CVEs — Hardware & Firmware Vulnerabilities
460 vulnerabilities from NVD.
| CVE ID | Description | Severity | CVSS | Date |
|---|---|---|---|---|
| CVE-2025-6599 | An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C... | MEDIUM | 5.3 | 2025-11-18 |
| CVE-2025-8693 | A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(A... | HIGH | 8.8 | 2025-11-18 |
| CVE-2025-8404 | Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access t... | MEDIUM | 5.5 | 2025-11-18 |
| CVE-2025-63225 | The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing au... | CRITICAL | 9.8 | 2025-11-18 |
| CVE-2025-63209 | The ELCA Star Transmitter Remote Control firmware 1.25 for STAR150, BP1000, STAR300, STAR2000, STAR1000, STAR500, and po... | HIGH | 7.5 | 2025-11-19 |
| CVE-2025-63211 | Stored cross-site scripting vulnerability in bridgetech VBC Server & Element Manager, firmware versions 6.5.0-9 thru 6.5... | MEDIUM | 6.1 | 2025-11-19 |
| CVE-2025-60737 | Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_0... | MEDIUM | 6.1 | 2025-11-20 |
| CVE-2025-44018 | A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially craft... | HIGH | 8.3 | 2025-11-24 |
| CVE-2025-12003 | A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact... | 0 | 2025-11-25 | |
| CVE-2025-59365 | A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigge... | 0 | 2025-11-25 | |
| CVE-2025-59366 | An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effe... | 0 | 2025-11-25 | |
| CVE-2025-59368 | An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerabil... | 0 | 2025-11-25 | |
| CVE-2025-59369 | A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnera... | 0 | 2025-11-25 | |
| CVE-2025-59370 | A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vul... | 0 | 2025-11-25 | |
| CVE-2025-59371 | An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated att... | 0 | 2025-11-25 | |
| CVE-2025-59372 | A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could expl... | 0 | 2025-11-25 | |
| CVE-2025-60739 | Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logi... | CRITICAL | 9.6 | 2025-11-25 |
| CVE-2025-33189 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A... | HIGH | 7.8 | 2025-11-25 |
| CVE-2025-33190 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A ... | MEDIUM | 6.7 | 2025-11-25 |
| CVE-2025-33191 | NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read.... | MEDIUM | 5.7 | 2025-11-25 |
| CVE-2025-33192 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an arbitrary memory read... | MEDIUM | 5.7 | 2025-11-25 |
| CVE-2025-33193 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper validation of i... | MEDIUM | 5.7 | 2025-11-25 |
| CVE-2025-33194 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of i... | MEDIUM | 5.7 | 2025-11-25 |
| CVE-2025-33195 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer... | MEDIUM | 4.4 | 2025-11-25 |
| CVE-2025-33196 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.... | MEDIUM | 4.4 | 2025-11-25 |
| CVE-2025-33197 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereferen... | MEDIUM | 4.3 | 2025-11-25 |
| CVE-2025-33198 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.... | LOW | 3.3 | 2025-11-25 |
| CVE-2025-33199 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow b... | LOW | 3.2 | 2025-11-25 |
| CVE-2025-33200 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.... | LOW | 2.3 | 2025-11-25 |
| CVE-2025-64983 | Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attac... | HIGH | 8 | 2025-11-26 |
| CVE-2025-8890 | Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell comman... | 0 | 2025-11-27 | |
| CVE-2025-34319 | TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contai... | 0 | 2025-12-03 | |
| CVE-2025-40226 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Account for failed debug initia... | 0 | 2025-12-04 | |
| CVE-2025-40321 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix crash while sending Action Fram... | 0 | 2025-12-08 | |
| CVE-2025-40938 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive inf... | HIGH | 8.1 | 2025-12-09 |
| CVE-2024-58314 | Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web confi... | HIGH | 8.8 | 2025-12-12 |
| CVE-2025-68236 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: ufs-qcom: Fix UFS OCP issue during UFS p... | 0 | 2025-12-16 | |
| CVE-2023-53896 | D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attacke... | HIGH | 7.5 | 2025-12-16 |
| CVE-2025-11901 | An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760... | 0 | 2025-12-17 | |
| CVE-2025-10910 | A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online... | 0 | 2025-12-18 | |
| CVE-2025-14884 | A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the com... | HIGH | 7.2 | 2025-12-18 |
| CVE-2025-14910 | A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon... | MEDIUM | 4.3 | 2025-12-19 |
| CVE-2025-11543 | Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may c... | CRITICAL | 9.8 | 2025-12-22 |
| CVE-2025-11544 | Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may c... | 0 | 2025-12-22 | |
| CVE-2025-68328 | In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix bug in saving controll... | 0 | 2025-12-22 | |
| CVE-2023-53967 | Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the ... | HIGH | 7.5 | 2025-12-22 |
| CVE-2023-53968 | Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authenti... | CRITICAL | 9.8 | 2025-12-22 |
| CVE-2023-53969 | Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authenti... | HIGH | 7.5 | 2025-12-22 |
| CVE-2023-53970 | Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass aut... | HIGH | 7.5 | 2025-12-22 |
| CVE-2025-65856 | Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.... | CRITICAL | 9.8 | 2025-12-22 |
| CVE-2022-50700 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: Delay the unmapping of the buffer On... | 0 | 2025-12-24 | |
| CVE-2023-54027 | In the Linux kernel, the following vulnerability has been resolved: iio: core: Prevent invalid memory access when there... | 0 | 2025-12-24 | |
| CVE-2025-68380 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix peer HE MCS assignment In ath11k... | 0 | 2025-12-24 | |
| CVE-2022-50763 | In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - prevent integer overflow... | 0 | 2025-12-24 | |
| CVE-2023-54058 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Check if ffa_driver remove is pr... | 0 | 2025-12-24 | |
| CVE-2023-54098 | In the Linux kernel, the following vulnerability has been resolved: drm/i915/gvt: fix gvt debugfs destroy When gvt deb... | 0 | 2025-12-24 | |
| CVE-2023-54129 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Add validation for lmac type Upon ph... | 0 | 2025-12-24 | |
| CVE-2023-54133 | In the Linux kernel, the following vulnerability has been resolved: nfp: clean mc addresses in application firmware whe... | 0 | 2025-12-24 | |
| CVE-2023-54150 | In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix an out of bounds error in BIOS parser ... | 0 | 2025-12-24 | |
| CVE-2023-54160 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_sdei: Fix sleep from invalid context ... | 0 | 2025-12-24 | |
| CVE-2025-52600 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... | HIGH | 7.2 | 2025-12-26 |
| CVE-2025-52601 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... | HIGH | 7.8 | 2025-12-26 |
| CVE-2025-8075 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... | MEDIUM | 5.4 | 2025-12-26 |
| CVE-2025-15245 | A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware ... | LOW | 3.5 | 2025-12-30 |
| CVE-2022-50880 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: add peer map clean up for peer delete... | 0 | 2025-12-30 | |
