Tue, Dec 30 · 01:16 PM CSTCVE-2023-54237
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix potential panic dues to unprotected smc_llc_srv_add_link() There is a certain chance to trigger the following panic: PID: 5900 TASK: ffff88c1c8af4100 CPU: 1 COMMAND: "kworker/1:48" #0 [ffff9456c1cc79a0] machine_kexec at ffffffff870665b7 #1
CVECVE-2023-54237
SeverityCRITICAL
TypeUPDATED
PublishedTue, Dec 30 · 01:16 PM CST
ModifiedMon, Sep 14 · 12:17 PM CDT
Fri, Aug 22 · 04:15 PM CDTCVE-2025-38660
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: [ceph] parse_longname(): strrchr() expects NUL-terminated string ... and parse_longname() is not guaranteed that. That's the reason why it uses kmemdup_nul() to build the argument for kstrtou64(); the problem is, kstrtou64() is not the only thing that
CVECVE-2025-38660
SeverityCRITICAL
TypeUPDATED
PublishedFri, Aug 22 · 04:15 PM CDT
ModifiedMon, Sep 14 · 12:17 PM CDT
Tue, Oct 28 · 12:15 PM CDTCVE-2025-40074
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF. Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(), ipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().
CVECVE-2025-40074
SeverityCRITICAL
TypeUPDATED
PublishedTue, Oct 28 · 12:15 PM CDT
ModifiedMon, Sep 14 · 12:17 PM CDT
Wed, Mar 04 · 09:15 AM CSTCVE-2026-27446
9.8/10 · Must read/watchNVDvuln
Summary
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result
CVECVE-2026-27446
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 04 · 09:15 AM CST
ModifiedMon, Sep 14 · 01:17 PM CDT
Tue, May 05 · 10:16 PM CDTCVE-2026-28780
9.8/10 · Must read/watchNVDvuln
Summary
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HT
CVECVE-2026-28780
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 05 · 10:16 PM CDT
ModifiedMon, Sep 14 · 01:17 PM CDT
Wed, May 06 · 12:16 PM CDTCVE-2026-43198
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is already visible from TCP ehash table and other cpus might use
CVECVE-2026-43198
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 06 · 12:16 PM CDT
ModifiedMon, Sep 14 · 12:17 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedMon, Sep 14 · 01:18 PM CDT
Wed, May 06 · 10:16 AM CDTCVE-2026-43114
9.4/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. The test first loads a ranomly generated pipapo set with 'ipv4 . port' key, i.e. nft -f foo. This works. T
CVECVE-2026-43114
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 06 · 10:16 AM CDT
ModifiedMon, Sep 14 · 01:18 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedMon, Sep 14 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedMon, Sep 14 · 01:18 PM CDT
Tue, Mar 12 · 05:15 PM CDTCVE-2024-21400
9.0/10 · Must read/watchNVDvuln
Summary
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CVECVE-2024-21400
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 12 · 05:15 PM CDT
ModifiedMon, Sep 14 · 01:44 PM CDT
Sun, May 19 · 09:15 AM CDTCVE-2024-35887
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: ax25: fix use-after-free bugs caused by ax25_ds_del_timer When the ax25 device is detaching, the ax25_dev_device_down() calls ax25_ds_del_timer() to cleanup the slave_timer. When the timer handler is running, the ax25_ds_del_timer() that calls del_time
CVECVE-2024-35887
SeverityHIGH
TypeUPDATED
PublishedSun, May 19 · 09:15 AM CDT
ModifiedMon, Sep 14 · 12:17 PM CDT
Mon, Jul 29 · 03:15 PM CDTCVE-2024-41062
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: bluetooth/l2cap: sync sock recv cb and release The problem occurs between the system call to close the sock and hci_rx_work, where the former releases the sock and the latter accesses it without lock protection. CPU0 CPU1 ---- ---- sock_close hci_rx_wo
CVECVE-2024-41062
SeverityHIGH
TypeUPDATED
