|
551
|
8.8 |
HIGH
Network
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix read abandonment during retry
Under certain circumstances, all the remaining subrequests from a read
request will get …
Update
|
-
|
CVE-2026-31435
|
2026-04-27 23:16 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
552
|
8.8 |
HIGH
Network
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix potencial OOB in get_file_all_info() for compound requests
When a compound request consists of QUERY_DIRECTORY + QUERY…
Update
|
-
|
CVE-2026-31433
|
2026-04-27 23:16 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
553
|
8.8 |
HIGH
Network
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix OOB write in QUERY_INFO for compound requests
When a compound request such as READ + QUERY_INFO(Security) is received,…
Update
|
-
|
CVE-2026-31432
|
2026-04-27 23:16 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
554
|
7.8 |
HIGH
Local
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the copying of
the assoc…
Update
|
-
|
CVE-2026-31431
|
2026-04-27 23:16 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
555
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net: skb: fix cross-cache free of KFENCE-allocated skb head
SKB_SMALL_HEAD_CACHE_SIZE is intentionally set to a non-power-of-2
va…
Update
|
-
|
CVE-2026-31429
|
2026-04-27 23:16 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
556
|
6.3 |
MEDIUM
Network
|
apache
|
dolphinscheduler
|
Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module.
This issue affects Apache DolphinScheduler:
Version >= 3.2.0 and < 3.3.1.
Attackers who can access the Maste…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2025-62233
|
2026-04-27 22:45 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
557
|
6.6 |
MEDIUM
Local
|
saurabh-kumar
|
python-dotenv
|
python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewri…
Update
|
CWE-59 CWE-61
Link Following UNIX Symbolic Link (Symlink) Following
|
CVE-2026-28684
|
2026-04-27 22:44 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
558
|
8.1 |
HIGH
Network
|
apache
|
dolphinscheduler
|
Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-23902
|
2026-04-27 22:42 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
559
|
6.1 |
MEDIUM
Network
|
astro
|
astro
|
Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /<\/script>/g to sanitize values injected into inline <sc…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-41067
|
2026-04-27 22:41 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
560
|
5.4 |
MEDIUM
Adjacent
|
openprinting
|
cups
|
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP bac…
Update
|
CWE-125 CWE-200
Out-of-bounds Read Information Exposure
|
CVE-2026-41079
|
2026-04-27 22:40 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
561
|
6.6 |
MEDIUM
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file …
Update
|
CWE-78
OS Command
|
CVE-2026-41411
|
2026-04-27 22:39 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
562
|
9.8 |
CRITICAL
Network
|
oracle
|
advanced_inbound_telephony
|
Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily explo…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-34275
|
2026-04-27 22:09 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
563
|
6.5 |
MEDIUM
Network
|
oracle
|
peoplesoft_enterprise_fin_contracts
|
Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affected is 9.2. Easily exploitable vulnerability allows …
Update
|
CWE-200
Information Exposure
|
CVE-2026-34300
|
2026-04-27 22:08 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
564
|
2.4 |
LOW
Network
|
oracle
|
database_server
|
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Easily exploitable vulnerability allows high privileged attacker having Row Acces…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-34312
|
2026-04-27 22:04 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
565
|
5.4 |
MEDIUM
Network
|
oracle
|
fusion_middleware
|
Vulnerability in Oracle Fusion Middleware (component: Dynamic Monitoring Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low pr…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-35232
|
2026-04-27 22:03 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
566
|
6.4 |
MEDIUM
Network
|
oracle
|
fusion_middleware
|
Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: C Oracle SSL API). Supported versions that are affected are 12.2.1.4.0 and 12.1.3.0.0. Difficult to expl…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-35252
|
2026-04-27 22:02 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
567
|
7.3 |
HIGH
Local
|
uutils
|
coreutils
|
A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not …
Update
|
CWE-22
Path Traversal
|
CVE-2026-35338
|
2026-04-27 21:28 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
568
|
3.3 |
LOW
Local
|
uutils
|
coreutils
|
The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. The implementation uses String::from_utf8_lossy(), which replaces invalid UTF-8 b…
Update
|
CWE-176
Improper Handling of Unicode Encoding
|
CVE-2026-35346
|
2026-04-27 21:28 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
569
|
4.4 |
MEDIUM
Local
|
uutils
|
coreutils
|
The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison operations. The are_files_identical function opens and reads from both input p…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-35347
|
2026-04-27 21:28 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
570
|
7.7 |
HIGH
Local
|
uutils
|
coreutils
|
A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementation uses a path-string check rather than comparing device and inode numbers to …
Update
|
CWE-59
Link Following
|
CVE-2026-35349
|
2026-04-27 21:28 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
571
|
4.2 |
MEDIUM
Local
|
uutils
|
coreutils
|
The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries. The utility falls back to a copy-and-delete routine that creates the destinati…
Update
|
CWE-281
Improper Preservation of Permissions
|
CVE-2026-35351
|
2026-04-27 21:28 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
572
|
3.3 |
LOW
Local
|
uutils
|
coreutils
|
The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions (typically 0755) before subsequently changing them …
Update
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35353
|
2026-04-27 21:27 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
573
|
6.3 |
MEDIUM
Local
|
uutils
|
coreutils
|
The install utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file installation. The implementation unlinks an existing destination file and t…
Update
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35355
|
2026-04-27 21:27 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
574
|
6.3 |
MEDIUM
Local
|
uutils
|
coreutils
|
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the install utility of uutils coreutils when using the -D flag. The command creates parent directories and subsequently performs a seco…