| CVE-2023-54234 | In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix missing mrioc->evtack_cmds initia... | 0 | 2025-12-30 | |
| CVE-2023-54279 | In the Linux kernel, the following vulnerability has been resolved: MIPS: fw: Allow firmware to pass a empty env fw_ge... | 0 | 2025-12-30 | |
| CVE-2023-54304 | In the Linux kernel, the following vulnerability has been resolved: firmware: meson_sm: fix to avoid potential NULL poi... | 0 | 2025-12-30 | |
| CVE-2023-54325 | In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix out-of-bounds read When preparin... | 0 | 2025-12-30 | |
| CVE-2025-15256 | A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /gofo... | HIGH | 7.3 | 2025-12-30 |
| CVE-2025-15257 | A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRo... | HIGH | 7.3 | 2025-12-30 |
| CVE-2025-15258 | A weakness has been identified in Edimax BR-6208AC 1.02/1.03. Affected by this issue is the function formALGSetup of the... | LOW | 3.5 | 2025-12-30 |
| CVE-2022-50796 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware uplo... | CRITICAL | 9.8 | 2025-12-30 |
| CVE-2021-47745 | Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script... | HIGH | 8.8 | 2025-12-31 |
| CVE-2025-15474 | AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticate... | 0 | 2026-01-07 | |
| CVE-2017-20212 | FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows una... | MEDIUM | 6.2 | 2026-01-08 |
| CVE-2017-20213 | FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows rem... | HIGH | 7.5 | 2026-01-08 |
| CVE-2017-20215 | FLIR Thermal Camera FC-S/PT firmware version 8.0.0.64 contains an authenticated OS command injection vulnerability that ... | HIGH | 8.8 | 2026-01-08 |
| CVE-2025-67089 | A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present ... | HIGH | 8.1 | 2026-01-08 |
| CVE-2025-7072 | The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all route... | 0 | 2026-01-09 | |
| CVE-2025-68812 | In the Linux kernel, the following vulnerability has been resolved: media: iris: Add sanity check for stop streaming A... | 0 | 2026-01-13 | |
| CVE-2025-68816 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, Validate format string paramet... | 0 | 2026-01-13 | |
| CVE-2025-68707 | An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated ne... | HIGH | 8.8 | 2026-01-13 |
| CVE-2022-50926 | WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipula... | CRITICAL | 9.8 | 2026-01-13 |
| CVE-2025-65396 | A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically prox... | MEDIUM | 6.1 | 2026-01-14 |
| CVE-2026-21912 | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statist... | MEDIUM | 5.5 | 2026-01-15 |
| CVE-2025-12006 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can up... | HIGH | 7.2 | 2026-01-16 |
| CVE-2025-12007 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can up... | HIGH | 8.4 | 2026-01-16 |
| CVE-2026-1221 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowi... | CRITICAL | 9.8 | 2026-01-20 |
| CVE-2026-23699 | AP180 series with firmware versions prior to AP_RGOS 11.9(4)B1P8 contains an OS command injection vulnerability. If this... | HIGH | 7.2 | 2026-01-22 |
| CVE-2025-64097 | NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vu... | CRITICAL | 9.8 | 2026-01-22 |
| CVE-2026-22981 | In the Linux kernel, the following vulnerability has been resolved: idpf: detach and close netdevs while handling a res... | MEDIUM | 5.5 | 2026-01-23 |
| CVE-2026-24433 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cross-site scripting vul... | MEDIUM | 5.4 | 2026-01-26 |
| CVE-2025-14756 | Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing... | HIGH | 8.8 | 2026-01-26 |
| CVE-2020-36963 | Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthentica... | HIGH | 7.5 | 2026-01-28 |
| CVE-2026-24426 | Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the w... | MEDIUM | 6.1 | 2026-02-03 |
| CVE-2025-70545 | A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X r... | MEDIUM | 6.1 | 2026-02-04 |
| CVE-2026-23059 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Sanitize payload size to prevent mem... | 0 | 2026-02-04 | |
| CVE-2026-23070 | In the Linux kernel, the following vulnerability has been resolved: Octeontx2-af: Add proper checks for fwdata firmwar... | 0 | 2026-02-04 | |
| CVE-2026-23084 | In the Linux kernel, the following vulnerability has been resolved: be2net: Fix NULL pointer dereference in be_cmd_get_... | 0 | 2026-02-04 | |
| CVE-2025-11730 | A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP s... | HIGH | 7.2 | 2026-02-05 |
| CVE-2026-25857 | Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagn... | HIGH | 8.8 | 2026-02-07 |
| CVE-2025-20080 | Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel... | MEDIUM | 6.8 | 2026-02-10 |
| CVE-2025-22453 | Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User ... | HIGH | 7.5 | 2026-02-10 |
| CVE-2025-22885 | Improper buffer restrictions in the firmware for the TDX Module may allow an escalation of privilege. System software ad... | MEDIUM | 4.7 | 2026-02-10 |
| CVE-2025-24851 | Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x withi... | MEDIUM | 6 | 2026-02-10 |
| CVE-2025-25210 | Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User ... | HIGH | 8.2 | 2026-02-10 |
| CVE-2025-27243 | Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring... | MEDIUM | 6 | 2026-02-10 |
| CVE-2025-27535 | Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before vers... | MEDIUM | 5.3 | 2026-02-10 |
| CVE-2025-27708 | Out-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) withi... | MEDIUM | 4.1 | 2026-02-10 |
| CVE-2025-32003 | Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, c... | MEDIUM | 6.5 | 2026-02-10 |
| CVE-2025-32008 | Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applica... | HIGH | 8.6 | 2026-02-10 |
| CVE-2025-32735 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia... | MEDIUM | 5.5 | 2026-02-10 |
| CVE-2025-32739 | Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Devic... | LOW | 2.8 | 2026-02-10 |
| CVE-2025-33030 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an e... | LOW | 3.3 | 2026-02-10 |
| CVE-2025-35992 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia... | MEDIUM | 4.7 | 2026-02-10 |
| CVE-2025-35999 | Incorrect permission assignment for critical resource for some System Firmware Update Utility (SysFwUpdt) for Intel(R) S... | MEDIUM | 6.7 | 2026-02-10 |
| CVE-2026-25872 | JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the ... | MEDIUM | 5.3 | 2026-02-10 |
| CVE-2026-23172 | In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: fix potential skb->frags overflow ... | 0 | 2026-02-14 | |
| CVE-2026-23186 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (acpi_power_meter) Fix deadlocks related to ... | 0 | 2026-02-14 | |
| CVE-2026-23206 | In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: prevent ZERO_SIZE_PTR dereference whe... | 0 | 2026-02-14 | |
| CVE-2026-2566 | A security vulnerability has been detected in Wavlink WL-NU516U1 up to 130/260. This affects the function sub_406194 of ... | HIGH | 7.2 | 2026-02-16 |
| CVE-2025-11845 | A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware ve... | MEDIUM | 4.9 | 2026-02-24 |
| CVE-2025-11846 | A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions... | MEDIUM | 4.9 | 2026-02-24 |
| CVE-2025-11847 | A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions thro... | MEDIUM | 4.9 | 2026-02-24 |
| CVE-2025-11848 | A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version throu... | MEDIUM | 4.9 | 2026-02-24 |
| CVE-2025-13942 | A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C... | CRITICAL | 9.8 | 2026-02-24 |
| CVE-2025-13943 | A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware ... | HIGH | 8.8 | 2026-02-24 |
