|
851
|
7.8 |
HIGH
Local
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: Fix possible invalid memory access after FLR
In the case that the first Function Level Reset (FLR) concludes
cor…
Update
|
-
|
CVE-2026-31442
|
2026-04-27 23:16 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
852
|
9.8 |
CRITICAL
Network
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc()
At the end of this function, d is the traversal c…
Update
|
-
|
CVE-2026-31436
|
2026-04-27 23:16 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
853
|
8.8 |
HIGH
Network
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix read abandonment during retry
Under certain circumstances, all the remaining subrequests from a read
request will get …
Update
|
-
|
CVE-2026-31435
|
2026-04-27 23:16 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
854
|
8.8 |
HIGH
Network
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix potencial OOB in get_file_all_info() for compound requests
When a compound request consists of QUERY_DIRECTORY + QUERY…
Update
|
-
|
CVE-2026-31433
|
2026-04-27 23:16 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
855
|
8.8 |
HIGH
Network
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix OOB write in QUERY_INFO for compound requests
When a compound request such as READ + QUERY_INFO(Security) is received,…
Update
|
-
|
CVE-2026-31432
|
2026-04-27 23:16 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
856
|
7.8 |
HIGH
Local
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the copying of
the assoc…
Update
|
-
|
CVE-2026-31431
|
2026-04-27 23:16 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
857
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net: skb: fix cross-cache free of KFENCE-allocated skb head
SKB_SMALL_HEAD_CACHE_SIZE is intentionally set to a non-power-of-2
va…
Update
|
-
|
CVE-2026-31429
|
2026-04-27 23:16 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
858
|
6.3 |
MEDIUM
Network
|
apache
|
dolphinscheduler
|
Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module.
This issue affects Apache DolphinScheduler:
Version >= 3.2.0 and < 3.3.1.
Attackers who can access the Maste…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2025-62233
|
2026-04-27 22:45 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
859
|
6.6 |
MEDIUM
Local
|
saurabh-kumar
|
python-dotenv
|
python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewri…
Update
|
CWE-59 CWE-61
Link Following UNIX Symbolic Link (Symlink) Following
|
CVE-2026-28684
|
2026-04-27 22:44 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
860
|
8.1 |
HIGH
Network
|
apache
|
dolphinscheduler
|
Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-23902
|
2026-04-27 22:42 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|