Aggregator
CVE-2026-23417 | Linux Kernel up to 6.12.79/6.18.20/6.19.10/7.0-rc4 bpf bpf_jit_blind_insn privilege escalation (EUVD-2026-18200 / Nessus ID 318102)
18 hours 33 minutes ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.12.79/6.18.20/6.19.10/7.0-rc4. The impacted element is the function bpf_jit_blind_insn of the component bpf. Executing a manipulation can lead to privilege escalation.
This vulnerability is handled as CVE-2026-23417. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-23374 | Linux Kernel up to 6.19.6/7.0-rc2 blktrace tracing_record_cmdline buffer overflow (Nessus ID 318102)
18 hours 33 minutes ago
A vulnerability was found in Linux Kernel up to 6.19.6/7.0-rc2. It has been rated as critical. Impacted is the function tracing_record_cmdline of the component blktrace. This manipulation causes buffer overflow.
This vulnerability is tracked as CVE-2026-23374. The attack is only possible within the local network. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-23375 | Linux Kernel up to 6.12.77/6.18.16/6.19.6/7.0-rc1 file_thp_enabled memory corruption (Nessus ID 318102)
18 hours 33 minutes ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.77/6.18.16/6.19.6/7.0-rc1. The affected element is the function file_thp_enabled. Such manipulation leads to memory corruption.
This vulnerability is listed as CVE-2026-23375. The attack must be carried out from within the local network. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-23354 | Linux Kernel up to 6.12.76/6.18.16/6.19.6/7.0-rc1 fred_extint stack-based overflow (Nessus ID 318102)
18 hours 33 minutes ago
A vulnerability identified as critical has been detected in Linux Kernel up to 6.12.76/6.18.16/6.19.6/7.0-rc1. Affected by this vulnerability is the function fred_extint. This manipulation causes stack-based buffer overflow.
The identification of this vulnerability is CVE-2026-23354. The attack needs to be done within the local network. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-23346 | Linux Kernel up to 6.18.16/6.19.6/7.0-rc1 arm64 ioremap_prot pgprot_t permission (Nessus ID 318102)
18 hours 33 minutes ago
A vulnerability classified as critical was found in Linux Kernel up to 6.18.16/6.19.6/7.0-rc1. This issue affects the function ioremap_prot of the component arm64. Executing a manipulation of the argument pgprot_t can lead to permission issues.
This vulnerability appears as CVE-2026-23346. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
WP Maps Pro 漏洞遭利用,WordPress 网站控制权易主
18 hours 36 minutes ago
Defiant 公司发出警告,威胁行为者正在利用 WordPress 插件 WP Maps Pro 中的一个严重漏洞来接管网站。 WP Maps Pro 允许网站管理员在其站点中嵌入谷歌地图,并可通过高级位置、标记和类别进行自定义设置。 此次被利用的漏洞编号为 CVE - 2026 - 8732(CVSS 评分为 9.8),未经身份验证的威胁行为者可借此创建新的管理员账...
hackernews
CVE-2020-8554 | Oracle Communications Cloud Native Core Service Communication Proxy SCP authorization
18 hours 55 minutes ago
A vulnerability was found in Oracle Communications Cloud Native Core Service Communication Proxy 1.14.0. It has been declared as critical. The impacted element is an unknown function of the component SCP. Such manipulation leads to incorrect authorization.
This vulnerability is listed as CVE-2020-8554. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-8554 | Oracle Communications Cloud Native Core Unified Data Repository UDR authorization
18 hours 55 minutes ago
A vulnerability was found in Oracle Communications Cloud Native Core Unified Data Repository 1.14.0. It has been rated as critical. This affects an unknown function of the component UDR. Performing a manipulation results in incorrect authorization.
This vulnerability is cataloged as CVE-2020-8554. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2020-8554 | Kubernetes API Server permission
18 hours 55 minutes ago
A vulnerability identified as critical has been detected in Kubernetes. This vulnerability affects unknown code of the component API Server. The manipulation leads to permission issues.