| CVE-2026-1459 | A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG362... | HIGH | 7.2 | 2026-02-24 |
| CVE-2026-23678 | Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerabilit... | HIGH | 8.8 | 2026-02-24 |
| CVE-2026-20910 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... | HIGH | 8 | 2026-02-27 |
| CVE-2026-24517 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke... | HIGH | 8 | 2026-02-27 |
| CVE-2026-24689 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker... | HIGH | 8 | 2026-02-27 |
| CVE-2026-25195 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack... | HIGH | 8 | 2026-02-27 |
| CVE-2026-1442 | Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an a... | HIGH | 7.8 | 2026-02-27 |
| CVE-2026-21660 | Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in F... | CRITICAL | 9.8 | 2026-02-27 |
| CVE-2026-27751 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remot... | CRITICAL | 9.8 | 2026-02-27 |
| CVE-2026-27753 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows re... | MEDIUM | 6.5 | 2026-02-27 |
| CVE-2026-27755 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability th... | CRITICAL | 9.8 | 2026-02-27 |
| CVE-2026-27756 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the... | MEDIUM | 6.1 | 2026-02-27 |
| CVE-2026-27757 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authentic... | HIGH | 7.1 | 2026-02-27 |
| CVE-2026-27758 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its man... | MEDIUM | 4.3 | 2026-02-27 |
| CVE-2026-3344 | A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and... | MEDIUM | 4.9 | 2026-03-03 |
| CVE-2025-69969 | A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Po... | CRITICAL | 9.6 | 2026-03-04 |
| CVE-2025-7375 | A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can... | MEDIUM | 6.5 | 2026-03-05 |
| CVE-2026-3612 | A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/... | HIGH | 7.2 | 2026-03-06 |
| CVE-2026-25070 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in... | CRITICAL | 9.8 | 2026-03-07 |
| CVE-2026-25071 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability i... | HIGH | 7.5 | 2026-03-07 |
| CVE-2026-25072 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnera... | CRITICAL | 9.8 | 2026-03-07 |
| CVE-2026-25073 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerabil... | MEDIUM | 5.4 | 2026-03-07 |
| CVE-2025-70798 | Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shado... | HIGH | 8.4 | 2026-03-10 |
| CVE-2025-70802 | Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/sh... | HIGH | 8.4 | 2026-03-10 |
| CVE-2026-28806 | Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bu... | 0 | 2026-03-10 | |
| CVE-2025-20005 | Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of priv... | 0 | 2026-03-10 | |
| CVE-2025-20096 | Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. ... | 0 | 2026-03-10 | |
| CVE-2025-20105 | Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation ... | 0 | 2026-03-10 | |
| CVE-2019-25470 | eWON Firmware versions 12.2 to 13.0 contain an authentication bypass vulnerability that allows attackers with minimal pr... | HIGH | 7.5 | 2026-03-11 |
| CVE-2025-36522 | Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3:... | MEDIUM | 6.7 | 2026-02-10 |
| CVE-2025-66646 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... | HIGH | 7.5 | 2025-12-17 |
| CVE-2025-66647 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... | CRITICAL | 9.8 | 2025-12-17 |
| CVE-2026-23833 | ESPHome is a system to control microcontrollers remotely through Home Automation systems. In versions 2025.9.0 through 2... | HIGH | 7.5 | 2026-01-19 |
| CVE-2026-25139 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... | CRITICAL | 9.1 | 2026-02-04 |
| CVE-2026-27703 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... | HIGH | 7.5 | 2026-03-11 |
| CVE-2025-66399 | Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw i... | HIGH | 8.8 | 2025-12-02 |
| CVE-2025-50681 | igmpproxy 0.4 before commit 2b30c36 allows remote attackers to cause a denial of service (application crash) via a craft... | HIGH | 7.5 | 2025-12-19 |
| CVE-2023-54047 | In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: dw_hdmi: cleanup drm encoder during u... | 0 | 2025-12-24 | |
| CVE-2022-50696 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cann... | CRITICAL | 9.8 | 2025-12-30 |
| CVE-2025-69425 | The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2... | 0 | 2026-01-09 | |
| CVE-2025-59103 | The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revis... | 0 | 2026-01-26 | |
| CVE-2025-65077 | A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devic... | 0 | 2026-02-03 | |
| CVE-2025-65078 | An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark device... | 0 | 2026-02-03 | |
| CVE-2020-37092 | Netis E1+ version 1.2.32533 contains a hardcoded root account vulnerability that allows unauthenticated attackers to acc... | HIGH | 7.5 | 2026-02-03 |
| CVE-2026-1997 | Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, poten... | MEDIUM | 5.3 | 2026-02-10 |
| CVE-2026-24455 | The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authenticati... | HIGH | 7.5 | 2026-02-20 |
| CVE-2026-25648 | Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated use... | HIGH | 8.7 | 2026-02-23 |
| CVE-2026-0754 | An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering t... | 0 | 2026-03-03 | |
| CVE-2025-40238 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix IPsec cleanup over MPV device When w... | 0 | 2025-12-04 | |
| CVE-2025-40243 | In the Linux kernel, the following vulnerability has been resolved: hfs: fix KMSAN uninit-value issue in hfs_find_set_z... | 0 | 2025-12-04 | |
| CVE-2025-40244 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix KMSAN uninit-value issue in __hfsplus_... | 0 | 2025-12-04 | |
| CVE-2025-40246 | In the Linux kernel, the following vulnerability has been resolved: xfs: fix out of bounds memory read error in symlink... | 0 | 2025-12-04 | |
| CVE-2025-40251 | In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_no... | MEDIUM | 5.5 | 2025-12-04 |
| CVE-2025-40257 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptc... | 0 | 2025-12-04 | |
| CVE-2025-40261 | In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in ... | 0 | 2025-12-04 | |
| CVE-2025-40265 | In the Linux kernel, the following vulnerability has been resolved: vfat: fix missing sb_min_blocksize() return value c... | 0 | 2025-12-04 | |
| CVE-2025-40273 | In the Linux kernel, the following vulnerability has been resolved: NFSD: free copynotify stateid in nfs4_free_ol_state... | 0 | 2025-12-06 | |
| CVE-2025-40274 | In the Linux kernel, the following vulnerability has been resolved: KVM: guest_memfd: Remove bindings on memslot deleti... | 0 | 2025-12-06 | |
| CVE-2025-40280 | In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_mon_reinit_self().... | 0 | 2025-12-06 | |
| CVE-2025-40281 | In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_... | 0 | 2025-12-06 | |
| CVE-2025-40290 | In the Linux kernel, the following vulnerability has been resolved: xsk: avoid data corruption on cq descriptor number ... | 0 | 2025-12-08 | |
| CVE-2025-40295 | In the Linux kernel, the following vulnerability has been resolved: fscrypt: fix left shift underflow when inode->i_blk... | 0 | 2025-12-08 | |
| CVE-2025-40309 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix UAF on sco_conn_free BUG: KASA... | 0 | 2025-12-08 | |
| CVE-2022-50628 | In the Linux kernel, the following vulnerability has been resolved: drm/gud: Fix UBSAN warning UBSAN complains about i... | 0 | 2025-12-08 | |
