CVE Database

45033+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-89826
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: harden firmware build-info bounds checks panthor_fw_read_build_info() checks whether the metadata range fits in the …

Sep 16, 2026
CVE-2026-89825
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix firmware control interface bounds checks panthor_init_cs_iface() and panthor_init_csg_iface() validate firmware control interface offsets …

Sep 16, 2026
CVE-2026-89823
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm: fix race between partial drm_dev_register() failure and ioctl If drm_dev_register() fails after registering a …

Sep 16, 2026
CVE-2026-89819
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: validate plane degamma LUT size for private color prop Unlike the CRTC degamma path, …

Sep 16, 2026
CVE-2026-89818
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check If the supplied msg[2] (num_buffers) is …

Sep 16, 2026
CVE-2026-89815
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Drop tt->restore after successful restore ttm_pool_restore_and_alloc() can successfully complete the restore process via ttm_pool_restore_commit(), …

Sep 16, 2026
CVE-2026-89814
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: clamp the isolation index for rings outside a partition adev->isolation[] has one slot per …

Sep 16, 2026
CVE-2026-89811
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add TLB flush after MES queue eviction/suspension MES (Micro Engine Scheduler) does not perform …

Sep 16, 2026
CVE-2026-89810
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix error path at svm_migrate_copy_to_ram If page migration from device to sys ram fails …

Sep 16, 2026
CVE-2026-89808
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram When migration vm range …

Sep 16, 2026
CVE-2026-89806
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation The framebuffer size calculation `fb_size = linebytes …

Sep 16, 2026
CVE-2026-89805
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: Fix folio allocation fallback and use-after-put drm_pagemap_migrate_populate_ram_pfn() had two issues when populating RAM PFNs …

Sep 16, 2026
CVE-2026-89804
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/dmem: fix mismatched DMA unmap size for large folios Device-private THP migration maps migration buffers …

Sep 16, 2026
CVE-2026-89803
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: unsubscribe the channel-kill event before the fence context nouveau_channel_del() tears the fence context down …

Sep 16, 2026
CVE-2026-89801
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE In nouveau_uvmm_bind_job_submit()'s OP_UNMAP_SPARSE arm, op->reg is set …

Sep 16, 2026
CVE-2026-89799
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in bpf_get_stackid The get_perf_callchain call needs disabled preemption plus we need it …

Sep 16, 2026
CVE-2026-89795
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: PCI: Allow per function PCI slots to fix slot reset on s390 On s390 systems, …

Sep 16, 2026
CVE-2026-89793
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ublk: clear VM_MAYWRITE on read-only ublk char device mmap ublk_ch_mmap() rejects mmap requests with VM_WRITE …

Sep 16, 2026
CVE-2026-73455
7.5 HIGH

On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to …

Sep 16, 2026
CVE-2026-73435
8.2 HIGH

On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on …

Sep 16, 2026
CVE-2026-89792
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config responses Validate IPC share configuration payload sizes before …

Sep 16, 2026
CVE-2026-89791
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: perf: Fix use-after-free when perf mmap() revival races with the last munmap() perf_mmap_close() drops rb->mmap_count …

Sep 16, 2026
CVE-2026-89789
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free gtp_newlink()'s error path frees tid_hash …

Sep 16, 2026
CVE-2026-89782
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table growth beyond U16_MAX entries During $LogFile replay, log_replay() indexes the transaction …

Sep 16, 2026
CVE-2026-89781
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() read_log_rec_buf() copies a log record into a caller buffer …

Sep 16, 2026
CVE-2026-89777
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: clear vdev->msi_perm after freeing it on init failure vfio_msi_cap_len() lazily allocates the per-device MSI …

Sep 16, 2026
CVE-2026-89774
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready sk deref in sco_conn_ready must be done either …

Sep 16, 2026
CVE-2026-81634
7.5 HIGH

In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer …

Sep 16, 2026
CVE-2026-73464
8.8 HIGH

On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC …

Sep 16, 2026
CVE-2026-73461
8.0 HIGH

On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, …

Sep 16, 2026
CVE-2026-73454
8.1 HIGH

On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target …

Sep 16, 2026
CVE-2026-73439
7.5 HIGH

On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and …

Sep 16, 2026
CVE-2026-2380
7.4 HIGH

On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may …

Sep 16, 2026
CVE-2026-88263
7.5 HIGH

XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected …

Sep 16, 2026
CVE-2026-84408
8.8 HIGH

QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC …

Sep 16, 2026
CVE-2026-27564
7.2 HIGH

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of …

Sep 16, 2026
CVE-2026-27563
7.2 HIGH

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution …

Sep 16, 2026
CVE-2026-27562
7.2 HIGH

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution …

Sep 16, 2026
CVE-2026-27561
7.2 HIGH

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution …

Sep 16, 2026
CVE-2026-27560
7.2 HIGH

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution …

Sep 16, 2026
CVE-2026-27559
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution …

Sep 16, 2026
CVE-2026-27558
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on …

Sep 16, 2026
CVE-2026-27557
7.5 HIGH

An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.

Sep 16, 2026
CVE-2026-27556
8.8 HIGH

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP …

Sep 16, 2026
CVE-2026-27555
8.8 HIGH

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP …

Sep 16, 2026
CVE-2026-27554
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on …

Sep 16, 2026
CVE-2026-27552
8.1 HIGH

A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing …

Sep 16, 2026
CVE-2026-27551
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on …

Sep 16, 2026
CVE-2026-27550
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on …

Sep 16, 2026
CVE-2026-27549
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on …

Sep 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.