Tue, May 26 · 02:16 PM CDTCVE-2026-7374
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container r
CVECVE-2026-7374
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 26 · 02:16 PM CDT
ModifiedSun, Aug 09 · 06:16 PM CDT
Sun, Aug 09 · 11:16 AM CDTCVE-2026-19348
9.8/10 · Must read/watchNVDvuln
Summary
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may
CVECVE-2026-19348
SeverityCRITICAL
TypeNEW
PublishedSun, Aug 09 · 11:16 AM CDT
ModifiedSun, Aug 09 · 11:16 AM CDT
Sun, Jul 19 · 04:17 PM CDTCVE-2026-63978
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: net/handshake: Drain pending requests at net namespace exit The arguments to list_splice_init() in handshake_net_exit() are reversed. The call moves the local empty "requests" list onto hn->hn_requests, leaving the local list empty, so the subsequent d
CVECVE-2026-63978
SeverityCRITICAL
TypeUPDATED
PublishedSun, Jul 19 · 04:17 PM CDT
ModifiedSun, Aug 09 · 07:17 PM CDT
Sun, Jul 19 · 04:17 PM CDTCVE-2026-63979
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: net/handshake: hand off the pinned file reference to accept_doit handshake_req_next() removes the request from the per-net pending list and drops hn_lock before handshake_nl_accept_doit() reads req->hr_sk->sk_socket and dereferences sock->file (once in
CVECVE-2026-63979
SeverityCRITICAL
TypeUPDATED
PublishedSun, Jul 19 · 04:17 PM CDT
ModifiedSun, Aug 09 · 07:17 PM CDT
Sat, Jul 25 · 10:17 AM CDTCVE-2026-64523
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-lived file reference at submit handshake_nl_accept_doit() needs the file pointer backing req->hr_sk->sk_socket to survive the window between handshake_req_next() and the subsequent FD_PREPARE() and get_file(). The submit-side
CVECVE-2026-64523
SeverityCRITICAL
TypeUPDATED
PublishedSat, Jul 25 · 10:17 AM CDT
ModifiedSun, Aug 09 · 07:17 PM CDT
Mon, Jul 20 · 08:16 AM CDTCVE-2026-16242
9.4/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could co
CVECVE-2026-16242
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jul 20 · 08:16 AM CDT
ModifiedSun, Aug 09 · 04:16 PM CDT
Wed, May 06 · 12:16 PM CDTCVE-2026-43197
9.1/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated. Before recent commit 7eab73b18630 ("netconsole: convert to NBCON console infrastructure") the message wou
CVECVE-2026-43197
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 06 · 12:16 PM CDT
ModifiedSun, Aug 09 · 07:17 PM CDT
Tue, Aug 04 · 12:17 AM CDTCVE-2026-62870
8.8/10 · Worth your timeNVDvuln
Summary
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
CVECVE-2026-62870
SeverityHIGH
TypeUPDATED
PublishedTue, Aug 04 · 12:17 AM CDT
ModifiedSun, Aug 09 · 02:32 PM CDT
Thu, Aug 06 · 08:16 AM CDTCVE-2026-64586
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device removal brcmf_fw_crashed() and the debugfs "reset" entry both schedule drvr->bus_reset, whose callback recovers drvr through container_of() and dereferences it. The removal path frees drvr (brcmf_free -> w
CVECVE-2026-64586
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 06 · 08:16 AM CDT
ModifiedSun, Aug 09 · 07:17 PM CDT
Fri, Jul 24 · 07:16 PM CDTCVE-2026-17107
8.5/10 · Worth your timeNVDvuln
Summary
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unre
CVECVE-2026-17107
SeverityHIGH
TypeUPDATED
PublishedFri, Jul 24 · 07:16 PM CDT
ModifiedSun, Aug 09 · 04:16 PM CDT
Mon, Aug 03 · 10:16 PM CDTCVE-2026-10849
8.2/10 · Worth your timeNVDvuln
Summary
The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL. When the full response ha
CVECVE-2026-10849
SeverityHIGH
TypeUPDATED
PublishedMon, Aug 03 · 10:16 PM CDT
ModifiedSun, Aug 09 · 02:41 PM CDT
