VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15516 CVEsRSS

CVE-2026-93228Critical· 9.1
4d ago

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chunks with segcount 0 A peer can send a Write or Reply chunk whose segcount field is zero. xdr_check_write_chunk() only rejects segcount >…

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chunks with segcount 0 A peer can send a Write or Reply chunk whose segcount field is zero. xdr_check_write_chunk() only rejects segcount >…

▾ MidnightLinux · LinuxEPSS 0.47%via NVD
CVE-2026-93231None
4d ago

In the Linux kernel, the following vulnerability has been resolved: lockd: fix swapped arguments in nlmsvc_match_ip() When releasing locks by server IP address via /proc/fs/nfsd/unlock_ip, nlmsvc_unlock_all_by_ip() calls nlm_traverse_f…

In the Linux kernel, the following vulnerability has been resolved: lockd: fix swapped arguments in nlmsvc_match_ip() When releasing locks by server IP address via /proc/fs/nfsd/unlock_ip, nlmsvc_unlock_all_by_ip() calls nlm_traverse_f…

▾ SunlitLinux · LinuxEPSS 0.17%via NVD
CVE-2026-93230None
4d ago

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier Gigantic bootmem HugeTLB pages are currently initialized from hugetlb_init(), but page_alloc_init…

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier Gigantic bootmem HugeTLB pages are currently initialized from hugetlb_init(), but page_alloc_init…

▾ SunlitLinux · LinuxEPSS 0.17%via NVD
CVE-2026-88369High· 7.3PoC
4d ago

zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump().

zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump().

▾ MidnightEPSS 0.24%via NVD
CVE-2026-88358None
4d ago

simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded()

simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafted truncated JSON document whose final structural token closes a nested array or object can cause json_iterator::walk_…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-88357High· 7.5PoC
4d ago

nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code

nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd offsets to be cast to uint16_t or wider integer pointers and direc…

▾ MidnightEPSS 0.60%via NVD
CVE-2026-93236None
4d ago

In the Linux kernel, the following vulnerability has been resolved: media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common When VIDIOC_TRY_FMT is called with an unsupported pixel format on the OUTPUT queue, vdec_try_fmt_comm…

In the Linux kernel, the following vulnerability has been resolved: media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common When VIDIOC_TRY_FMT is called with an unsupported pixel format on the OUTPUT queue, vdec_try_fmt_comm…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-93235None
4d ago

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to zero post-EOF data when extending file size generic/794 4s ..

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to zero post-EOF data when extending file size generic/794 4s ... - output mismatch (see /share/git/fstests/results//generic/794.out.bad) --- tests/gene…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-93234None
4d ago

In the Linux kernel, the following vulnerability has been resolved: drm/gud: validate TV mode names before creating enum property The GUD protocol returns TV mode names as fixed-size GUD_CONNECTOR_TV_MODE_NAME_LEN entries and requires …

In the Linux kernel, the following vulnerability has been resolved: drm/gud: validate TV mode names before creating enum property The GUD protocol returns TV mode names as fixed-size GUD_CONNECTOR_TV_MODE_NAME_LEN entries and requires …

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-88366None
4d ago

NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG arc commands

NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG arc commands. A specially crafted SVG document containing extreme arc radius values can cause intermediate arc calculat…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-77581High· 8.6PoC
4d ago

BentoPDF is a client-side PDF toolkit that is self hostable

BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS proxy in cloudflare/cors-proxy-worker.js uses isPrivateOrReservedHost() to validate a supplied hostname separately from…

▾ Midnightalam00000 · bentopdfEPSS 0.27%via NVD
CVE-2026-63630Low· 3.4
4d ago

BentoPDF is a client-side PDF toolkit that is self hostable

BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Timestamp node's tsaUrl control from imported JSON without schema or destination validation. When a user imports the cra…

▾ Sunlitalam00000 · bentopdfEPSS 0.31%via NVD
CVE-2026-96873Medium· 5.5
4d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0.