| CVE-2023-53752 | In the Linux kernel, the following vulnerability has been resolved: net: deal with integer overflows in kmalloc_reserve... | 0 | 2025-12-08 | |
| CVE-2023-53761 | In the Linux kernel, the following vulnerability has been resolved: USB: usbtmc: Fix direction for 0-length ioctl contr... | 0 | 2025-12-08 | |
| CVE-2023-53762 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_... | 0 | 2025-12-08 | |
| CVE-2023-53764 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Handle lock during peer_id find ath1... | 0 | 2025-12-08 | |
| CVE-2023-53765 | In the Linux kernel, the following vulnerability has been resolved: dm cache: free background tracker's queued work in ... | 0 | 2025-12-08 | |
| CVE-2022-50652 | In the Linux kernel, the following vulnerability has been resolved: uio: uio_dmem_genirq: Fix missing unlock in irq con... | 0 | 2025-12-09 | |
| CVE-2023-53781 | In the Linux kernel, the following vulnerability has been resolved: smc: Fix use-after-free in tcp_write_timer_handler(... | 0 | 2025-12-09 | |
| CVE-2023-53795 | In the Linux kernel, the following vulnerability has been resolved: iommufd: IOMMUFD_DESTROY should not increase the re... | 0 | 2025-12-09 | |
| CVE-2023-53800 | In the Linux kernel, the following vulnerability has been resolved: ubi: Fix use-after-free when volume resizing failed... | 0 | 2025-12-09 | |
| CVE-2023-53809 | In the Linux kernel, the following vulnerability has been resolved: l2tp: Avoid possible recursive deadlock in l2tp_tun... | 0 | 2025-12-09 | |
| CVE-2023-53821 | In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix slab-use-after-free in decode_session6... | 0 | 2025-12-09 | |
| CVE-2023-53824 | In the Linux kernel, the following vulnerability has been resolved: netlink: annotate lockless accesses to nlk->max_rec... | 0 | 2025-12-09 | |
| CVE-2023-53829 | In the Linux kernel, the following vulnerability has been resolved: f2fs: flush inode if atomic file is aborted Let's ... | 0 | 2025-12-09 | |
| CVE-2023-53831 | In the Linux kernel, the following vulnerability has been resolved: net: read sk->sk_family once in sk_mc_loop() syzbo... | 0 | 2025-12-09 | |
| CVE-2023-53841 | In the Linux kernel, the following vulnerability has been resolved: devlink: report devlink_port_type_warn source devic... | 0 | 2025-12-09 | |
| CVE-2023-53846 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on direct node in trun... | 0 | 2025-12-09 | |
| CVE-2023-53847 | In the Linux kernel, the following vulnerability has been resolved: usb-storage: alauda: Fix uninit-value in alauda_che... | 0 | 2025-12-09 | |
| CVE-2023-53857 | In the Linux kernel, the following vulnerability has been resolved: bpf: bpf_sk_storage: Fix invalid wait context lockd... | 0 | 2025-12-09 | |
| CVE-2023-53860 | In the Linux kernel, the following vulnerability has been resolved: dm: don't attempt to queue IO under RCU protection ... | 0 | 2025-12-09 | |
| CVE-2023-53862 | In the Linux kernel, the following vulnerability has been resolved: hfs: fix missing hfs_bnode_get() in __hfs_bnode_cre... | 0 | 2025-12-09 | |
| CVE-2023-53865 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix warning when putting transaction with qg... | 0 | 2025-12-09 | |
| CVE-2024-38798 | EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized ... | 0 | 2025-12-09 | |
| CVE-2025-2296 | EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successf... | 0 | 2025-12-09 | |
| CVE-2025-58770 | APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privile... | HIGH | 8.8 | 2025-12-12 |
| CVE-2025-40349 | In the Linux kernel, the following vulnerability has been resolved: hfs: validate record offset in hfsplus_bmap_alloc ... | 0 | 2025-12-16 | |
| CVE-2025-40351 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix KMSAN uninit-value issue in hfsplus_de... | 0 | 2025-12-16 | |
| CVE-2025-40355 | In the Linux kernel, the following vulnerability has been resolved: sysfs: check visibility before changing group attri... | 0 | 2025-12-16 | |
| CVE-2025-40357 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix general protection fault in __smc_diag... | 0 | 2025-12-16 | |
| CVE-2025-68180 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL deref in debugfs odm_comb... | 0 | 2025-12-16 | |
| CVE-2025-68199 | In the Linux kernel, the following vulnerability has been resolved: codetag: debug: handle existing CODETAG_EMPTY in ma... | 0 | 2025-12-16 | |
| CVE-2025-68229 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: tcm_loop: Fix segfault in tcm_loop_tp... | 0 | 2025-12-16 | |
| CVE-2025-68231 | In the Linux kernel, the following vulnerability has been resolved: mm/mempool: fix poisoning order>0 pages with HIGHME... | 0 | 2025-12-16 | |
| CVE-2025-68261 | In the Linux kernel, the following vulnerability has been resolved: ext4: add i_data_sem protection in ext4_destroy_inl... | 0 | 2025-12-16 | |
| CVE-2025-68265 | In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin request_queue lifetime The namespa... | 0 | 2025-12-16 | |
| CVE-2025-68291 | In the Linux kernel, the following vulnerability has been resolved: mptcp: Initialise rcv_mss before calling tcp_send_a... | 0 | 2025-12-16 | |
| CVE-2025-68297 | In the Linux kernel, the following vulnerability has been resolved: ceph: fix crash in process_v2_sparse_read() for enc... | 0 | 2025-12-16 | |
| CVE-2025-68332 | In the Linux kernel, the following vulnerability has been resolved: comedi: c6xdigio: Fix invalid PNP driver unregistra... | 0 | 2025-12-22 | |
| CVE-2025-68335 | In the Linux kernel, the following vulnerability has been resolved: comedi: pcl818: fix null-ptr-deref in pcl818_ai_can... | 0 | 2025-12-22 | |
| CVE-2022-50705 | In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: defer fsnotify calls to task context ... | 0 | 2025-12-24 | |
| CVE-2023-54004 | In the Linux kernel, the following vulnerability has been resolved: udplite: Fix NULL pointer dereference in __sk_mem_r... | 0 | 2025-12-24 | |
| CVE-2023-54006 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix data-race around unix_tot_inflight. u... | 0 | 2025-12-24 | |
| CVE-2023-54008 | In the Linux kernel, the following vulnerability has been resolved: virtio_vdpa: build affinity masks conditionally We... | 0 | 2025-12-24 | |
| CVE-2023-54032 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race when deleting quota root from the d... | 0 | 2025-12-24 | |
| CVE-2023-54037 | In the Linux kernel, the following vulnerability has been resolved: ice: prevent NULL pointer deref during reload Call... | 0 | 2025-12-24 | |
| CVE-2025-68367 | In the Linux kernel, the following vulnerability has been resolved: macintosh/mac_hid: fix race condition in mac_hid_to... | 0 | 2025-12-24 | |
| CVE-2025-68368 | In the Linux kernel, the following vulnerability has been resolved: md: init bioset in mddev_init IO operations may be... | 0 | 2025-12-24 | |
| CVE-2022-50715 | In the Linux kernel, the following vulnerability has been resolved: md/raid1: stop mdx_raid1 thread when raid1 array ru... | 0 | 2025-12-24 | |
| CVE-2022-50716 | In the Linux kernel, the following vulnerability has been resolved: wifi: ar5523: Fix use-after-free on ar5523_cmd() ti... | 0 | 2025-12-24 | |
| CVE-2022-50720 | In the Linux kernel, the following vulnerability has been resolved: x86/apic: Don't disable x2APIC if locked The APIC ... | 0 | 2025-12-24 | |
| CVE-2022-50726 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix possible use-after-free in async comm... | 0 | 2025-12-24 | |
| CVE-2022-50735 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: do not run mt76u_status_worker if the d... | 0 | 2025-12-24 | |
| CVE-2022-50737 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate index root when initialize NTFS ... | 0 | 2025-12-24 | |
