Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-23224 — erofs: fix UAF issue for file-backed mounts w/ directio option

In the Linux kernel, the following vulnerability has been resolved: erofs: fix UAF issue for file-backed mounts w/ directio option [ 9.269940][ T3222] Call trace: [ 9.269948][ T3222] ext4_fi…

linux_kernel | Race Condition
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2026-23223 — xfs: fix UAF in xchk_btree_check_block_owner

In the Linux kernel, the following vulnerability has been resolved: xfs: fix UAF in xchk_btree_check_block_owner We cannot dereference bs->cur when trying to determine if bs->cur aliases bs->sc->sa…

linux_kernel | Memory Corruption
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2026-23222 — crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly

In the Linux kernel, the following vulnerability has been resolved: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly The existing allocation of scatterlists in omap_crypto_copy…

linux_kernel | Memory Corruption
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2026-23221 — bus: fsl-mc: fix use-after-free in driver_override_show()

In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: fix use-after-free in driver_override_show() The driver_override_show() function reads the driver_override string wi…

linux_kernel | Memory Corruption
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2026-23220 — ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths The problem occurs when a signed request fails smb2…

linux_kernel | Denial of Service
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2025-71237 — nilfs2: Fix potential block overflow that cause system hang

In the Linux kernel, the following vulnerability has been resolved: nilfs2: Fix potential block overflow that cause system hang When a user executes the FITRIM command, an underflow can occur when …

linux_kernel | Denial of Service
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2025-71236 — scsi: qla2xxx: Validate sp before freeing associated memory

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate sp before freeing associated memory System crash with the following signature [154563.214890] nvme nvme2:…

Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2025-71235 — scsi: qla2xxx: Delay module unload while fabric scan in progress

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Delay module unload while fabric scan in progress System crash seen during load/unload test in a loop. [105954.38…

linux_kernel | Race Condition
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2025-71234 — wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add

In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add The driver does not set hw->sta_data_size, which causes mac80211 to al…

linux_kernel | Memory Corruption
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2025-71233 — PCI: endpoint: Avoid creating sub-groups asynchronously

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Avoid creating sub-groups asynchronously The asynchronous creation of sub-groups by a delayed work could lead to a…

linux_kernel | Race Condition
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2025-71232 — scsi: qla2xxx: Free sp in error path to fix system crash

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Free sp in error path to fix system crash System crash seen during load/unload test in a loop, [61110.449331] qla…

linux_kernel | Memory Corruption
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2025-71231 — crypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode

In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode The local variable 'i' is initialized with -EINVAL, but …

linux_kernel | Memory Corruption
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2025-71230 — hfs: ensure sb->s_fs_info is always cleaned up

In the Linux kernel, the following vulnerability has been resolved: hfs: ensure sb->s_fs_info is always cleaned up When hfs was converted to the new mount api a bug was introduced by changing the a…

Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2025-71229 — wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon()

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon() rtw_core_enable_beacon() reads 4 bytes from an address that is not a…

linux_kernel | Memory Corruption
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2025-70998 — UTT HiPER 810 Telnet Insecure Default Credentials Vulnerability

UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the telnet service, possibly allowing a remote attacker to gain root access via a craf…

810_firmware 810 | Remote | Authentication
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2025-65791 — ZoneMinder Command Injection Vulnerability

ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function.

zoneminder | Remote | Injection
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2025-65519 — Mayswind Ezbookkeeping XML/JSON File Processing Denial of Service

mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and XML file import processing. The application fails to validate nesting depth during parsing operations, a…

ezbookkeeping | Remote | Denial of Service
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
9.5 CRITICAL
CVE-2025-15579 — An Insecure Deserialization vulnerability has been discovered in OpenText™ Directory Serv…

Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerability could lead to remote code execution, denial of service, or privilege escal…

directory_services | Remote | Injection
Feb 18, 2026 Feb 27, 2026
Feb 18, 2026
Feb 27, 2026
2.5 LOW
CVE-2026-2656 — ChaiScript type_info.hpp bare_equal use after free

A flaw has been found in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file include/chaiscript/dispatchkit/type_info.hpp. This manipulation causes use aft…

chaiscript | Memory Corruption
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2026-2329 — Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow

An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remo…

Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
Showing 20 of 5035 Results