepare (CVE-2026-89745)

A flaw was found in the Linux kernel's debugfs component. The lockdown mechanism, designed to enhance system integrity, did not properly account for files using the `mmap_prepare` operation. This oversight could allow an attacker to bypass…

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.20%via CSAF
CVE-2026-89740Medium· 5.5
3w ago

kernel: serial: imx: serialize imx_uart_ports[] lifetime (CVE-2026-89740)

A flaw was found in the Linux kernel's `serial: imx` component. The `imx_uart_probe()` function publishes a device-managed allocated port in the `imx_uart_ports[]` array before it is fully added. If the port addition fails or the port is r…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89332Medium· 5.5
3w ago

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Craf…

▾ Sunlitamazon · kiro_ideEPSS 0.18%via NVD
CVE-2026-89161High· 7.4
3w ago

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

▾ Twilightpcre · pcre2EPSS 0.13%via NVD
CVE-2026-78124Low· 3.7
3w ago

strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.

strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.

▾ Sunlitstrongswan · strongswanEPSS 0.19%via NVD
CVE-2026-62089High· 7.1
3w ago

WordPress Master Addons for Elementor plugin <= 3.2.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.

▾ TwilightPixar Labs · master-addonsEPSS 0.32%via CVEORG
CVE-2026-52630Critical· 9.8
3w ago

SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php

SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php

▾ MidnightEPSS 0.66%via NVD
CVE-2026-8778Critical· 9.8
3w ago

MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload

The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versio…

▾ Midnightmulika · MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields.EPSS 1.1%via CVEORG
CVE-2026-62140Medium· 5.3
3w ago

WordPress Quiz And Survey Master plugin <= 11.2.5 - Insecure Direct Object References (IDOR) vulnerability

Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.

▾ SunlitExpressTech Systems · quiz-master-nextEPSS 0.31%via CVEORG
CVE-2026-62137Medium· 5.3
3w ago

WordPress bbPress plugin <= 2.6.14 - Sensitive Data Exposure vulnerability

Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.

▾ SunlitJohn James Jacoby · bbpressEPSS 0.31%via CVEORG
CVE-2026-62135Medium· 5.3
3w ago

WordPress Booktics plugin <= 1.0.24 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.

▾ SunlitArraytics · bookticsEPSS 0.29%via CVEORG
CVE-2026-62132Medium· 5.3
3w ago

WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability

Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.

▾ Sunlitmasteriyo · learning-management-systemEPSS 0.29%via CVEORG
CVE-2026-62113Medium· 4.3
3w ago

WordPress Slim SEO plugin <= 4.10.0 - Insecure Direct Object References (IDOR) vulnerability

Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions.

▾ SunlitAnh Tran · slim-seoEPSS 0.27%via CVEORG
CVE-2026-62110Medium· 6.5
3w ago

WordPress Bold Page Builder plugin <= 5.9.9 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.

▾ Sunlitboldthemes · bold-page-builderEPSS 0.22%via CVEORG
CVE-2026-62107High· 8.8
3w ago

WordPress Masteriyo - LMS plugin <= 3.4.0 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.

▾ Twilightmasteriyo · learning-management-systemEPSS 0.52%via CVEORG
CVE-2026-62103Critical· 9.8
3w ago

WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.

▾ Midnightwpeverest · everest-formsEPSS 0.56%via CVEORG
CVE-2026-18579High· 7.2
3w ago

WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escapin…

▾ Twilightopajaap · WP Photo Album PlusEPSS 0.29%via CVEORG
CVE-2026-11496Medium· 6.5
3w ago

Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure

The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8. This is due to the InspectOrder() AJAX ha…

▾ Sunlitedgarrojas · PDF Builder for WooCommerce. Create invoices,packing slips and moreEPSS 0.26%via CVEORG
CVE-2024-12145Medium· 4.3
3w ago

BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Deletion

The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes…

▾ Sunlitbuddypress · BuddyPressEPSS 0.19%via CVEORG
CVE-2026-89265Medium· 4.3PoC
3w ago

MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint

MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office …

▾ Twilightmoxi624 · MoguBlogEPSS 0.37%via CVEORG
CVEs tagged “cve.org” — page 361 · VulnSea