Update
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35356
|
2026-04-27 21:27 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
575
|
4.4 |
MEDIUM
Local
|
uutils
|
coreutils
|
The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting the SELinux context. If labeling fails, the utility attempts cleanup using std…
Update
|
CWE-281 CWE-459
Improper Preservation of Permissions Incomplete Cleanup
|
CVE-2026-35361
|
2026-04-27 21:27 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
576
|
3.6 |
LOW
Local
|
uutils
|
coreutils
|
The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to…
Update
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35362
|
2026-04-27 21:26 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
577
|
4.3 |
MEDIUM
Network
|
apache
|
airflow
|
The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment …
Update
|
CWE-1220
Insufficient Granularity of Access Control
|
CVE-2026-40690
|
2026-04-27 21:24 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
578
|
4.3 |
MEDIUM
Network
|
apache
|
airflow
|
The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG…
Update
|
CWE-1220
Insufficient Granularity of Access Control
|
CVE-2026-38743
|
2026-04-27 21:24 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
579
|
8.8 |
HIGH
Network
|
apache
|
activemq activemq_broker
|
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
An authenticated attacker may by…
Update
|
CWE-20 CWE-94
Improper Input Validation Code Injection
|
CVE-2026-40466
|
2026-04-27 21:23 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
580
|
7.5 |
HIGH
Network
|
oracle
|
jre jdk graalvm graalvm_for_jdk
|
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-34282
|
2026-04-27 21:20 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
581
|
2.9 |
LOW
Local
|
oracle
|
jre jdk graalvm graalvm_for_jdk
|
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java S…
Update
|
CWE-200
Information Exposure
|
CVE-2026-34268
|
2026-04-27 21:19 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
582
|
5.3 |
MEDIUM
Network
|
oracle
|
jre jdk graalvm graalvm_for_jdk
|
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-22021
|
2026-04-27 21:18 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
583
|
3.7 |
LOW
Network
|
oracle
|
jre jdk graalvm graalvm_for_jdk
|
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java …
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-22018
|
2026-04-27 21:17 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
584
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
x86/CPU: Fix FPDSS on Zen1
Zen1's hardware divider can leave, under certain circumstances, partial
results from previous operatio…
Update
|
-
|
CVE-2026-31628
|
2026-04-27 21:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
585
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
bnge: return after auxiliary_device_uninit() in error path
When auxiliary_device_add() fails, the error block calls
auxiliary_dev…
Update
|
-
|
CVE-2026-31621
|
2026-04-27 21:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
586
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usx2y: us144mkii: fix NULL deref on missing interface 0
A malicious USB device with the TASCAM US-144MKII device id can hav…
Update
|
-
|
CVE-2026-31620
|
2026-04-27 21:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
587
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_hid: don't call cdev_init while cdev in use
When calling unbind, then bind again, cdev_init reinitialized the cdev…
Update
|
-
|
CVE-2026-31606
|
2026-04-27 21:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
588
|
7.5 |
HIGH
Network
|
oracle
|
jre jdk graalvm graalvm_for_jdk
|
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8…
Update
|
CWE-200 CWE-502
Information Exposure Deserialization of Untrusted Data
|
CVE-2026-22016
|
2026-04-27 21:16 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
589
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
vfio/xe: Reorganize the init to decouple migration from reset
Attempting to issue reset on VF devices that don't support migratio…
Update
|
-
|
CVE-2026-31601
|
2026-04-27 21:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
590
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU
Reject synchronizing vCPU state to its associated VM…
Update
|
-
|
CVE-2026-31593
|
2026-04-27 21:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
591
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock
Take and hold kvm->lock for before checking sev_guest() i…
Update
|
-
|
CVE-2026-31592
|
2026-04-27 21:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
592
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Lock all vCPUs when synchronzing VMSAs for SNP launch finish
Lock all vCPUs when synchronizing and encrypting VMSAs for…
Update
|
-
|
CVE-2026-31591
|
2026-04-27 21:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
593
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (powerz) Fix use-after-free on USB disconnect
After powerz_disconnect() frees the URB and releases the mutex, a
subsequent…
Update
|
-
|
CVE-2026-31582
|
2026-04-27 21:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
594
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit
wg_netns_pre_exit() manually acquires rtnl_lock…
Update
|
-
|
CVE-2026-31579
|
2026-04-27 21:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
595
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
clockevents: Add missing resets of the next_event_forced flag
The prevention mechanism against timer interrupt starvation missed …
Update
|
-
|
CVE-2026-31574
|
2026-04-27 21:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
596
|
5.3 |
MEDIUM
Network
|
oracle
|
jdk graalvm graalvm_for_jdk jre
|
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 8…
Update
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-22013
|
2026-04-27 21:15 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
597
|
2.9 |
LOW
Local
|
oracle
|
graalvm graalvm_for_jdk jre jdk
|
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java S…
Update
|
CWE-200
Information Exposure
|
CVE-2026-22007
|
2026-04-27 21:14 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
598
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorizati…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-30368
|
2026-04-27 20:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
599
|
7.8 |
HIGH
Local
|
-
|
-
|
A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerabi…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-34003
|
2026-04-27 19:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
600
|
7.8 |
HIGH
Local
|
-
|
-
|
A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to…
Update
|
CWE-825
Expired Pointer Dereference
|
CVE-2026-34001
|
2026-04-27 19:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|