2026-07-19
2026-07-19 12:16Z
CRIT

CVE-2026-63795 — Linux: A later use or put of oldfid can then trigger a use-after-free or refcount

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63795

In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set to false, fid aliases oldfid. If the walk subsequently fails after the request has been sent, the error path jumps to clunk_fid, which currently calls p9_fid_put(fid) unconditionally. This drops a reference to oldfid even though ownership of oldfid remains with the caller. If this is the last reference, o CVSSv3.1 10.0 (CRITICAL)

TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-19
2026-07-19 12:16Z
CRIT

CVE-2026-53399 — Linux: In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53399

In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via idr_alloc_cyclic() under cl_lock before returning to nfsd4_alloc_layout_stateid(). When nfsd4_layout_setlease() then fails, the error path frees the layout stateid directly with kmem_cache_free() without ever calling idr_remove(), leaving the IDR slot pointing at freed slab memory. Any subsequent CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 12:16Z
CRIT

CVE-2026-53398 — Linux: In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53398

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. If the XDR stream is truncated, the decoder returns nfserr_bad_xdr before sin_exp is initialized. Since commit 3fdc54646234 ("NFSD: Reduce amount of struct nfsd4_compoundargs that needs clearing"), the inline iops array is not cleared between RPC calls. A failed SECINFO_NO_N CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 12:16Z
HIGH

CVE-2026-53390 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53390

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds read in smb_check_perm_dacl() The permission-check ACE walk in smb_check_perm_dacl() validates the ACE header size and caps sid.num_subauth at SID_MAX_SUB_AUTHORITIES, but it never checks that ace->size is actually large enough to contain num_subauth sub-authorities before compare_sids() dereferences them. CIFS_SID_BASE_SIZE covers the SID header up to but excluding the sub_auth[] CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-19
2026-07-19 12:16Z
CRIT

CVE-2026-53384 — Linux: The devm-allocated driver data is freed while the port still references it (via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53384

In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 8250 port via serial8250_register_8250_port() and then, if the device has a clock, registers a clock notifier. If clk_notifier_register() fails, probe returns the error but leaves the 8250 port registered. The matching serial8250_unregister_port() lives in dw8250_remove(), which is not called when probe fails CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 11:16Z
HIGH

CVE-2026-53375 — Linux: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial address

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53375

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial address patches In the case that only one of lo/hi is valid, the patching could result in a bad address written to in FW. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-19
2026-07-19 11:16Z
HIGH

CVE-2026-53374 — Linux: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53374

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocation GART TLB is flushed after unmapping but not after mapping. Since amdgpu_bo_create_kernel() does not zero-initialize the buffer, when a single PTE is written the TLB may speculatively load other uninitialized entries from the same cacheline. Those garbage entries can appear valid, and a subsequent write to another PTE in the same cacheline may cause the GP CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-19
2026-07-19 09:17Z
HIGH

CVE-2026-53369 — Linux: A crafted UDF image can set descCRCLength to an oversized value to bypass CRC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53369

In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length udf_read_tagged() skips CRC verification when descCRCLength + sizeof(struct tag) exceeds the block size. A crafted UDF image can set descCRCLength to an oversized value to bypass CRC validation entirely; the descriptor is then accepted based solely on the 8-bit tag checksum, which is trivially recomputable. Reject such descriptors instead of silently accep CVSSv3.1 8.4 (HIGH) · EPSS 8th percentile

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-18
2026-07-18 23:17Z
HIGH

CVE-2026-10130 — QueryWeaver: contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10130

QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The signup route unconditionally creates and links a new token to the matching Identity via a Cypher MERGE operation before checking whether the email belongs to an existing account, causing the server to return a valid authenticated session token for the victim' CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDQueryweaverTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-18
2026-07-18 21:17Z
HIGH

CVE-2026-12228 — XSS: A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12228

A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.content` without server-side sanitization. When a victim opens the direct message (DM) thread, the message is rendered by the DM UI through `MessageContentRenderer`, which uses `v-html` to insert rendered HTML into the DOM. The frontend sanitizer, which is regex-ba CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDXssTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-18
2026-07-18 14:17Z
HIGH

CVE-2026-9323 — The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9323

The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twister PRNG, which is not cryptographically secure. Each call consumes approximately 30 bits of PRNG state, and the Mersenne Twister internal state is approximately 19,937 bits, so an attacker who observes approximately 334 session IDs (for example via the X-Urwid-ID HTTP response hea CVSSv3.1 8.1 (HIGH)

