|
1931
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
xfrm: prevent policy_hthresh.work from racing with netns teardown
A XFRM_MSG_NEWSPDINFO request can queue the per-net work item
p…
|
CWE-362
Race Condition
|
CVE-2026-31516
|
2026-04-29 01:30 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1932
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
af_key: validate families in pfkey_send_migrate()
syzbot was able to trigger a crash in skb_put() [1]
Issue is that pfkey_send_m…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-31515
|
2026-04-29 01:20 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1933
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
erofs: set fileio bio failed in short read case
For file-backed mount, IO requests are handled by vfs_iocb_iter_read().
However, …
|
NVD-CWE-noinfo
|
CVE-2026-31514
|
2026-04-29 01:19 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1934
|
- |
|
-
|
-
|
Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-priv…
|
-
|
CVE-2026-38948
|
2026-04-29 01:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1935
|
- |
|
-
|
-
|
Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attack…
|
-
|
CVE-2026-38651
|
2026-04-29 01:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1936
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2025-69428
|
2026-04-29 01:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1937
|
7.5 |
HIGH
Network
|
-
|
-
|
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthen…
|
CWE-377 CWE-532
Insecure Temporary File Inclusion of Sensitive Information in Log Files
|
CVE-2025-67223
|
2026-04-29 01:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1938
|
5.3 |
MEDIUM
Network
|
-
|
-
|
An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which may be used to bypass ASLR. Cl…
|
-
|
CVE-2025-60887
|
2026-04-29 01:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1939
|
8.1 |
HIGH
Adjacent
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req
Syzbot reported a KASAN stack-out-of-bounds read in l2cap_…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-31513
|
2026-04-29 01:15 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1940
|
7.5 |
HIGH
Network
|
linaro
|
op-tee
|
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. From 3.8.0 to 4.10, in the function e…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-33662
|
2026-04-29 00:48 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|