7.8

CVSS3.1

CVE-2026-23413 - clsact: Fix use-after-free in init/destroy rollback asymmetry

In the Linux kernel, the following vulnerability has been resolved: clsact: Fix use-after-free in init/destroy rollback asymmetry Fix a use-after-free in the clsact qdisc upon init/destroy rollback asymmetry. The latter is achieved by first fully initializing a clsact instance, and then in a seco…

📅 Published: April 2, 2026, midnight 🔄 Last Modified: April 24, 2026, 3:22 p.m.

6.1

CVSS3.1

CVE-2026-30251 - Reflected XSS via injected codice_azienda in ZenShare Suite login endpoint

A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.

📅 Published: April 2, 2026, midnight 🔄 Last Modified: April 9, 2026, 8:29 a.m.

9.8

CVSS3.1

CVE-2026-34877 -

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused …

📅 Published: April 2, 2026, midnight 🔄 Last Modified: April 7, 2026, 7:56 a.m.

5.3

CVSS3.1

CVE-2026-26895 -

User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.

📅 Published: April 2, 2026, midnight 🔄 Last Modified: April 8, 2026, 7:56 p.m.

5.5

CVSS3.1

CVE-2026-23417 - bpf: Fix constant blinding for PROBE_MEM32 stores

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix constant blinding for PROBE_MEM32 stores BPF_ST | BPF_PROBE_MEM32 immediate stores are not handled by bpf_jit_blind_insn(), allowing user-controlled 32-bit immediates to survive unblinded into JIT-compiled native code wh…

📅 Published: April 2, 2026, midnight 🔄 Last Modified: April 24, 2026, 3:21 p.m.

5.5

CVSS3.1

CVE-2026-23416 - mm/mseal: update VMA end correctly on merge

In the Linux kernel, the following vulnerability has been resolved: mm/mseal: update VMA end correctly on merge Previously we stored the end of the current VMA in curr_end, and then upon iterating to the next VMA updated curr_start to curr_end to advance to the next VMA. However, this doesn't ta…

📅 Published: April 2, 2026, midnight 🔄 Last Modified: April 24, 2026, 3:21 p.m.

7.5

CVSS3.1

CVE-2026-23414 - tls: Purge async_hold in tls_decrypt_async_wait()

In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() The async_hold queue pins encrypted input skbs while the AEAD engine references their scatterlist data. Once tls_decrypt_async_wait() returns, every AEAD operation has completed a…

📅 Published: April 2, 2026, midnight 🔄 Last Modified: April 27, 2026, 2:02 p.m.

7.8

CVSS3.1

CVE-2026-23412 - netfilter: bpf: defer hook memory release until rcu readers are done

In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu readers are done Yiming Qian reports UaF when concurrent process is dumping hooks via nfnetlink_hooks: BUG: KASAN: slab-use-after-free in nfnl_hook_dump_one.isra.0+0xe71/0x10f0…

📅 Published: April 2, 2026, midnight 🔄 Last Modified: April 24, 2026, 3:23 p.m.

7.5

CVSS3.1

CVE-2026-30332 - Time‑of‑Check to Time‑of‑Use Race Condition in Balena Etcher Allows Privilege Escalation

A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows attackers to escalate privileges and execute arbitrary code via replacing a legitimate script with a crafted payload during the flashing process.

📅 Published: April 2, 2026, midnight 🔄 Last Modified: April 3, 2026, 4:10 p.m.

4

CVSS3.1

CVE-2026-21767 - HCL BigFix Platform is affected by insufficient authentication

HCL BigFix Platform is affected by insufficient authentication.  The application might allow users to access sensitive areas of the application without proper authentication.

📅 Published: April 1, 2026, 11:47 p.m. 🔄 Last Modified: April 16, 2026, 4:05 p.m.
Total resulsts: 349182
Page 742 of 34,919
« previous page » next page
Filters