0.0

CVE-2026-42509 - Apache Wicket: crafted strings can break out of the JavaScript sequence

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes the issue.

📅 Published: May 6, 2026, 8:34 a.m. 🔄 Last Modified: May 6, 2026, 8:34 a.m.

0.0

CVE-2026-43646 - Apache Wicket: crafted URLs can bypass PackageResourceGuard

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes the issue.

📅 Published: May 6, 2026, 8:31 a.m. 🔄 Last Modified: May 6, 2026, 8:31 a.m.

0.0

CVE-2026-43975 - Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager

FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to write arbitrary files outside the intended upload directory or read files from arbitrary locations on …

📅 Published: May 6, 2026, 8:28 a.m. 🔄 Last Modified: May 6, 2026, 8:28 a.m.

6.6

CVSS3.1

CVE-2026-35255 -

Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is affected is v2.3.2. Easily exploitable vulnerability allows unauthenticated attacker to compromise Oracle Cloud Native Environment Command Line Interfac…

📅 Published: May 6, 2026, 8:05 a.m. 🔄 Last Modified: May 6, 2026, 8:05 a.m.

0.0

CVE-2026-43120 - RDMA/irdma: Fix double free related to rereg_user_mr

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix double free related to rereg_user_mr If IB_MR_REREG_TRANS is set during rereg_user_mr, the umem will be released and a new one will be allocated in irdma_rereg_mr_trans. If any step of irdma_rereg_mr_trans fails a…

📅 Published: May 6, 2026, 7:40 a.m. 🔄 Last Modified: May 6, 2026, 7:40 a.m.

0.0

CVE-2026-43119 - Bluetooth: hci_sync: annotate data-races around hdev->req_status

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: annotate data-races around hdev->req_status __hci_cmd_sync_sk() sets hdev->req_status under hdev->req_lock: hdev->req_status = HCI_REQ_PEND; However, several other functions read or write hdev->req_stat…

📅 Published: May 6, 2026, 7:40 a.m. 🔄 Last Modified: May 6, 2026, 7:40 a.m.

0.0

CVE-2026-43118 - btrfs: fix zero size inode with non-zero size after log replay

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix zero size inode with non-zero size after log replay When logging that an inode exists, as part of logging a new name or logging new dir entries for a directory, we always set the generation of the logged inode item to …

📅 Published: May 6, 2026, 7:40 a.m. 🔄 Last Modified: May 6, 2026, 7:40 a.m.

0.0

CVE-2026-43117 - btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file()

In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() If overlay is used on top of btrfs, dentry->d_sb translates to overlay's super block and fsid assignment will lead to a crash. Use file_inode(file…

📅 Published: May 6, 2026, 7:40 a.m. 🔄 Last Modified: May 6, 2026, 7:40 a.m.

0.0

CVE-2026-43116 - netfilter: ctnetlink: ensure safe access to master conntrack

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference on the expectation is not sufficient, the master conntrack object can just go away, making exp->master invalid. To access exp->master safely: - Grab…

📅 Published: May 6, 2026, 7:40 a.m. 🔄 Last Modified: May 6, 2026, 7:40 a.m.

0.0

CVE-2026-43115 - srcu: Use irq_work to start GP in tiny SRCU

In the Linux kernel, the following vulnerability has been resolved: srcu: Use irq_work to start GP in tiny SRCU Tiny SRCU's srcu_gp_start_if_needed() directly calls schedule_work(), which acquires the workqueue pool->lock. This causes a lockdep splat when call_srcu() is called with a scheduler l…

📅 Published: May 6, 2026, 7:40 a.m. 🔄 Last Modified: May 6, 2026, 7:40 a.m.
Total resulsts: 348208
Page 2 of 34,821
« previous page » next page
Filters