| CVE-2022-50739 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add null pointer check for inode operatio... | 0 | 2025-12-24 | |
| CVE-2022-50752 | In the Linux kernel, the following vulnerability has been resolved: md/raid5: Remove unnecessary bio_put() in raid5_rea... | 0 | 2025-12-24 | |
| CVE-2022-50753 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on summary info As We... | 0 | 2025-12-24 | |
| CVE-2023-54051 | In the Linux kernel, the following vulnerability has been resolved: net: do not allow gso_size to be set to GSO_BY_FRAG... | 0 | 2025-12-24 | |
| CVE-2023-54060 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Set end correctly when doing batch carry ... | 0 | 2025-12-24 | |
| CVE-2023-54067 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race when deleting free space root from ... | 0 | 2025-12-24 | |
| CVE-2023-54073 | In the Linux kernel, the following vulnerability has been resolved: tpm: Add !tpm_amd_is_rng_defective() to the hwrng_u... | 0 | 2025-12-24 | |
| CVE-2023-54080 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: skip splitting and logical rewriting ... | 0 | 2025-12-24 | |
| CVE-2023-54090 | In the Linux kernel, the following vulnerability has been resolved: ixgbe: Fix panic during XDP_TX with > 64 CPUs Comm... | 0 | 2025-12-24 | |
| CVE-2023-54094 | In the Linux kernel, the following vulnerability has been resolved: net: prevent skb corruption on frag list segmentati... | 0 | 2025-12-24 | |
| CVE-2023-54113 | In the Linux kernel, the following vulnerability has been resolved: rcu: dump vmalloc memory info safely Currently, fo... | 0 | 2025-12-24 | |
| CVE-2023-54125 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Return error for inconsistent extended at... | 0 | 2025-12-24 | |
| CVE-2023-54132 | In the Linux kernel, the following vulnerability has been resolved: erofs: stop parsing non-compact HEAD index if clust... | 0 | 2025-12-24 | |
| CVE-2023-54142 | In the Linux kernel, the following vulnerability has been resolved: gtp: Fix use-after-free in __gtp_encap_destroy(). ... | 0 | 2025-12-24 | |
| CVE-2023-54148 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Move representor neigh cleanup to profil... | 0 | 2025-12-24 | |
| CVE-2022-50816 | In the Linux kernel, the following vulnerability has been resolved: ipv6: ensure sane device mtu in tunnels Another sy... | 0 | 2025-12-30 | |
| CVE-2022-50817 | In the Linux kernel, the following vulnerability has been resolved: net: hsr: avoid possible NULL deref in skb_clone() ... | 0 | 2025-12-30 | |
| CVE-2022-50819 | In the Linux kernel, the following vulnerability has been resolved: udmabuf: Set ubuf->sg = NULL if the creation of sg ... | 0 | 2025-12-30 | |
| CVE-2022-50841 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add overflow check for attribute size Th... | 0 | 2025-12-30 | |
| CVE-2022-50850 | In the Linux kernel, the following vulnerability has been resolved: scsi: ipr: Fix WARNING in ipr_init() ipr_init() wi... | 0 | 2025-12-30 | |
| CVE-2022-50851 | In the Linux kernel, the following vulnerability has been resolved: vhost_vdpa: fix the crash in unmap a large memory ... | 0 | 2025-12-30 | |
| CVE-2022-50862 | In the Linux kernel, the following vulnerability has been resolved: bpf: prevent decl_tag from being referenced in func... | 0 | 2025-12-30 | |
| CVE-2022-50881 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: Fix use-after-free in ath9k_hif_usb_di... | 0 | 2025-12-30 | |
| CVE-2022-50885 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix NULL-ptr-deref in rxe_qp_do_cleanup()... | 0 | 2025-12-30 | |
| CVE-2023-54164 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix iso_conn related locking and va... | 0 | 2025-12-30 | |
| CVE-2023-54165 | In the Linux kernel, the following vulnerability has been resolved: zsmalloc: move LRU update from zs_map_object() to z... | 0 | 2025-12-30 | |
| CVE-2023-54170 | In the Linux kernel, the following vulnerability has been resolved: keys: Fix linking a duplicate key to a keyring's as... | 0 | 2025-12-30 | |
| CVE-2023-54176 | In the Linux kernel, the following vulnerability has been resolved: mptcp: stricter state check in mptcp_worker As rep... | 0 | 2025-12-30 | |
| CVE-2023-54180 | In the Linux kernel, the following vulnerability has been resolved: btrfs: handle case when repair happens with dev-rep... | 0 | 2025-12-30 | |
| CVE-2023-54193 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: remove block_cb from driver_lis... | 0 | 2025-12-30 | |
| CVE-2023-54196 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix NULL pointer dereference in 'ni_write... | 0 | 2025-12-30 | |
| CVE-2023-54203 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in init_smb2_rsp_hdr ... | 0 | 2025-12-30 | |
| CVE-2023-54206 | In the Linux kernel, the following vulnerability has been resolved: net/sched: flower: fix filter idr initialization T... | 0 | 2025-12-30 | |
| CVE-2023-54213 | In the Linux kernel, the following vulnerability has been resolved: USB: sisusbvga: Add endpoint checks The syzbot fuz... | 0 | 2025-12-30 | |
| CVE-2023-54216 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: TC, Fix using eswitch mapping in nic mod... | 0 | 2025-12-30 | |
| CVE-2023-54218 | In the Linux kernel, the following vulnerability has been resolved: net: Fix load-tearing on sk->sk_stamp in sock_recv_... | 0 | 2025-12-30 | |
| CVE-2023-54219 | In the Linux kernel, the following vulnerability has been resolved: Revert "IB/isert: Fix incorrect release of isert co... | 0 | 2025-12-30 | |
| CVE-2023-54223 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix invalid buffer access for legac... | 0 | 2025-12-30 | |
| CVE-2023-54226 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix data races around sk->sk_shutdown. KC... | 0 | 2025-12-30 | |
| CVE-2023-54236 | In the Linux kernel, the following vulnerability has been resolved: net/net_failover: fix txq exceeding warning The fa... | 0 | 2025-12-30 | |
| CVE-2023-54239 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Check for uptr overflow syzkaller found t... | 0 | 2025-12-30 | |
| CVE-2023-54241 | In the Linux kernel, the following vulnerability has been resolved: MIPS: KVM: Fix NULL pointer dereference After comm... | 0 | 2025-12-30 | |
| CVE-2023-54242 | In the Linux kernel, the following vulnerability has been resolved: block, bfq: Fix division by zero error on zero wsum... | 0 | 2025-12-30 | |
| CVE-2023-54251 | In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: Limit TCA_TAPRIO_ATTR_SCHED_CYCL... | 0 | 2025-12-30 | |
| CVE-2023-54270 | In the Linux kernel, the following vulnerability has been resolved: media: usb: siano: Fix use after free bugs caused b... | 0 | 2025-12-30 | |
| CVE-2023-54274 | In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Add a check for valid 'mad_agent' pointe... | 0 | 2025-12-30 | |
| CVE-2023-54277 | In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: Fix endpoint check The syzbot fuzzer... | 0 | 2025-12-30 | |
| CVE-2023-54283 | In the Linux kernel, the following vulnerability has been resolved: bpf: Address KCSAN report on bpf_lru_list KCSAN re... | 0 | 2025-12-30 | |
| CVE-2023-54286 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dvm: Fix memcpy: detected field-span... | 0 | 2025-12-30 | |
| CVE-2023-54291 | In the Linux kernel, the following vulnerability has been resolved: vduse: fix NULL pointer dereference vduse_vdpa_set... | 0 | 2025-12-30 | |
| CVE-2023-54296 | In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Get source vCPUs from source VM for SEV-E... | 0 | 2025-12-30 | |
| CVE-2023-54308 | In the Linux kernel, the following vulnerability has been resolved: ALSA: ymfpci: Create card with device-managed snd_d... | 0 | 2025-12-30 | |
