Search
32,629 CVEs · Critical severity
CVEs (32,629, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 32,629 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63978 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: net/handshake: Drain pending requests at net namespace exit The arguments to list_splice_init() in han… | |
| CVE-2026-63938 | CRITICAL | 9.3 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Check PSC request indices against the actual size of the buffer When processing Page State C… | |
| CVE-2026-63939 | CRITICAL | 9.3 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Compute the correct max length of the in-GHCB scratch area When setting the length of the GH… | |
| CVE-2026-63940 | CRITICAL | 9.3 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length '0' Explicitly ignore Port I/O requests of length '0' (or… | |
| CVE-2026-63922 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_network_header(skb) in … | |
| CVE-2026-63924 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() ipv6_hop_jumbo() calls pskb_trim_rcsum(), whi… | |
| CVE-2026-63912 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer… | |
| CVE-2026-63886 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates … | |
| CVE-2026-63887 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() co… | |
| CVE-2026-63888 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in t… | |
| CVE-2026-63857 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() The transmit loop in airo… | |
| CVE-2026-63830 | CRITICAL | 9.4 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms The sk_msg sg.copy bitmap is part of the scatterlist… | |
| CVE-2026-63825 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concurrent access crashes GCC's GCOV instrumentation can merge… | |
| CVE-2026-63808 | CRITICAL | Patched | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_he… |
| CVE-2026-63800 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_upd… | |
| CVE-2026-53399 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_sta… | |
| CVE-2026-63795 | CRITICAL | 10.0 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set… | |
| CVE-2026-53398 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes si… | |
| CVE-2026-53384 | CRITICAL | 9.8 | 2026-07-19 | In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 82… | |
| CVE-2026-16117 | CRITICAL | Patched | 10.0 | 2026-07-18 | Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes path… |
| CVE-2026-47865 | CRITICAL | Patched | 9.8 | 2026-07-18 | VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the … |
| CVE-2026-55518 | CRITICAL | Patched | 9.6 | 2026-07-17 | Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the U… |
| CVE-2026-52348 | CRITICAL | 9.8 | 2026-07-17 | cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. | |
| CVE-2026-54159 | CRITICAL | Patched | 10.0 | 2026-07-17 | PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the … |
| CVE-2026-48062 | CRITICAL | Patched | 9.8 | 2026-07-17 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived gue… |