s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

229687 CVEs matched. Showing 1151–1200 (page 24 of 4594).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-93232 mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and HVO bootmem pages — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93231 lockd: fix swapped arguments in nlmsvc_match_ip() — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93230 mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93229 nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry HIGH 7.1 — — Linux 2026-09-24 20 ⚠ Threat raw · ⬇
CVE-2026-93228 svcrdma: Reject Write/Reply chunks with segcount 0 CRITICAL 9.1 — — Linux 2026-09-24 20 ⚠ Threat raw · ⬇
CVE-2026-93227 mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93226 ipv6: use RCU iterator to dump route exceptions — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-96873 Reflected XSS in CirrusSearch debug explain output MEDIUM 5.5 — — wikimedia-foundation 2026-09-24 10 — raw · ⬇
CVE-2026-77581 BentoPDF: SSRF in cors-proxy-worker.js via DNS-based hostname allowlist bypass HIGH 8.6 — — GitHub_M 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2025-32000 Insufficient Input Sanitization is addressed in HCL Sametime 12.0.4. It is recommended to upgrade to the latest version. MEDIUM 4.3 4.3 — HCL 2026-09-24 10 — raw · ⬇
CVE-2026-93225 phy: fsl-imx8mq-usb: fix typec switch leak on probe error path HIGH 7.4 — — Linux 2026-09-24 20 ⚠ Threat raw · ⬇
CVE-2026-93224 svcrdma: Fix unmatched rn_unregister on failed accept HIGH 8.1 — — Linux 2026-09-24 20 ⚠ Threat raw · ⬇
CVE-2026-93223 staging: media: tegra-video: fix of_node_put() on VIP parse errors — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93222 signal: avoid shared siginfo namespace rewrites — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-56739 Logto: SSRF via Webhooks and Custom OAuth2 Connector UserInfo Endpoint HIGH 8.5 — — GitHub_M 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-63203 Logto: Account API can disclose stored third-party provider tokens without the identities scope HIGH 7.6 7.6 — GitHub_M 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-67233 RabbitMQ: Monitoring-tag user can DELETE shovels MEDIUM 6.0 — — GitHub_M 2026-09-24 10 — raw · ⬇
CVE-2026-93221 nfsd: convert nfsd_net boolean flags to unsigned long flags word HIGH 8.1 — — Linux 2026-09-24 20 ⚠ Threat raw · ⬇
CVE-2026-93220 sched_ext: Keep kick_sync waiting on the rq's own CPU — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93219 clocksource/drivers/timer-sun4i: Advertise a real minimum delta — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93218 mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93217 mm/madvise: skip device-private PMDs in cold and pageout walks — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93216 mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg() — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93215 cdx: Fix double free when sysfs file creation fails — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93214 usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93213 of: fix out-of-bounds read in of_alias_scan() stem parser — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93212 nfsd: guard nfsd_serv deref in nfsd_file_net_dispose — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93211 nfsd: initialize DRC hash table before registering shrinker — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93210 smb: client: harden DFS cache against invalid target hints — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93209 Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93208 kasan: fix cache shrink race with CPU hotplug — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93207 SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry CRITICAL 9.8 — — Linux 2026-09-24 20 ⚠ Threat raw · ⬇
CVE-2026-93206 PCI/proc: Use file_ns_capable() when checking config space read access — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-93205 iommu/arm-smmu-v3: Manage teardown with devm — — — — Linux 2026-09-24 10 — raw · ⬇
CVE-2026-92680 Araxis Merge insufficiently protected credentials MEDIUM 6.8 — — cisa-cg 2026-09-24 10 — raw · ⬇
CVE-2026-97225 DbGate JSON Runner runners.js code injection MEDIUM 5.3 — — VulDB 2026-09-24 10 — raw · ⬇
CVE-2026-56737 phpMyFAQ's two-factor authentication login bypasses the password factor HIGH 8.1 — — GitHub_M 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-73064 CVE-2026-73064 LOW 2.9 2.9 — mitre 2026-09-24 10 — raw · ⬇
CVE-2026-58008 Unchecked HKDF key-size input in EL3 causes a stack buffer overflow HIGH 8.3 — — Altera 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-58007 Unchecked SDM mailbox response address enables EL3 secure-memory corruption HIGH 8.3 8.1 — Altera 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-58006 Altera SoCFPGA BL31 Mailbox Output Pointer Validation Enables EL3 Secure-Memory Corruption HIGH 8.3 — — Altera 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-58005 Unvalidated SiP v2 mailbox pointers allow non-secure EL1 access to arbitrary physical addresses through EL3. HIGH 8.3 8.1 — Altera 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-58004 Crafted oversized firmware image causes EL3 stack overflow during VAB authentication on Trusted Firmware. HIGH 8.3 8.1 — Altera 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-13467 Systemic Missing Address Validation in SiP SMC Handlers HIGH 8.3 8.1 — Altera 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-13466 Unit Confusion in VAB Authentication HIGH 8.3 — — Altera 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-13465 EL3 Stack Buffer Overflow in FCS HKDF Request HIGH 8.3 — — Altera 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-97362 HFS2 2.4.0 Unauthenticated Denial of Service via Hung Serving Thread HIGH 8.7 7.5 — VulnCheck 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-90959 Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pul… HIGH 8.1 — — redhat 2026-09-24 10 ⚠ Threat raw · ⬇
CVE-2026-97224 Excalidraw Imported File restore.ts cross site scripting MEDIUM 5.3 — — VulDB 2026-09-24 10 — raw · ⬇
CVE-2026-77707 TLS Certificate Validation Disabled for Keycloak Connections in HAVELSAN's Liman Render Engine MEDIUM 5.9 — — TR-CERT 2026-09-24 10 — raw · ⬇