2026-07-20
2026-07-20 07:16Z
CRIT

CVE-2026-13147 — Kirki: The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13147

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery). CVSSv3.1 9.1 (CRITICAL)

VNDKirkiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-20
2026-07-20 07:16Z
HIGH

CVE-2026-13142 — Social: The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13142

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator, leading to full site takeover. CVSSv3.1 8.1 (HIGH) · EPSS 3th percentile

CWECWE 269VNDSocialTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-20
2026-07-20 07:16Z
HIGH

CVE-2026-11349 — Modern: The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11349

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDModernTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-20
2026-07-20 07:16Z
HIGH

CVE-2026-10081 — Unlimited: The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10081

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver Stored XSS to any visitor (including administrators) of any WP page displaying that Place ID's reviews. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDUnlimitedTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 00:16Z
CRIT

CVE-2026-44359 — Meshtastic: This issue is separate from GHSA-6mwm-v2vv-pp96, which addressed a command injection via github.head_ref in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44359

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository secrets and elevated GITHUB_TOKEN permissions. No approval gate exists. Pull requests from external users with author_association: "NONE" triggered the CI workflow automatically. The workflow directly CVSSv3.1 10.0 (CRITICAL)

CWECWE 94CWECWE 829VNDMeshtasticTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-19
2026-07-19 17:00Z
HIGH

gopacket — A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled

GitHub · AD attack tooling·github.comGITHUB POC

Mandiant released gopacket, a complete Go reimplementation of the Impacket toolkit with 63 CLI tools and 24 protocol libraries for Windows and Active Directory attacks. The project compiles to a single dependency-free binary and supports proxychains and SOCKS5 proxying. This represents a significant shift in attacker tooling from Python-based Impacket to compiled Go binaries, mirroring real-world threat actor adoption patterns.

SRFOsSRFNetworkTACTA0006TACTA0007SRFIdentityTACTA0008TACTA0009SWGopacket
82
Edit Score
2026-07-19
2026-07-19 16:18Z
HIGH

CVE-2026-64178 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64178

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF read of dev->name bnep_add_connection() needs to keep holding the bnep_session_sem while reading dev->name (just like bnep_get_connlist() does); otherwise the bnep_session() thread can concurrently free the net_device, which can for example be triggered by a concurrent bnep_del_connection(). (This UAF is fairly uninteresting from a security perspective; calling bnep_add_connection( CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64176 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64176

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix driver-set TX rates on old devices On old devices such as 7265D, rates are still encoded in version 1 format, which doesn't use the CCK/OFDM rate index (0-3/0-7) but rather their PLCP value (e.g. 10 for 1 Mbps CCK rate.) While introducing v3 rates, I changed the driver from internally handling v1 rates and converting to v2, to internally handling v3 and converting to v1 or v2 accord CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64162 — Linux: In the Linux kernel, the following vulnerability has been resolved: idpf: fix read_dev_clk_lock spinlock

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64162

In the Linux kernel, the following vulnerability has been resolved: idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() In idpf_ptp_init(), read_dev_clk_lock is initialized after ptp_schedule_worker() had already been called (and after idpf_ptp_settime64() could reach the lock). The PTP aux worker fires immediately upon scheduling and can call into idpf_ptp_read_src_clk_reg_direct(), which takes spin_lock(&ptp->read_dev_clk_lock) on an uninitialized lock, triggerin CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64160 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64160

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential for tearing in ->remote_i_size and ->zero_point Fix potential tearing in using ->remote_i_size and ->zero_point by copying i_size_read() and i_size_write() and using the same seqcount as for i_size. We need to make sure that netfslib and the filesystems that use it always hold i_lock whilst updating any of the sizes to prevent i_size_seqcount from getting corrupted. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64153 — Linux: In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix iommu_map_sgtable() return

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64153

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN Commit "iommu: return full error code from iommu_map_sg[_atomic]()" changed iommu_map_sgtable() to return an ssize_t and negative values in error cases, rather than a size_t and a zero. Store the return value in the appropriate type and in case of error, return it rather than WARNing. Patchwork: https://patchwork.freedesktop.org/patch/7196 CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64151 — Linux: In the Linux kernel, the following vulnerability has been resolved: iommupt: Check for missing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64151

In the Linux kernel, the following vulnerability has been resolved: iommupt: Check for missing PAGE_SIZE in the pgsize_bitmap Sashiko pointed out that the driver could drop PAGE_SIZE from the pgsize_bitmap. That is technically allowed but nothing does it, and such an iommu_domain would not be used with the DMA API today. Still, it is against the design and it is trivial to fix up. Lift the PT_WARN_ON to the if branch and just skip the fast path. CVSSv3.1 8.4 (HIGH)

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64150 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: release local_lock

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64150

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: release local_lock before re-enabling softirqs Quoting sashiko: In the error path, local_bh_enable() is called before local_unlock_nested_bh(). CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64142 — Linux: * Bypass the per-conn open_files_count decrement in __put_fd_final() when fp is detached from any