This vulnerability is documented as CVE-2020-8554. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2020-8561 | Kubernetes kube-apiserver Request confused deputy (Issue 10472)
18 hours 55 minutes ago
A vulnerability labeled as problematic has been found in Kubernetes. This affects the function MutatingWebhookConfiguration/ValidatingWebhookConfiguration of the component kube-apiserver Request Handler. Executing a manipulation can lead to unintended intermediary.
The identification of this vulnerability is CVE-2020-8561. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2021-25740 | Kubernetes Network Traffic confused deputy (Issue 10367)
18 hours 55 minutes ago
A vulnerability marked as problematic has been reported in Kubernetes. This impacts an unknown function of the component Network Traffic Handler. The manipulation leads to unintended intermediary.
This vulnerability is referenced as CVE-2021-25740. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2020-8562 | Kubernetes DNS Resolution toctou (Issue 10149 / Nessus ID 256688)
18 hours 55 minutes ago
A vulnerability classified as problematic was found in Kubernetes. This vulnerability affects unknown code of the component DNS Resolution Handler. Executing a manipulation can lead to time-of-check time-of-use.
This vulnerability is tracked as CVE-2020-8562. The attack is only possible within the local network. No exploit exists.
vuldb.com
CVE-2020-8554 | Oracle Communications Cloud Native Core Policy 1.15.0 authorization
18 hours 55 minutes ago
A vulnerability, which was classified as problematic, has been found in Oracle Communications Cloud Native Core Policy 1.15.0. This issue affects some unknown processing of the component Policy. This manipulation causes incorrect authorization.
This vulnerability is registered as CVE-2020-8554. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2024-12146 | Finder Fire Safety Finder ERP CRM prior 18.12.2024 improper validation of syntactic correctness of input
18 hours 55 minutes ago
A vulnerability classified as problematic has been found in Finder Fire Safety Finder ERP CRM. This affects an unknown function. This manipulation causes improper validation of syntactic correctness of input.
This vulnerability is handled as CVE-2024-12146. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-12604 | Tapandsign Tap&Sign App prior 1.025 Environment Variable exposure of sensitive information through environmental variables
18 hours 55 minutes ago
A vulnerability categorized as critical has been discovered in Tapandsign Tap&Sign App. This affects an unknown function of the component Environment Variable Handler. The manipulation results in exposure of sensitive information through environmental variables.
This vulnerability is identified as CVE-2024-12604. The attack can be executed remotely. There is not any exploit available.
This product is available as a managed service. Users are not able to maintain vulnerability countermeasures themselves. It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-21847 | Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3 sof_ipc_msg_data null pointer dereference (Nessus ID 236983 / WID-SEC-2025-0545)
18 hours 55 minutes ago
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3. The affected element is the function sof_ipc_msg_data. The manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2025-21847. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2025-21863 | Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3 io_uring privilege escalation (Nessus ID 236983 / WID-SEC-2025-0545)
18 hours 55 minutes ago
A vulnerability classified as problematic has been found in Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3. This affects an unknown part of the component io_uring. The manipulation leads to privilege escalation.
This vulnerability is listed as CVE-2025-21863. The attack must be carried out from within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
礼盒上线!地球Online日历提醒您,端午副本已开启
19 hours 5 minutes ago
地球Online提醒您,请勿在NPC上浪费时间。
CVE-2026-23313 | Linux Kernel up to 6.12.76/6.18.16/6.19.6/7.0-rc2 i40e get_cpu memory leak (Nessus ID 318102 / WID-SEC-2026-0861)
19 hours 7 minutes ago
A vulnerability was found in Linux Kernel up to 6.12.76/6.18.16/6.19.6/7.0-rc2. It has been declared as critical. Impacted is the function get_cpu of the component i40e. Such manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2026-23313. The attack can only be initiated within the local network. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com