Aggregator
Please support the site operations by clicking ads.
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
1 month 3 weeks hence
[Virtual Event] Building a Secure AI Strategy for the Enterprise
2 weeks 6 days hence
CVE-2026-90350 | Linux Kernel up to 6.18.51/7.2.5 mt76 mt76_vif_link out-of-bounds
4 hours 8 minutes ago
A vulnerability was found in Linux Kernel up to 6.18.51/7.2.5. It has been classified as very critical. This affects the function mt76_vif_link of the component mt76. Performing a manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-90350. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-90349 | Linux Kernel up to 6.18.51/7.2.5 mt7996 mt7996_tx out-of-bounds
4 hours 8 minutes ago
A vulnerability was found in Linux Kernel up to 6.18.51/7.2.5 and classified as very critical. The impacted element is the function mt7996_tx of the component mt7996. Such manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-90349. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-90346 | Linux Kernel up to 7.2.5 nl80211 nl80211_color_change/nl80211_parse_beacon allocation of resources
4 hours 9 minutes ago
A vulnerability has been found in Linux Kernel up to 7.2.5 and classified as critical. The affected element is the function nl80211_color_change/nl80211_parse_beacon of the component nl80211. This manipulation causes allocation of resources.
This vulnerability is registered as CVE-2026-90346. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-90343 | Linux Kernel up to 6.18.51/7.2.5 cfg80211 cfg80211_stop_p2p_device locking
4 hours 9 minutes ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.51/7.2.5. Impacted is the function cfg80211_stop_p2p_device of the component cfg80211. The manipulation results in improper locking.
This vulnerability is cataloged as CVE-2026-90343. The attack must be initiated from a local position. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-90345 | Linux Kernel up to 7.2.5 brcmfmac input validation
4 hours 9 minutes ago
A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 7.2.5. This issue affects some unknown processing of the component brcmfmac. The manipulation leads to improper input validation.
This vulnerability is listed as CVE-2026-90345. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-90342 | Linux Kernel BPF arena_vm_fault deadlock
4 hours 9 minutes ago
A vulnerability classified as critical was found in Linux Kernel. This vulnerability affects the function arena_vm_fault of the component BPF. Executing a manipulation can lead to deadlock.
This vulnerability is tracked as CVE-2026-90342. The attack can be launched remotely. No exploit exists.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2026-90338 | Linux Kernel up to 6.18.51/7.2.5 amba-pl011 spinlock_rt.c pl011_console_write_atomic locking
4 hours 10 minutes ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.18.51/7.2.5. This affects the function pl011_console_write_atomic of the file spinlock_rt.c of the component amba-pl011. Performing a manipulation results in improper locking.
This vulnerability is identified as CVE-2026-90338. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-90347 | Linux Kernel up to 7.2.5 Ptrace privileges management
4 hours 10 minutes ago
A vulnerability described as problematic has been identified in Linux Kernel up to 7.2.5. Affected by this issue is some unknown functionality of the component Ptrace. Such manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2026-90347. The attack can only be performed from a local environment. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-90344 | Linux Kernel up to 6.12.109/6.18.51/7.2.5 mac80211 input validation
4 hours 10 minutes ago
A vulnerability marked as critical has been reported in Linux Kernel up to 6.12.109/6.18.51/7.2.5. Affected by this vulnerability is an unknown functionality of the component mac80211. This manipulation causes improper input validation.
The identification of this vulnerability is CVE-2026-90344. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-90341 | Linux Kernel up to 7.2.5 coreboot coreboot_table_probe memory corruption
4 hours 11 minutes ago
A vulnerability labeled as very critical has been found in Linux Kernel up to 7.2.5. Affected is the function coreboot_table_probe of the component coreboot. The manipulation results in memory corruption.
This vulnerability was named CVE-2026-90341. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-90339 | Linux Kernel up to 7.2.5 Syscall system_call_exception function return value
4 hours 11 minutes ago
A vulnerability identified as problematic has been detected in Linux Kernel up to 7.2.5. This impacts the function system_call_exception of the component Syscall Handler. The manipulation leads to incorrect check of function return value.
This vulnerability is uniquely identified as CVE-2026-90339. Local access is required to approach this attack. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-90348 | Linux Kernel up to 7.2.5 ath10k ath10k_snoc_fw_crashed_dump buffer overflow
4 hours 11 minutes ago
A vulnerability categorized as very critical has been discovered in Linux Kernel up to 7.2.5. This affects the function ath10k_snoc_fw_crashed_dump of the component ath10k. Executing a manipulation can lead to buffer overflow.
This vulnerability is handled as CVE-2026-90348. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-93337 | nm-l2tp NetworkManager-l2tp up to 1.52.4 VPN Connection Properties write_config_option mru/mtu input validation
4 hours 12 minutes ago
A vulnerability was found in nm-l2tp NetworkManager-l2tp up to 1.52.4. It has been rated as critical. The impacted element is the function write_config_option of the component VPN Connection Properties. Performing a manipulation of the argument mru/mtu results in improper input validation.
This vulnerability is known as CVE-2026-93337. Attacking locally is a requirement. No exploit is available.
vuldb.com
CVE-2026-92756 | MongoDB Entity Framework Core Provider up to 8.4.2/9.1.2/10.0.2 cleartext storage
4 hours 12 minutes ago
A vulnerability was found in MongoDB Entity Framework Core Provider up to 8.4.2/9.1.2/10.0.2. It has been declared as problematic. The affected element is an unknown function. Such manipulation leads to cleartext storage of sensitive information.
This vulnerability is traded as CVE-2026-92756. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-92758 | MongoDB Entity Framework Core Provider up to 8.4.3/9.1.3/10.0.3 information disclosure
4 hours 12 minutes ago
A vulnerability was found in MongoDB Entity Framework Core Provider up to 8.4.3/9.1.3/10.0.3. It has been classified as problematic. Impacted is an unknown function. This manipulation causes information disclosure.
This vulnerability appears as CVE-2026-92758. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-92943 | AWS IoT Device SDK for Python up to 1.6.0 TLS Connection certificate validation
4 hours 13 minutes ago
A vulnerability was found in AWS IoT Device SDK for Python up to 1.6.0 and classified as problematic. This issue affects some unknown processing of the component TLS Connection. The manipulation results in improper certificate validation.
This vulnerability is reported as CVE-2026-92943. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-90322 | Linux Kernel up to 6.12.109/6.18.51/7.2.5 ocfs2 heartbeat.c o2hb_do_disk_heartbeat out-of-bounds
4 hours 13 minutes ago
A vulnerability has been found in Linux Kernel up to 6.12.109/6.18.51/7.2.5 and classified as very critical. This vulnerability affects the function o2hb_do_disk_heartbeat of the file fs/ocfs2/cluster/heartbeat.c of the component ocfs2. The manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-90322. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com