Thu, Jul 16 · 01:16 AM CDTCVE-2026-1609
8.1/10 · Worth your timeNVDvuln
Summary
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulne
CVECVE-2026-1609
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 16 · 01:16 AM CDT
ModifiedSun, Aug 09 · 03:10 PM CDT
Tue, Jun 17 · 01:15 PM CDTCVE-2025-6020
7.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
CVECVE-2025-6020
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 17 · 01:15 PM CDT
ModifiedSun, Aug 09 · 06:16 PM CDT
Mon, Aug 10 · 01:16 AM CDTCVE-2026-19381
7.8/10 · Worth your timeNVDvuln
Summary
A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege management. The attack needs to be approached locally. The exploit has bee
CVECVE-2026-19381
SeverityHIGH
TypeNEW
PublishedMon, Aug 10 · 01:16 AM CDT
ModifiedMon, Aug 10 · 01:16 AM CDT
Tue, Aug 04 · 07:16 AM CDTCVE-2026-64563
7.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-validates iter->p against the table and sets iter->p = NULL if the object is gone. When ite
CVECVE-2026-64563
SeverityHIGH
TypeUPDATED
PublishedTue, Aug 04 · 07:16 AM CDT
ModifiedSun, Aug 09 · 07:17 PM CDT
Thu, May 28 · 09:16 AM CDTCVE-2026-9804
7.7/10 · Worth your timeNVDvuln
Summary
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated
CVECVE-2026-9804
SeverityHIGH
TypeUPDATED
PublishedThu, May 28 · 09:16 AM CDT
ModifiedSun, Aug 09 · 06:16 PM CDT
Mon, Aug 10 · 03:16 AM CDTCVE-2026-19387
7.6/10 · Worth your timeNVDvuln
Summary
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to applicati
CVECVE-2026-19387
SeverityHIGH
TypeNEW
PublishedMon, Aug 10 · 03:16 AM CDT
ModifiedMon, Aug 10 · 03:16 AM CDT
Tue, Jun 30 · 07:16 AM CDTCVE-2026-14164
7.5/10 · Worth your timeNVDvuln
Summary
A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region
CVECVE-2026-14164
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 30 · 07:16 AM CDT
ModifiedMon, Aug 10 · 10:17 AM CDT
Mon, Apr 27 · 09:16 PM CDTCVE-2026-3087
7.5/10 · Worth your timeNVDvuln
Summary
If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.
CVECVE-2026-3087
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 27 · 09:16 PM CDT
ModifiedMon, Aug 10 · 01:16 AM CDT
Sun, Aug 09 · 12:16 PM CDTCVE-2026-19351
7.3/10 · Worth your timeNVDvuln
Summary
A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the
CVECVE-2026-19351
SeverityHIGH
TypeNEW
PublishedSun, Aug 09 · 12:16 PM CDT
ModifiedSun, Aug 09 · 12:16 PM CDT
Sun, Aug 09 · 02:17 PM CDTCVE-2026-19355
7.3/10 · Worth your timeNVDvuln
Summary
A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has been
CVECVE-2026-19355
SeverityHIGH
TypeNEW
PublishedSun, Aug 09 · 02:17 PM CDT
ModifiedSun, Aug 09 · 02:17 PM CDT
Sun, Aug 09 · 11:16 PM CDTCVE-2026-19374
7.3/10 · Worth your timeNVDvuln
Summary
A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack is possible to
CVECVE-2026-19374
SeverityHIGH
TypeNEW
PublishedSun, Aug 09 · 11:16 PM CDT
ModifiedSun, Aug 09 · 11:16 PM CDT
Mon, Aug 10 · 12:17 AM CDTCVE-2026-19376
7.3/10 · Worth your timeNVDvuln
Summary
A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and m
CVECVE-2026-19376
SeverityHIGH
TypeNEW
PublishedMon, Aug 10 · 12:17 AM CDT
ModifiedMon, Aug 10 · 12:17 AM CDT
Mon, Aug 10 · 01:16 AM CDTCVE-2026-19379
7.3/10 · Worth your timeNVDvuln
Summary
A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The v
CVECVE-2026-19379
SeverityHIGH
TypeNEW
PublishedMon, Aug 10 · 01:16 AM CDT
ModifiedMon, Aug 10 · 01:16 AM CDT
Mon, Aug 10 · 03:16 AM CDTCVE-2026-19384
7.3/10 · Worth your timeNVDvuln
Summary
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to
CVECVE-2026-19384
SeverityHIGH
TypeNEW
PublishedMon, Aug 10 · 03:16 AM CDT
ModifiedMon, Aug 10 · 03:16 AM CDT