| CVE-2023-54316 | In the Linux kernel, the following vulnerability has been resolved: refscale: Fix uninitalized use of wait_queue_head_t... | 0 | 2025-12-30 | |
| CVE-2023-54318 | In the Linux kernel, the following vulnerability has been resolved: net/smc: use smc_lgr_list.lock to protect smc_lgr_l... | 0 | 2025-12-30 | |
| CVE-2025-68757 | In the Linux kernel, the following vulnerability has been resolved: drm/vgem-fence: Fix potential deadlock on release ... | 0 | 2026-01-05 | |
| CVE-2025-68769 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix return value of f2fs_recover_fsync_data()... | 0 | 2026-01-13 | |
| CVE-2025-68772 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid updating compression context dur... | 0 | 2026-01-13 | |
| CVE-2025-68776 | In the Linux kernel, the following vulnerability has been resolved: net/hsr: fix NULL pointer dereference in prp_get_un... | 0 | 2026-01-13 | |
| CVE-2025-68793 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix a job->pasid access race in gpu rec... | 0 | 2026-01-13 | |
| CVE-2025-68796 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid updating zero-sized extent in ex... | 0 | 2026-01-13 | |
| CVE-2025-68800 | In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_mr: Fix use-after-free when updatin... | 0 | 2026-01-13 | |
| CVE-2025-68801 | In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_router: Fix neighbour use-after-fre... | 0 | 2026-01-13 | |
| CVE-2025-68810 | In the Linux kernel, the following vulnerability has been resolved: KVM: Disallow toggling KVM_MEM_GUEST_MEMFD on an ex... | 0 | 2026-01-13 | |
| CVE-2025-68815 | In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: Remove drr class from the active li... | 0 | 2026-01-13 | |
| CVE-2025-68818 | In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: qla2xxx: Perform lockless comma... | 0 | 2026-01-13 | |
| CVE-2025-71065 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadlock As Jiaming Z... | 0 | 2026-01-13 | |
| CVE-2025-71087 | In the Linux kernel, the following vulnerability has been resolved: iavf: fix off-by-one issues in iavf_config_rss_reg(... | 0 | 2026-01-13 | |
| CVE-2025-71088 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fallback earlier on simult connection Syzka... | 0 | 2026-01-13 | |
| CVE-2025-71091 | In the Linux kernel, the following vulnerability has been resolved: team: fix check for port enabled in team_queue_over... | 0 | 2026-01-13 | |
| CVE-2025-71093 | In the Linux kernel, the following vulnerability has been resolved: e1000: fix OOB in e1000_tbi_should_accept() In e10... | 0 | 2026-01-13 | |
| CVE-2025-71105 | In the Linux kernel, the following vulnerability has been resolved: f2fs: use global inline_xattr_slab instead of per-s... | 0 | 2026-01-14 | |
| CVE-2025-71107 | In the Linux kernel, the following vulnerability has been resolved: f2fs: ensure node page reads complete before f2fs_p... | 0 | 2026-01-14 | |
| CVE-2025-71118 | In the Linux kernel, the following vulnerability has been resolved: ACPICA: Avoid walking the Namespace if start_node i... | 0 | 2026-01-14 | |
| CVE-2025-71123 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix string copying in parse_apply_sb_mount_op... | 0 | 2026-01-14 | |
| CVE-2025-71125 | In the Linux kernel, the following vulnerability has been resolved: tracing: Do not register unsupported perf events S... | 0 | 2026-01-14 | |
| CVE-2025-71126 | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid deadlock on fallback while reinjecting... | 0 | 2026-01-14 | |
| CVE-2025-71132 | In the Linux kernel, the following vulnerability has been resolved: smc91x: fix broken irq-context in PREEMPT_RT When ... | 0 | 2026-01-14 | |
| CVE-2025-71144 | In the Linux kernel, the following vulnerability has been resolved: mptcp: ensure context reset on disconnect() After ... | MEDIUM | 5.5 | 2026-01-14 |
| CVE-2026-0421 | A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads wh... | MEDIUM | 6.5 | 2026-01-14 |
| CVE-2026-22976 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix NULL deref when deactivatin... | MEDIUM | 5.5 | 2026-01-21 |
| CVE-2026-22977 | In the Linux kernel, the following vulnerability has been resolved: net: sock: fix hardened usercopy panic in sock_recv... | MEDIUM | 5.5 | 2026-01-21 |
| CVE-2026-22996 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Don't store mlx5e_priv in mlx5e_dev devl... | MEDIUM | 5.5 | 2026-01-25 |
| CVE-2026-23000 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix crash on profile change rollback fai... | MEDIUM | 5.5 | 2026-01-25 |
| CVE-2026-23003 | In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tn... | 0 | 2026-01-25 | |
| CVE-2026-23004 | In the Linux kernel, the following vulnerability has been resolved: dst: fix races in rt6_uncached_list_del() and rt_de... | 0 | 2026-01-25 | |
| CVE-2026-23005 | In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state wh... | 0 | 2026-01-25 | |
| CVE-2026-23010 | In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix use-after-free in inet6_addr_del(). syzb... | 0 | 2026-01-25 | |
| CVE-2026-23011 | In the Linux kernel, the following vulnerability has been resolved: ipv4: ip_gre: make ipgre_header() robust Analog to... | 0 | 2026-01-25 | |
| CVE-2025-71183 | In the Linux kernel, the following vulnerability has been resolved: btrfs: always detect conflicting inodes when loggin... | 0 | 2026-01-31 | |
| CVE-2026-23035 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Pass netdev to mlx5e_destroy_netdev inst... | 0 | 2026-01-31 | |
| CVE-2026-23045 | In the Linux kernel, the following vulnerability has been resolved: net/ena: fix missing lock when update devlink param... | 0 | 2026-02-04 | |
| CVE-2026-23062 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: Fix kernel panic in GET_I... | MEDIUM | 5.5 | 2026-02-04 |
| CVE-2026-23088 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix crash on synthetic stacktrace field us... | 0 | 2026-02-04 | |
| CVE-2026-23099 | In the Linux kernel, the following vulnerability has been resolved: bonding: limit BOND_MODE_8023AD to Ethernet devices... | 0 | 2026-02-04 | |
| CVE-2026-23101 | In the Linux kernel, the following vulnerability has been resolved: leds: led-class: Only Add LED to leds_list when it ... | 0 | 2026-02-04 | |
| CVE-2026-23126 | In the Linux kernel, the following vulnerability has been resolved: netdevsim: fix a race issue related to the operatio... | 0 | 2026-02-14 | |
| CVE-2026-23131 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: Fix kobject warnings for ... | 0 | 2026-02-14 | |
| CVE-2026-23167 | In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix race between rfkill and nci_unregiste... | 0 | 2026-02-14 | |
| CVE-2026-23171 | In the Linux kernel, the following vulnerability has been resolved: bonding: fix use-after-free due to enslave fail aft... | 0 | 2026-02-14 | |
| CVE-2026-23173 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: TC, delete flows only for existing peers... | 0 | 2026-02-14 | |
| CVE-2026-23192 | In the Linux kernel, the following vulnerability has been resolved: linkwatch: use __dev_put() in callers to prevent UA... | 0 | 2026-02-14 | |
| CVE-2026-23198 | In the Linux kernel, the following vulnerability has been resolved: KVM: Don't clobber irqfd routing type when deassign... | 0 | 2026-02-14 | |
| CVE-2026-23200 | In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix ECMP sibling count mismatch when clearing... | 0 | 2026-02-14 | |
| CVE-2026-23214 | In the Linux kernel, the following vulnerability has been resolved: btrfs: reject new transactions if the fs is fully r... | 0 | 2026-02-18 | |
| CVE-2026-23215 | In the Linux kernel, the following vulnerability has been resolved: x86/vmware: Fix hypercall clobbers Fedora QA repor... | 0 | 2026-02-18 | |