PublishedMon, Jul 29 · 03:15 PM CDT
ModifiedMon, Sep 14 · 12:17 PM CDT
Mon, Oct 21 · 08:15 PM CDTCVE-2024-50029
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync This checks if the ACL connection remains valid as it could be destroyed while hci_enhanced_setup_sync is pending on cmd_sync leading to the following trace: BUG: KASAN: slab-use-after-free in hci
CVECVE-2024-50029
SeverityHIGH
TypeUPDATED
PublishedMon, Oct 21 · 08:15 PM CDT
ModifiedMon, Sep 14 · 12:17 PM CDT
Thu, Feb 19 · 07:17 AM CSTCVE-2025-12821
8.8/10 · Worth your timeNVDvuln
Summary
The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.5.9. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files and achieve remot
CVECVE-2025-12821
SeverityHIGH
TypeUPDATED
PublishedThu, Feb 19 · 07:17 AM CST
ModifiedMon, Sep 14 · 11:17 PM CDT
Wed, Apr 16 · 03:15 PM CDTCVE-2025-22039
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was originally typed as int and used in an unchecked addition, which could overflow and bypass the existing bounds check in both smb_check_perm_dacl() and smb_inherit_dacl(). This coul
CVECVE-2025-22039
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 16 · 03:15 PM CDT
ModifiedMon, Sep 14 · 12:17 PM CDT
Fri, Sep 19 · 04:15 PM CDTCVE-2025-39862
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix list corruption after hardware restart Since stations are recreated from scratch, all lists that wcids are added to must be cleared before calling ieee80211_restart_hw. Set wcid->sta = 0 for each wcid entry in order to ensure th
CVECVE-2025-39862
SeverityHIGH
TypeUPDATED
PublishedFri, Sep 19 · 04:15 PM CDT
ModifiedMon, Sep 14 · 12:17 PM CDT
Wed, Mar 25 · 06:16 PM CDTCVE-2025-67030
8.8/10 · Worth your timeNVDvuln
Summary
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
CVECVE-2025-67030
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 25 · 06:16 PM CDT
ModifiedMon, Sep 14 · 01:17 PM CDT
Wed, Apr 08 · 02:16 AM CDTCVE-2026-33810
8.2/10 · Worth your timeNVDvuln
Summary
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in th
CVECVE-2026-33810
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedMon, Sep 14 · 01:18 PM CDT
Tue, Mar 04 · 04:15 PM CSTCVE-2025-23368
8.1/10 · Worth your timeNVDvuln
Summary
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
CVECVE-2025-23368
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 04 · 04:15 PM CST
ModifiedMon, Sep 14 · 10:16 PM CDT
Thu, Mar 05 · 07:16 PM CSTCVE-2026-3009
8.1/10 · Worth your timeNVDvuln
Summary
A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restrictio
CVECVE-2026-3009
SeverityHIGH
TypeUPDATED
PublishedThu, Mar 05 · 07:16 PM CST
ModifiedMon, Sep 14 · 01:18 PM CDT
Fri, May 22 · 02:16 PM CDTCVE-2026-9277
8.1/10 · Worth your timeNVDvuln
Summary
shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.op` therefore passed throu
CVECVE-2026-9277
SeverityHIGH
TypeUPDATED
PublishedFri, May 22 · 02:16 PM CDT
ModifiedMon, Sep 14 · 01:19 PM CDT
Thu, Feb 26 · 01:16 AM CSTCVE-2026-27830
8.0/10 · Worth your timeNVDvuln
Summary
c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map >`. Prior to v0.12.0, that
CVECVE-2026-27830
SeverityHIGH
TypeUPDATED
PublishedThu, Feb 26 · 01:16 AM CST
ModifiedMon, Sep 14 · 01:17 PM CDT
Wed, May 27 · 11:16 AM CDTCVE-2026-3012
8.0/10 · Worth your timeNVDvuln
Summary
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect
CVECVE-2026-3012
SeverityHIGH
TypeUPDATED
PublishedWed, May 27 · 11:16 AM CDT
ModifiedMon, Sep 14 · 01:18 PM CDT
Thu, Jul 01 · 03:15 AM CDTCVE-2021-36081
7.8/10 · Worth your timeNVDvuln
Summary
Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.
CVECVE-2021-36081
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 01 · 03:15 AM CDT
ModifiedMon, Sep 14 · 02:14 PM CDT