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64142

In the Linux kernel, the following vulnerability has been resolved: ksmbd: close durable scavenger races against m_fp_list lookups ksmbd_durable_scavenger() has two related races against any walker that iterates f_ci->m_fp_list, including ksmbd_lookup_fd_inode() (used by ksmbd_vfs_rename) and the share-mode checks in fs/smb/server/smb_common.c. (1) fp->node list-head reuse. Durable-preserved handles can remain linked on f_ci->m_fp_list after session teardown so share-mode CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64138 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64138

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descriptor during ACL inheritance Introduce smb_validate_ntsd_sid() helper to safely validate Owner SID and Group SID inside the NT Security Descriptor (smb_ntsd) retrieved from the parent directory. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64136 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64136

In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields") refactored cifs code to change cifs_tcp_ses_lock for tc_lock around tc_count changes. There was missing lock around tc_count increment inside smb2_find_smb_sess_tcon_unlocked(). CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64132 — Linux: In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64132

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr pointer before ioam6_event() Reported by Sashiko: In ipv6_hop_ioam(), the hdr pointer is initialized to point into the skb's linear data buffer. Later, the code calls skb_ensure_writable(), which might reallocate the buffer: if (skb_ensure_writable(skb, optoff + 2 + hdr->opt_len)) goto drop; /* Trace pointer may have changed */ trace = (struct ioam6_trace_hdr *)(skb_network_h CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64125 — Linux: This shows up more often now that phy_support_eee() enables EEE by default, but it

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64125

In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting RBUF_EEE_EN | RBUF_PM_EN in RBUF_ENERGY_CTRL breaks the RX path on GENET hardware once MAC EEE becomes active. RX traffic stops flowing while the link stays up and the usual descriptor/RX error counters remain quiet. In that state the MAC still accepts frames (rbuf_ovflow_cnt keeps climbing) but RBUF no longer forwards them to DMA, so rx_packets is no longer CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64124 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: devmem: reject dma-buf

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64124

In the Linux kernel, the following vulnerability has been resolved: net: devmem: reject dma-buf bind with non-page-aligned size or SG length net_devmem_bind_dmabuf() trusts dmabuf->size and sg_dma_len() to be PAGE_SIZE multiples without checking: - tx_vec is sized dmabuf->size / PAGE_SIZE, and net_devmem_get_niov_at() only bounds-checks virt_addr < dmabuf->size before indexing tx_vec[virt_addr / PAGE_SIZE]. With size = N*PAGE_SIZE + r (1 <= r < PAGE_SIZE), se CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64122 — Linux: In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64122

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover mlx5e_tx_reporter_timeout_recover() accesses sq->netdev after mlx5e_safe_reopen_channels() has torn down and freed the channel (and its embedded SQs). Replace the three sq->netdev references with priv->netdev which is safe because priv outlives channel teardown. The netdev_err() call already used priv->netdev for this reason; make the trylo CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64118 — Linux: In the Linux kernel, the following vulnerability has been resolved: qed: fix double free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64118

In the Linux kernel, the following vulnerability has been resolved: qed: fix double free in qed_cxt_tables_alloc() If one of the later PF or VF CID bitmap allocations fails, qed_cid_map_alloc() jumps to cid_map_fail and frees the previously allocated CID bitmaps before returning an error. qed_cxt_tables_alloc() then calls qed_cxt_mngr_free(), which invokes qed_cid_map_free() again. Fix this by setting each CID bitmap pointer to NULL after bitmap_free() to avoid double free CVSSv3.1 8.4 (HIGH)

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64117 — Linux: The latter is KASAN slab-use-after-free in ieee80211_prepare_and_rx_handle.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64117

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb ieee80211_invoke_fast_rx() reads RX status through IEEE80211_SKB_RXCB(skb), which aliases the same skb->cb storage that ieee80211_rx_mesh_data() reuses as IEEE80211_TX_INFO. In the unicast forward path, mesh_data does: info = IEEE80211_SKB_CB(fwd_skb); memset(info, 0, sizeof(*info)); on the same skb the caller still names via rx->skb, then CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64115 — Linux: One second later vsock_pending_work() observed is_pending=true and performed full cleanup: vsock_remove_pending() then the two

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64115

In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: fix UAF when peer resets connection during handshake vmci_transport_recv_connecting_server() returned err = 0 for a peer RST in its default switch arm: err = pkt->type == VMCI_TRANSPORT_PACKET_TYPE_RST ? 0 : -EINVAL; That made vmci_transport_recv_listen() skip vsock_remove_pending(), leaving the pending socket on the listener's pending_links with sk_state = TCP_CLOSE while destroy: still drop CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64113 — Linux: In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64113

In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb and continuing to the next descriptor: dev_kfree_skb_irq(skb); continue; The skb pointer is declared outside the while loop and persists across iterations. Because the continue skips the "skb = NULL" reset at CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64109 — Linux: In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix UAF read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64109

In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix UAF read of tail->len in unix_stream_data_wait() unix_stream_data_wait() does skb_peek_tail(&sk->sk_receive_queue) without holding any lock that prevents SKBs on that queue from being dequeued and freed. This has been the case since commit 79f632c71bea ("unix/stream: fix peeking with an offset larger than data in queue"). The first consequence of this is that the pointer comparison `tail != las CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score