|
671
|
6.2 |
MEDIUM
Local
|
apple
|
ipados iphone_os
|
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2. Notifications marked for deletion could be unexpectedly …
Update
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2026-28950
|
2026-04-30 05:16 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
672
|
5.1 |
MEDIUM
Local
|
-
|
-
|
EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in thi…
Update
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2025-10549
|
2026-04-30 05:16 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
673
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime upda…
Update
|
CWE-295 CWE-296 CWE-494
Improper Certificate Validation Improper Following of a Certificate's Chain of Trust Download of Code Without Integrity Check
|
CVE-2025-10539
|
2026-04-30 05:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
674
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
vfio/xe: Reorganize the init to decouple migration from reset
Attempting to issue reset on VF devices that don't support migratio…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31601
|
2026-04-30 05:15 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
675
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
arm64: mm: Handle invalid large leaf mappings correctly
It has been possible for a long time to mark ptes in the linear map as
in…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-31600
|
2026-04-30 05:14 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
676
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections
syzbot reported a general protection fault in vidt…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-31599
|
2026-04-30 05:12 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
677
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: fix possible deadlock between unlink and dio_end_io_write
ocfs2_unlink takes orphan dir inode_lock first and then ip_alloc…
Update
|
CWE-667
Improper Locking
|
CVE-2026-31598
|
2026-04-30 05:10 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
678
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list()
smb_direct_flush_send_list() already…
Update
|
CWE-415
Double Free
|
CVE-2026-31608
|
2026-04-30 05:03 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
679
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_hid: don't call cdev_init while cdev in use
When calling unbind, then bind again, cdev_init reinitialized the cdev…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31606
|
2026-04-30 05:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
680
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
Much like commit 19f953e74356 ("fbdev: fb_pm2fb: Avoid potential divide…
Update
|
CWE-369
Divide By Zero
|
CVE-2026-31605
|
2026-04-30 04:36 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|