| CVE-2026-23219 | In the Linux kernel, the following vulnerability has been resolved: mm/slab: Add alloc_tagging_slab_free_hook for memcg... | 0 | 2026-02-18 | |
| CVE-2025-71232 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Free sp in error path to fix system ... | 0 | 2026-02-18 | |
| CVE-2025-71236 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate sp before freeing associate... | 0 | 2026-02-18 | |
| CVE-2025-64736 | An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Ma... | MEDIUM | 6.1 | 2026-03-03 |
| CVE-2026-20777 | A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbios... | HIGH | 8.1 | 2026-03-03 |
| CVE-2026-22891 | A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig... | CRITICAL | 9.8 | 2026-03-03 |
| CVE-2025-71238 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix bsg_done() causing double free ... | 0 | 2026-03-04 | |
| CVE-2026-0940 | A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local pr... | MEDIUM | 6.7 | 2026-03-11 |
| CVE-2025-8860 | A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, t... | LOW | 3.3 | 2026-02-18 |
| CVE-2025-20027 | Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of p... | 0 | 2026-03-10 | |
| CVE-2025-20064 | Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation... | 0 | 2026-03-10 | |
| CVE-2025-20068 | Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalati... | 0 | 2026-03-10 | |
| CVE-2025-20073 | Improper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an infor... | 0 | 2026-03-10 | |
| CVE-2025-22444 | Exposure of resource to wrong sphere in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an inform... | 0 | 2026-03-10 | |
| CVE-2025-22850 | Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an in... | 0 | 2026-03-10 | |
| CVE-2022-50738 | In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: fix an iotlb memory leak Before commit... | 0 | 2025-12-24 | |
| CVE-2025-71089 | In the Linux kernel, the following vulnerability has been resolved: iommu: disable SVA when CONFIG_X86 is set Patch se... | HIGH | 7.8 | 2026-01-13 |
| CVE-2025-63624 | SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows... | CRITICAL | 9.8 | 2026-02-03 |
| CVE-2025-71202 | In the Linux kernel, the following vulnerability has been resolved: iommu/sva: invalidate stale IOTLB entries for kerne... | 0 | 2026-02-14 | |
| CVE-2026-27177 | MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability via the /objects/?op=se... | HIGH | 7.2 | 2026-02-18 |
| CVE-2026-20761 | A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in th... | HIGH | 8.1 | 2026-02-20 |
| CVE-2026-22885 | A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in th... | LOW | 3.7 | 2026-02-20 |
| CVE-2026-24015 | A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Us... | CRITICAL | 9.8 | 2026-03-09 |
| CVE-2026-24713 | Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from... | CRITICAL | 9.8 | 2026-03-09 |
| CVE-2025-33188 | NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware contro... | HIGH | 8 | 2025-11-25 |
| CVE-2025-13129 | Improper Enforcement of Behavioral Workflow vulnerability in Seneka Software Hardware Information Technology Trade Contr... | MEDIUM | 4.3 | 2025-12-01 |
| CVE-2025-40222 | In the Linux kernel, the following vulnerability has been resolved: tty: serial: sh-sci: fix RSCI FIFO overrun handling... | 0 | 2025-12-04 | |
| CVE-2025-40230 | In the Linux kernel, the following vulnerability has been resolved: mm: prevent poison consumption when splitting THP ... | 0 | 2025-12-04 | |
| CVE-2025-40235 | In the Linux kernel, the following vulnerability has been resolved: btrfs: directly free partially initialized fs_info ... | 0 | 2025-12-04 | |
| CVE-2025-40247 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix pgtable prealloc error path The follo... | 0 | 2025-12-04 | |
| CVE-2025-40317 | In the Linux kernel, the following vulnerability has been resolved: regmap: slimbus: fix bus_context pointer in regmap ... | 0 | 2025-12-08 | |
| CVE-2022-50614 | In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Fix pci_endpoint_test_{cop... | 0 | 2025-12-08 | |
| CVE-2022-50625 | In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: avoid SBSA UART accessing DMACR... | 0 | 2025-12-08 | |
| CVE-2022-50627 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix monitor mode bringup crash When ... | 0 | 2025-12-08 | |
| CVE-2023-53758 | In the Linux kernel, the following vulnerability has been resolved: spi: atmel-quadspi: Free resources even if runtime ... | 0 | 2025-12-08 | |
| CVE-2022-50647 | In the Linux kernel, the following vulnerability has been resolved: RISC-V: Make port I/O string accessors actually wor... | 0 | 2025-12-09 | |
| CVE-2022-50648 | In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix recursive locking direct_mutex in ftrac... | 0 | 2025-12-09 | |
| CVE-2023-53789 | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Improve page fault error reporting If I... | 0 | 2025-12-09 | |
| CVE-2023-53790 | In the Linux kernel, the following vulnerability has been resolved: bpf: Zeroing allocated object from slab in bpf memo... | 0 | 2025-12-09 | |
| CVE-2022-50674 | In the Linux kernel, the following vulnerability has been resolved: riscv: vdso: fix NULL deference in vdso_join_timens... | 0 | 2025-12-09 | |
| CVE-2022-50678 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix invalid address access when ena... | 0 | 2025-12-09 | |
| CVE-2023-53859 | In the Linux kernel, the following vulnerability has been resolved: s390/idle: mark arch_cpu_idle() noinstr linux-next... | 0 | 2025-12-09 | |
| CVE-2025-40337 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Correctly handle Rx checksum offload e... | 0 | 2025-12-09 | |
| CVE-2025-40356 | In the Linux kernel, the following vulnerability has been resolved: spi: rockchip-sfc: Fix DMA-API usage Use DMA-API d... | 0 | 2025-12-16 | |
| CVE-2025-68175 | In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: Fix streaming cleanup on rele... | 0 | 2025-12-16 | |
| CVE-2025-68184 | In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Disable AFBC support on Mediatek DRM ... | 0 | 2025-12-16 | |
| CVE-2025-68185 | In the Linux kernel, the following vulnerability has been resolved: nfs4_setup_readdir(): insufficient locking for ->d_... | 0 | 2025-12-16 | |
| CVE-2025-68192 | In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: initialize MAC header offset in... | 0 | 2025-12-16 | |
| CVE-2025-68194 | In the Linux kernel, the following vulnerability has been resolved: media: imon: make send_packet() more robust syzbot... | 0 | 2025-12-16 | |
| CVE-2025-68204 | In the Linux kernel, the following vulnerability has been resolved: pmdomain: arm: scmi: Fix genpd leak on provider reg... | 0 | 2025-12-16 | |
| CVE-2025-68220 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: netcp: Standardize knav_dma_open... | 0 | 2025-12-16 | |
| CVE-2025-68222 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: s32cc: fix uninitialized memory in s32_pin... | 0 | 2025-12-16 | |
| CVE-2025-68260 | In the Linux kernel, the following vulnerability has been resolved: rust_binder: fix race condition on death_list Rust... | 0 | 2025-12-16 | |
| CVE-2025-68262 | In the Linux kernel, the following vulnerability has been resolved: crypto: zstd - fix double-free in per-CPU stream cl... | 0 | 2025-12-16 | |
| CVE-2025-68286 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check NULL before accessing [WHAT... | 0 | 2025-12-16 | |
| CVE-2025-68306 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Fix kernel crash when r... | 0 | 2025-12-16 | |
| CVE-2025-68310 | In the Linux kernel, the following vulnerability has been resolved: s390/pci: Avoid deadlock between PCI error recovery... | 0 | 2025-12-16 | |
