7.1

CVSS3.1

CVE-2026-23269 - apparmor: validate DFA start states are in bounds in unpack_pdb

In the Linux kernel, the following vulnerability has been resolved: apparmor: validate DFA start states are in bounds in unpack_pdb Start states are read from untrusted data and used as indexes into the DFA state tables. The aa_dfa_next() function call in unpack_pdb() will access dfa->tables[YYTD…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

7.8

CVSS3.1

CVE-2026-23268 - apparmor: fix unprivileged local user can do privileged policy management

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unprivileged local user can do privileged policy management An unprivileged local user can load, replace, and remove profiles by opening the apparmorfs interfaces, via a confused deputy attack, by passing the opened…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

9.1

CVSS3.1

CVE-2026-30704 - Unprotected UART Interface in Yeapook WDR201A WiFi Extender (CVE-2026-30704)

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 24, 2026, 10:53 a.m.

0.0

CVE-2026-23265 - f2fs: fix to do sanity check on node footer in {read,write}_end_io

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node footer in {read,write}_end_io -----------[ cut here ]------------ kernel BUG at fs/f2fs/data.c:358! Call Trace: <IRQ> blk_update_request+0x5eb/0xe70 block/blk-mq.c:987 blk_mq_end_request+0x…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.

7.0

CVSS3.1

CVE-2026-23262 - gve: Fix stats report corruption on queue count change

In the Linux kernel, the following vulnerability has been resolved: gve: Fix stats report corruption on queue count change The driver and the NIC share a region in memory for stats reporting. The NIC calculates its offset into this region based on the total size of the stats region and the size o…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 29, 2026, 8:28 p.m.

8.8

CVSS3.1

CVE-2025-55040 - CSRF Upload Exploit Enables Malicious Form Installation in MuraCMS

The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function lacks CSRF token validation, enabling malicious websites to forge file upload requests that install attacke…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

5.5

CVSS3.1

CVE-2026-23257 - net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup

In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup In setup_nic_devices(), the initialization loop jumps to the label setup_nic_dev_free on failure. The current cleanup loop while(i--) skip the failing index i,…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 3:48 p.m.

9.1

CVSS3.1

CVE-2026-30701 -

The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of Server Side Include) within multiple server-side web pages, including login.shtml and settings.shtml. These pages embed server-side execution directive…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

7.0

CVSS3.1

CVE-2025-71269 - btrfs: do not free data reservation in fallback from inline due to -ENOSPC

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallback from inline due to -ENOSPC If we fail to create an inline extent due to -ENOSPC, we will attempt to go through the normal COW path, reserve an extent, create an ordered extent, etc.…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 11, 2026, 1:16 p.m.

8.8

CVSS3.1

CVE-2026-4446 - chromium-browser: Use after free in WebRTC

Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 2:10 p.m.
Total resulsts: 348208
Page 978 of 34,821
Β« previous page Β» next page
Filters