CVE Database

9856+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-64061
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put of sink folio in netfs_read_gaps() Fix netfs_read_gaps() to release the sink …

Jul 19, 2026
CVE-2026-64056
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port The SKB used to assemble packets from fragments …

Jul 19, 2026
CVE-2026-64055
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter The gmac_rx() NAPI poll function assembles packets in …

Jul 19, 2026
CVE-2026-64047
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring When an sk_msg …

Jul 19, 2026
CVE-2026-64046
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain in plain text SG Sashiko points out that if end = …

Jul 19, 2026
CVE-2026-64037
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled When the TLC notification …

Jul 19, 2026
CVE-2026-64035
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: igc: set tx buffer type for SMD frames Sashiko pointed out that igc_fpe_init_smd_frame() initializes igc_tx_buffer …

Jul 19, 2026
CVE-2026-64034
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer In mana_hwc_rx_event_handler(), resp->response.hwc_msg_id is read …

Jul 19, 2026
CVE-2026-64033
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Fix use-after-free in path file creation cleanup In the error path of rtrs_srv_create_path_files(), the …

Jul 19, 2026
CVE-2026-64025
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: bpf, skmsg: fix verdict sk_data_ready racing with ktls rx sk_psock_strp_data_ready() already checks tls_sw_has_ctx_rx() and defers …

Jul 19, 2026
CVE-2026-64024
9.4 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction Blamed commit moved the TIME_WAIT-derived ISN …

Jul 19, 2026
CVE-2026-64018
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out-of-bounds array access In mana_hwc_rx_event_handler(), rx_req_idx is derived from …

Jul 19, 2026
CVE-2026-64016
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix durable reconnect error path file lifetime After a durable reconnect succeeds, ksmbd_reopen_durable_fd() republishes …

Jul 19, 2026
CVE-2026-64007
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ensure_writable synproxy_tstamp_adjust() rewrites the TCP timestamp option in place and …

Jul 19, 2026
CVE-2026-64000
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervision frame handling Ensure the entire TLV header …

Jul 19, 2026
CVE-2026-63994
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() Sashiko found that iptunnel_pmtud_build_icmp() and iptunnel_pmtud_build_icmpv6() were …

Jul 19, 2026
CVE-2026-63993
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() skb_tunnel_check_pmtu() can change skb->head. Reusing old_iph …

Jul 19, 2026
CVE-2026-63992
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() In some cases, iptunnel_pmtud_check_icmp() can be called …

Jul 19, 2026
CVE-2026-63984
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() ipv6_rpl_srh_decompress() computes: outhdr->hdrlen = (((n + 1) * …

Jul 19, 2026
CVE-2026-63979
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net/handshake: hand off the pinned file reference to accept_doit handshake_req_next() removes the request from the …

Jul 19, 2026
CVE-2026-63978
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net/handshake: Drain pending requests at net namespace exit The arguments to list_splice_init() in handshake_net_exit() are …

Jul 19, 2026
CVE-2026-63940
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length '0' Explicitly ignore Port I/O requests of …

Jul 19, 2026
CVE-2026-63939
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Compute the correct max length of the in-GHCB scratch area When setting the …

Jul 19, 2026
CVE-2026-63938
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Check PSC request indices against the actual size of the buffer When processing …

Jul 19, 2026
CVE-2026-63924
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() ipv6_hop_jumbo() calls pskb_trim_rcsum(), which can change skb pointers. …

Jul 19, 2026
CVE-2026-63922
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_network_header(skb) in nh while walking …

Jul 19, 2026
CVE-2026-63912
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer …

Jul 19, 2026
CVE-2026-63888
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the …

Jul 19, 2026
CVE-2026-63887
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates "key=value\0" records into login->rsp_buf, an …

Jul 19, 2026
CVE-2026-63886
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(chap->digest_size) and …

Jul 19, 2026
CVE-2026-63857
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() The transmit loop in airoha_dev_xmit() …

Jul 19, 2026
CVE-2026-63830
9.4 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms The sk_msg sg.copy bitmap is part of the …

Jul 19, 2026
CVE-2026-63825
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concurrent access crashes GCC's GCOV instrumentation can merge …

Jul 19, 2026
CVE-2026-63808
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_head obtained from exfat_get_dentry() is released …

Jul 19, 2026
CVE-2026-63800
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls …

Jul 19, 2026
CVE-2026-63795
10.0 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set …

Jul 19, 2026
CVE-2026-53399
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via …

Jul 19, 2026
CVE-2026-53398
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. If the …

Jul 19, 2026
CVE-2026-53384
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 8250 port via serial8250_register_8250_port() …

Jul 19, 2026
CVE-2026-16117
10.0 CRITICAL

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for …

Jul 18, 2026
CVE-2026-47865
9.8 CRITICAL

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by …

Jul 18, 2026
CVE-2026-55518
9.6 CRITICAL

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in …

Jul 17, 2026
CVE-2026-54159
10.0 CRITICAL

PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, …

Jul 17, 2026
CVE-2026-52348
9.8 CRITICAL

cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.

Jul 17, 2026
CVE-2026-48062
9.8 CRITICAL

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the …

Jul 17, 2026
CVE-2026-13446
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound …

Jul 17, 2026
CVE-2026-8859
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the …

Jul 17, 2026
CVE-2026-8635
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve …

Jul 17, 2026
CVE-2026-8505
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The …

Jul 17, 2026
CVE-2026-8481
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied …

Jul 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.