▾ SunlitThe Wikimedia Foundation · Mediawiki - CirrusSearch ExtensionEPSS 0.27%via NVD
CVE-2026-93240None
4d ago

In the Linux kernel, the following vulnerability has been resolved: memcg: make the v1 soft limit knob inert The v1 soft limit has been deprecated since v6.12 and nobody has reported depending on it

In the Linux kernel, the following vulnerability has been resolved: memcg: make the v1 soft limit knob inert The v1 soft limit has been deprecated since v6.12 and nobody has reported depending on it. Start the removal by decoupling th…

▾ SunlitLinux · LinuxEPSS 0.22%via NVD
CVE-2026-93237High· 7.8
4d ago

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Add DIRECT_MAP_PHYSMEM_END definition get_free_mem_region() and mhp_get_pluggable_range() bound their search to DIRECT_MAP_PHYSMEM_END

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Add DIRECT_MAP_PHYSMEM_END definition get_free_mem_region() and mhp_get_pluggable_range() bound their search to DIRECT_MAP_PHYSMEM_END. LoongArch does not d…

▾ TwilightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-93242None
4d ago

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb() qla24xx_process_response_queue() advances ring_ptr past the head IOCB before dispatching, so…

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb() qla24xx_process_response_queue() advances ring_ptr past the head IOCB before dispatching, so…

▾ SunlitLinux · LinuxEPSS 0.22%via NVD
CVE-2026-93239None
4d ago

In the Linux kernel, the following vulnerability has been resolved: arm64: mm: Fix the lockless page-table walk in show_pte() show_pte() walks page tables locklessly and can run with interrupts enabled

In the Linux kernel, the following vulnerability has been resolved: arm64: mm: Fix the lockless page-table walk in show_pte() show_pte() walks page tables locklessly and can run with interrupts enabled. A concurrent teardown can free a…

▾ SunlitLinux · LinuxEPSS 0.20%via NVD
CVE-2026-93238None
4d ago

In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap The DECLARE_BITMAP(apm_filtered, AP_DEVICES) macro allocates the bitmap on the stack without zero-…

In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap The DECLARE_BITMAP(apm_filtered, AP_DEVICES) macro allocates the bitmap on the stack without zero-…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-93244None
4d ago

In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: simpledrm: Improve stride validation Validate the computed stride against the maximum value INT_MAX.

In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: simpledrm: Improve stride validation Validate the computed stride against the maximum value INT_MAX.

▾ SunlitLinux · LinuxEPSS 0.18%via NVD
CVE-2026-93243None
4d ago

In the Linux kernel, the following vulnerability has been resolved: mm/secretmem: properly account locked pages secretmem accounts folios by treating memory as if it were mlock()'d and thus limited by the RLIMIT_MEMLOCK limit. However…

In the Linux kernel, the following vulnerability has been resolved: mm/secretmem: properly account locked pages secretmem accounts folios by treating memory as if it were mlock()'d and thus limited by the RLIMIT_MEMLOCK limit. However…

▾ SunlitLinux · LinuxEPSS 0.23%via NVD
CVE-2026-93241None
4d ago

In the Linux kernel, the following vulnerability has been resolved: memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done At Meta, we are seeing instances where an OOM killed job is stuck in the exit path for…

In the Linux kernel, the following vulnerability has been resolved: memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done At Meta, we are seeing instances where an OOM killed job is stuck in the exit path for…

▾ SunlitLinux · LinuxEPSS 0.23%via NVD
CVE-2026-88362High· 7.5PoC
4d ago

MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c

MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted JavaScript input containing an excessively large numeric array index can cause an out-of-range floating-point value to…

▾ MidnightEPSS 0.34%via NVD
CVE-2025-32000Medium· 4.3
4d ago

HCL Sametime is vulnerable to insufficient input sanitization

HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly trusted without sufficient sanitization, malicious actors can leverage …

▾ SunlitHCL Software · HCL SametimeEPSS 0.21%via NVD
CVE-2026-97404Critical· 9.2
4d ago

In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header

In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target project's UUID may bypass both Keystone …

▾ MidnightOpenStack · ZaqarEPSS 0.27%via NVD
CVE-2026-97362High· 7.5PoC
4d ago

HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request

HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung ser…

▾ Midnightrejetto · hfs2EPSS 0.29%via NVD
CVE-2026-97224Medium· 4.3
4d ago

A vulnerability was detected in Excalidraw up to 0.18.1

A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file packages/excalidraw/data/restore.ts of the component Imported File Handler. Performing a manipulation of the argument custom…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-90959High· 8.1
4d ago

A path traversal vulnerability was found in pulpcore

A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme valida…

▾ TwilightRed Hat · ansible-automation-platform-24/hub-rhel8EPSS 0.32%via NVD
CVE-2026-90481Critical· 9.2
4d ago

In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.

In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.

▾ MidnightPortSwigger · Burp Suite DASTEPSS 0.33%via NVD
CVE-2026-88351Critical· 9.8PoC
4d ago

An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms

An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with an excessively large element count, the page allocation size cal…

▾ AbyssalEPSS 0.31%via NVD
CVE-2026-82094High· 7.1
4d ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.28%via NVD
CVEs tagged “cve.org” — page 51 · VulnSea