Search
34,702 CVEs · Critical severity
EOL hidden · Show all products
CVEs (34,702, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 34,702 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-80694 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller mtk_handle_irq_rx expects… | |
| CVE-2026-80693 | CRITICAL | 9.3 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: idpf: bound interrupt-vector register fill to the allocated array idpf_get_reg_intr_vecs() fills the c… | |
| CVE-2026-80684 | CRITICAL | 9.3 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix NULL dereference on AIBV allocation failure The airq_iv_create() can return NULL o… | |
| CVE-2026-80681 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit() Before route_shortcircuit(), the eth header poin… | |
| CVE-2026-80674 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident attribute lists and harden the validator A base inode's $ATTRIBUTE_LIST is san… | |
| CVE-2026-80673 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() When resolving an attribu… | |
| CVE-2026-80671 | CRITICAL | 9.3 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: perf sched: Fix register_pid() overflow, strcpy, and BUG_ON register_pid() has several issues when pro… | |
| CVE-2026-80670 | CRITICAL | 9.1 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: perf tools: Use perf_env__get_cpu_topology() in machine__resolve() machine__resolve() accesses env->cp… | |
| CVE-2026-80668 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use conntrack GC to reap expectations This patch replaces the timer AP… | |
| CVE-2026-80634 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag The DEV_PATH_BR_VLAN_UNTAG case … | |
| CVE-2026-80630 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen Whene… | |
| CVE-2026-80617 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_check_time allocation size foe_check_time is declared as u16 pointer but was allo… | |
| CVE-2026-80612 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: net: lwtunnel: Drop skb metadata before LWT encapsulation skb metadata is meant for passing informatio… | |
| CVE-2026-80609 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-bounds check for cqe->len_list[] Move index check before element access. | |
| CVE-2026-80603 | CRITICAL | 9.1 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read parse_dcc() treats data_end as an inc… | |
| CVE-2026-80600 | CRITICAL | 9.8 | 2026-08-28 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only after skb realloc The pskb_may_pull() called by batadv_get… | |
| CVE-2026-78032 | CRITICAL | 9.8 | 2026-08-28 | SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege. | |
| CVE-2026-76581 | CRITICAL | 9.8 | 2026-08-28 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HM… | |
| CVE-2026-40541 | CRITICAL | Patched | 9.0 | 2026-08-28 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows re… |
| CVE-2026-82082 | CRITICAL | 9.8 | 2026-08-28 | NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server. | |
| CVE-2026-61800 | CRITICAL | Patched | 9.1 | 2026-08-28 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the… |
| CVE-2026-78239 | CRITICAL | 9.8 | 2026-08-28 | Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that shoul… | |
| CVE-2026-76943 | CRITICAL | 9.8 | 2026-08-28 | Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command exe… | |
| CVE-2026-76179 | CRITICAL | 9.8 | 2026-08-28 | An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are ins… | |
| CVE-2026-75337 | CRITICAL | 9.8 | 2026-08-28 | The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview ro… |