|
1891
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure
When ttm_tt_swapout() fails, the current code calls
ttm_resour…
|
-
|
CVE-2026-52965
|
2026-06-25 02:17 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1892
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
The USB MIDI 2.0 endpoint parser has the same descriptor walking
patter…
|
-
|
CVE-2026-52964
|
2026-06-25 02:17 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1893
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Bound MIDI endpoint descriptor scans
snd_usbmidi_get_ms_info() validates the internal MIDIStreaming endpoint
des…
|
-
|
CVE-2026-52963
|
2026-06-25 02:17 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1894
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
The generic/642 test-case can reproduce the kernel crash:
…
|
-
|
CVE-2026-52961
|
2026-06-25 02:17 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1895
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on backup failure
Apply the same fix as b2ed01e7ad ("drm/ttm: Fix ttm_bo_swapout()…
|
-
|
CVE-2026-52949
|
2026-06-25 02:17 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1896
|
7.7 |
HIGH
Network
|
-
|
-
|
The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki en…
|
CWE-22
Path Traversal
|
CVE-2026-42129
|
2026-06-25 02:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1897
|
9.6 |
CRITICAL
Network
|
-
|
-
|
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connecte…
|
CWE-284
Improper Access Control
|
CVE-2026-28381
|
2026-06-25 02:16 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1898
|
9.0 |
CRITICAL
Network
|
-
|
-
|
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted
by an unauthenticated user, l…
|
CWE-287 CWE-330 CWE-340
Improper Authentication Use of Insufficiently Random Values Generation of Predictable Numbers or Identifiers
|
CVE-2026-11374
|
2026-06-25 02:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1899
|
5.9 |
MEDIUM
Network
|
-
|
-
|
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted reques…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-10852
|
2026-06-25 02:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1900
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, enabling path traversal. A Viewer-role user can: (1) ca…
|
CWE-22
Path Traversal
|
CVE-2026-10601
|
2026-06-25 02:16 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|