| CVE-2025-68320 | In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix sleeping in atomic context The follow... | 0 | 2025-12-16 | |
| CVE-2025-68327 | In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Fix synchronous external abort ... | 0 | 2025-12-22 | |
| CVE-2022-50697 | In the Linux kernel, the following vulnerability has been resolved: mrp: introduce active flags to prevent UAF when app... | 0 | 2025-12-24 | |
| CVE-2022-50699 | In the Linux kernel, the following vulnerability has been resolved: selinux: enable use of both GFP_KERNEL and GFP_ATOM... | 0 | 2025-12-24 | |
| CVE-2022-50704 | In the Linux kernel, the following vulnerability has been resolved: USB: gadget: Fix use-after-free during usb config s... | 0 | 2025-12-24 | |
| CVE-2025-68360 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: wed: use proper wed reference in mt76 w... | 0 | 2025-12-24 | |
| CVE-2022-50714 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921e: fix rmmod crash in driver relo... | 0 | 2025-12-24 | |
| CVE-2022-50741 | In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Disable useless interrupt to avoid... | 0 | 2025-12-24 | |
| CVE-2023-54089 | In the Linux kernel, the following vulnerability has been resolved: virtio_pmem: add the missing REQ_OP_WRITE for flush... | 0 | 2025-12-24 | |
| CVE-2023-54126 | In the Linux kernel, the following vulnerability has been resolved: crypto: safexcel - Cleanup ring IRQ workqueues on l... | 0 | 2025-12-24 | |
| CVE-2023-54156 | In the Linux kernel, the following vulnerability has been resolved: sfc: fix crash when reading stats while NIC is rese... | 0 | 2025-12-24 | |
| CVE-2023-54157 | In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF of alloc->vma in race with munmap()... | 0 | 2025-12-24 | |
| CVE-2022-50828 | In the Linux kernel, the following vulnerability has been resolved: clk: zynqmp: Fix stack-out-of-bounds in strncpy` "... | 0 | 2025-12-30 | |
| CVE-2022-50849 | In the Linux kernel, the following vulnerability has been resolved: pstore: Avoid kcore oops by vmap()ing with VM_IOREM... | 0 | 2025-12-30 | |
| CVE-2022-50877 | In the Linux kernel, the following vulnerability has been resolved: net: broadcom: bcm4908_enet: update TX stats after ... | 0 | 2025-12-30 | |
| CVE-2023-54172 | In the Linux kernel, the following vulnerability has been resolved: x86/hyperv: Disable IBT when hypercall page lacks E... | 0 | 2025-12-30 | |
| CVE-2023-54220 | In the Linux kernel, the following vulnerability has been resolved: serial: 8250: Fix oops for port->pm on uart_change_... | 0 | 2025-12-30 | |
| CVE-2023-54229 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix registration of 6Ghz-only phy wit... | 0 | 2025-12-30 | |
| CVE-2023-54257 | In the Linux kernel, the following vulnerability has been resolved: net: macb: fix a memory corruption in extended buff... | 0 | 2025-12-30 | |
| CVE-2023-54287 | In the Linux kernel, the following vulnerability has been resolved: tty: serial: imx: disable Ageing Timer interrupt re... | 0 | 2025-12-30 | |
| CVE-2025-3654 | Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows un... | MEDIUM | 5.3 | 2026-01-04 |
| CVE-2025-68751 | In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Fix false-positive kmsan report in fpu_vs... | 0 | 2026-01-05 | |
| CVE-2025-71078 | In the Linux kernel, the following vulnerability has been resolved: powerpc/64s/slb: Fix SLB multihit issue during SLB ... | 0 | 2026-01-13 | |
| CVE-2025-71092 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix OOB write in bnxt_re_copy_err_sta... | 0 | 2026-01-13 | |
| CVE-2025-71133 | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: avoid invalid read in irdma_net_event ... | 0 | 2026-01-14 | |
| CVE-2025-71134 | In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: change all pageblocks migrate type o... | 0 | 2026-01-14 | |
| CVE-2026-21982 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... | HIGH | 7.5 | 2026-01-20 |
| CVE-2021-47770 | OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to... | HIGH | 8.8 | 2026-01-21 |
| CVE-2025-71158 | In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: ensure worker is torn down When an IR... | MEDIUM | 5.5 | 2026-01-23 |
| CVE-2026-23009 | In the Linux kernel, the following vulnerability has been resolved: xhci: sideband: don't dereference freed ring when r... | 0 | 2026-01-25 | |
| CVE-2025-69418 | Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs... | MEDIUM | 4 | 2026-01-27 |
| CVE-2026-23046 | In the Linux kernel, the following vulnerability has been resolved: virtio_net: fix device mismatch in devm_kzalloc/dev... | 0 | 2026-02-04 | |
| CVE-2026-23055 | In the Linux kernel, the following vulnerability has been resolved: i2c: riic: Move suspend handling to NOIRQ phase Co... | 0 | 2026-02-04 | |
| CVE-2026-23102 | In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: signal: Fix restoration of SVE contex... | 0 | 2026-02-04 | |
| CVE-2026-23107 | In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: signal: Allocate SSVE storage when re... | 0 | 2026-02-04 | |
| CVE-2025-35998 | Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) ... | HIGH | 7.9 | 2026-02-10 |
| CVE-2025-8668 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite So... | CRITICAL | 9.4 | 2026-02-11 |
| CVE-2025-14014 | Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software H... | CRITICAL | 9.8 | 2026-02-12 |
| CVE-2026-25933 | Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in t... | MEDIUM | 6.8 | 2026-02-12 |
| CVE-2025-71200 | In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-of-dwcmshc: Prevent illegal clock reduct... | 0 | 2026-02-14 | |
| CVE-2026-23115 | In the Linux kernel, the following vulnerability has been resolved: serial: Fix not set tty->port race condition Rever... | 0 | 2026-02-14 | |
| CVE-2026-23128 | In the Linux kernel, the following vulnerability has been resolved: arm64: Set __nocfi on swsusp_arch_resume() A DABT ... | 0 | 2026-02-14 | |
| CVE-2026-23130 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix dead lock while flushing manageme... | 0 | 2026-02-14 | |
| CVE-2026-23147 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zlib: fix the folio leak on S390 hardware ac... | 0 | 2026-02-14 | |
| CVE-2026-23163 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix NULL pointer dereference in amdgpu_... | 0 | 2026-02-14 | |
| CVE-2026-23175 | In the Linux kernel, the following vulnerability has been resolved: net: cpsw: Execute ndo_set_rx_mode callback in a wo... | 0 | 2026-02-14 | |
| CVE-2026-23180 | In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: add bounds check for if_id in IRQ han... | 0 | 2026-02-14 | |
| CVE-2026-23183 | In the Linux kernel, the following vulnerability has been resolved: cgroup/dmem: fix NULL pointer dereference when sett... | 0 | 2026-02-14 | |
| CVE-2026-23184 | In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF in binder_netlink_report() Oneway ... | 0 | 2026-02-14 | |
| CVE-2026-23203 | In the Linux kernel, the following vulnerability has been resolved: net: cpsw_new: Execute ndo_set_rx_mode callback in ... | 0 | 2026-02-14 | |
| CVE-2025-71229 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix alignment fault in rtw_core_enable... | 0 | 2026-02-18 | |
| CVE-2026-27212 | Swiper is a free and mobile touch slider with hardware accelerated transitions and native behavior. Versions 6.5.1 throu... | HIGH | 7.8 | 2026-02-21 |
| CVE-2026-30829 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and... | MEDIUM | 5.3 | 2026-03-07 |
| CVE-2025-15037 | An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulne... | 0 | 2026-03-12 |