CWECWE 338TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-18
2026-07-18 14:17Z
CRIT

CVE-2026-16117 — Impact: Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16117

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encoded form, and the prefix-rewrite step uses a literal string replace against the decoded prefix. A request that encodes one or more characters of the configured prefix therefore matches the route but skips the rewrite, so the raw encoded path is CVSSv3.1 10.0 (CRITICAL)

CWECWE 20VNDImpactTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-18
2026-07-18 14:17Z
HIGH

CVE-2026-11826 — OpenPLC_v3: contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11826

OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supplied buffer with no size parameter and no bounds check. In parseConfig() the function is invoked with the 100-byte heap-allocated MB_device.dev_name field. An authenticated attacker with access to the OpenPLC web interface can send a crafted HTTP POST to the /modbus endpoint with an oversized device CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDOpenplc V3TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-18
2026-07-18 14:17Z
HIGH

CVE-2025-71392 — Surrealdb Surrealdb: When a higher-privileged user subsequently imports the exported backup, the injected SurrealQL executes, enabling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71392

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR roles can create tables or fields with malicious names containing SurrealQL. When a higher-privileged user subsequently imports the exported backup, the injected SurrealQL executes, enabling privilege escalation and root-level takeover of the SurrealDB instance. Applications that CVSSv3.1 8.0 (HIGH) · EPSS 15th percentile

CWECWE 77VNDSurrealdbTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-18
2026-07-18 14:17Z
HIGH

CVE-2025-71390 — Surrealdb Surrealdb: before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71390

SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) with a hostname that resolves to a denied IP address, causing the server to issue the request anyway and return the response. This bypasses network access controls, allowing access to restricted internal endpoints and potentially retrieving o CVSSv3.1 8.8 (HIGH) · EPSS 14th percentile

CWECWE 863VNDSurrealdbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-18
2026-07-18 14:17Z
HIGH

CVE-2024-58366 — SurrealDB: before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-58366

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges. CVSSv3.1 8.5 (HIGH)

CWECWE 134VNDSurrealdbTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-18
2026-07-18 14:17Z
HIGH

CVE-2024-58362 — SurrealDB: before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-58362

SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. When a record access method defines a SIGNIN or SIGNUP query and the RPC API is exposed to untrusted users, an unauthenticated attacker can encode a binary object containing a subquery using the bincode serialization format and supply it in place of credentials. The subquery is the CVSSv3.1 8.8 (HIGH)

CWECWE 75VNDSurrealdbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-18
2026-07-18 14:17Z
HIGH

CVE-2023-54366 — SurrealDB: before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-54366

SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database access or unauthenticated users on publicly exposed instances can perform unrestricted operations on unprotected tables within their authorization scope. CVSSv3.1 8.8 (HIGH)

CWECWE 276VNDSurrealdbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-18
2026-07-18 13:17Z
HIGH

CVE-2026-16158 — Impact: Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16158

Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs. When getUpstream selects an upstream from request data, a URL cached for one upstream can be reused for a request intended for another upstream, causing cross-upstream data access CVSSv3.1 8.7 (HIGH)

CWECWE 441VNDImpactTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-18
2026-07-18 13:17Z
HIGH

CVE-2026-15631 — Impact: The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15631

Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapses dot segments, so a crafted upgrade request with path traversal sequences can escape the rewrite prefix and reach upstream endpoints that were not meant to be exposed by the proxy CVSSv3.1 8.7 (HIGH)

CWECWE 22VNDImpactTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-18
2026-07-18 12:17Z
HIGH

CVE-2026-16097 — Shibby: The manipulation of the argument a1 results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16097

A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDShibbyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-18
2026-07-18 12:17Z
HIGH

CVE-2026-16096 — The manipulation leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16096

A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This project is superseded by FreshTomato. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-18
2026-07-18 11:16Z
HIGH

CVE-2026-16095 — Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16095

A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write. The attack may be performed from remote. This project is superseded by FreshTomato. CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-18
2026-07-18 09:17Z
HIGH

CVE-2026-47871 — VMware: Avi Load Balancer contains a directory traversal vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47871

VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7) CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDVmwareTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-18
2026-07-18 09:17Z
HIGH

CVE-2026-47869 — VMware: Avi Load Balancer contains a remote code execution vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47869

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7) CVSSv3.1 8.7 (HIGH)

CWECWE 94VNDVmwareTYPVulnerability
8.7
CVSS v3.1
94
Edit Score