5.5

CVSS3.1

CVE-2026-23021 - net: usb: pegasus: fix memory leak in update_eth_regs_async()

In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: fix memory leak in update_eth_regs_async() When asynchronously writing to the device registers and if usb_submit_urb() fail, the code fail to release allocated to this point resources.

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 1 a.m.

7.8

CVSS3.1

CVE-2026-23025 - mm/page_alloc: prevent pcp corruption with SMP=n

In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: prevent pcp corruption with SMP=n The kernel test robot has reported: BUG: spinlock trylock failure on UP on CPU#0, kcompactd0/28 lock: 0xffff888807e35ef0, .magic: dead4ead, .owner: kcompactd0/28, .owner_cpu: 0…

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 2:30 p.m.

5.5

CVSS3.1

CVE-2026-23022 - idpf: fix memory leak in idpf_vc_core_deinit()

In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leak in idpf_vc_core_deinit() Make sure to free hw->lan_regs. Reported by kmemleak during reset: unreferenced object 0xff1b913d02a936c0 (size 96): comm "kworker/u258:14", pid 2174, jiffies 4294958305 hex dum…

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 2:30 p.m.

5.5

CVSS3.1

CVE-2026-23020 - net: 3com: 3c59x: fix possible null dereference in vortex_probe1()

In the Linux kernel, the following vulnerability has been resolved: net: 3com: 3c59x: fix possible null dereference in vortex_probe1() pdev can be null and free_ring: can be called in 1297 with a null pdev.

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 2:30 p.m.

0.0

CVE-2026-23034 - drm/amdgpu/userq: Fix fence reference leak on queue teardown v2

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: Fix fence reference leak on queue teardown v2 The user mode queue keeps a pointer to the most recent fence in userq->last_fence. This pointer holds an extra dma_fence reference. When the queue is destroyed, we …

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 6:45 p.m.

0.0

CVE-2026-23027 - LoongArch: KVM: Fix kvm_device leak in kvm_pch_pic_destroy()

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix kvm_device leak in kvm_pch_pic_destroy() In kvm_ioctl_create_device(), kvm_device has allocated memory, kvm_device->destroy() seems to be supposed to free its kvm_device struct, but kvm_pch_pic_destroy() is no…

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 6:45 p.m.

5.5

CVSS3.1

CVE-2025-71187 - dmaengine: sh: rz-dmac: fix device leak on probe failure

In the Linux kernel, the following vulnerability has been resolved: dmaengine: sh: rz-dmac: fix device leak on probe failure Make sure to drop the reference taken when looking up the ICU device during probe also on probe failures (e.g. probe deferral).

πŸ“… Published: Jan. 31, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 6:43 p.m.

7.3

CVSS3.1

CVE-2026-25156 - HotCRP vulnerable to stored XSS via comment attachments

HotCRP is conference review software. HotCRP versions from October 2025 through January 2026 delivered documents of all types with inline Content-Disposition, causing them to be rendered in the user’s browser rather than downloaded. (The intended behavior was for only `text/plain`, `application/pdf…

πŸ“… Published: Jan. 30, 2026, 10:11 p.m. πŸ”„ Last Modified: April 18, 2026, 2:30 p.m.

8.8

CVSS4.0

CVE-2020-37057 - Online-Exam-System 2015 - 'fid' SQL Injection

Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through the 'fid' parameter. Attackers can inject malicious SQL code into the 'fid' parameter to potentially extract, modify, or delete database information.

πŸ“… Published: Jan. 30, 2026, 10:07 p.m. πŸ”„ Last Modified: March 12, 2026, 6:50 p.m.

6.9

CVSS4.0

CVE-2020-37056 - Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass

Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-IP, and X-Real-IP headers to circumvent security checks and g…

πŸ“… Published: Jan. 30, 2026, 10:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347407
Page 1698 of 34,741
Β« previous page Β» next page
Filters