|
361
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ASoC: qcom: q6apm: move component registration to unmanaged version
q6apm component registers dais dynamically from ASoC toplolog…
Update
|
CWE-416
Use After Free
|
CVE-2026-31587
|
2026-04-29 05:44 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362
|
8.9 |
HIGH
Network
|
github
|
enterprise_server
|
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through a timing si…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5921
|
2026-04-29 05:43 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363
|
8.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Use scratch field in MMIO fragment to hold small write values
When exiting to userspace to service an emulated MMIO wri…
Update
|
CWE-416
Use After Free
|
CVE-2026-31588
|
2026-04-29 05:42 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
364
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
mm: call ->free_folio() directly in folio_unmap_invalidate()
We can only call filemap_free_folio() if we have a reference to (or …
Update
|
CWE-416
Use After Free
|
CVE-2026-31589
|
2026-04-29 05:40 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
365
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION
Drop the WARN in sev_pin_memory() on npages overflowing an in…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31590
|
2026-04-29 05:38 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
366
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Lock all vCPUs when synchronzing VMSAs for SNP launch finish
Lock all vCPUs when synchronizing and encrypting VMSAs for…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31591
|
2026-04-29 05:34 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
367
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock
Take and hold kvm->lock for before checking sev_guest() i…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-31592
|
2026-04-29 05:33 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
368
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMessage in the library src/lib/rls/rls_pdu.cpp of the component Radio Link Simulati…
New
|
CWE-248
Uncaught Exception
|
CVE-2026-7183
|
2026-04-29 05:27 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
369
|
8.8 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boaform/formTracert. Executing a manipulation of the argument datasize can lead to co…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7160
|
2026-04-29 05:26 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
370
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipu…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7154
|
2026-04-29 05:24 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|