Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-43482 — sched_ext: Disable preemption between scx_claim_exit() and kicking helper work

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Disable preemption between scx_claim_exit() and kicking helper work scx_claim_exit() atomically sets exit_kind, which …

linux_kernel | Race Condition
May 13, 2026 May 22, 2026
May 13, 2026
May 22, 2026
7.8 HIGH
CVE-2026-43481 — net-shapers: don't free reply skb after genlmsg_reply()

In the Linux kernel, the following vulnerability has been resolved: net-shapers: don't free reply skb after genlmsg_reply() genlmsg_reply() hands the reply skb to netlink, and netlink_unicast() con…

linux_kernel | Memory Corruption
May 13, 2026 May 22, 2026
May 13, 2026
May 22, 2026
0.0 NA
CVE-2026-43480 — ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition The acp3x_5682_init() function did not check the r…

linux_kernel | Misconfiguration
May 13, 2026 May 22, 2026
May 13, 2026
May 22, 2026
0.0 NA
CVE-2026-43479 — net: usb: lan78xx: fix WARN in __netif_napi_del_locked on disconnect

In the Linux kernel, the following vulnerability has been resolved: net: usb: lan78xx: fix WARN in __netif_napi_del_locked on disconnect Remove redundant netif_napi_del() call from disconnect path.…

linux_kernel | Misconfiguration
May 13, 2026 May 22, 2026
May 13, 2026
May 22, 2026
0.0 NA
CVE-2026-43478 — ASoC: codecs: rt1011: Use component to get the dapm context in spk_mode_put

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: rt1011: Use component to get the dapm context in spk_mode_put The correct helper to use in rt1011_recv_spk_mode_put…

May 13, 2026 May 22, 2026
May 13, 2026
May 22, 2026
0.0 NA
CVE-2026-43477 — drm/i915/vrr: Configure VRR timings after enabling TRANS_DDI_FUNC_CTL

In the Linux kernel, the following vulnerability has been resolved: drm/i915/vrr: Configure VRR timings after enabling TRANS_DDI_FUNC_CTL Apparently ICL may hang with an MCE if we write TRANS_VRR_V…

May 13, 2026 May 22, 2026
May 13, 2026
May 22, 2026
7.8 HIGH
CVE-2026-43476 — iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas()

In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() sizeof(num) evaluates to sizeof(size_t) (8 bytes on 64-bit) in…

May 13, 2026 May 22, 2026
May 13, 2026
May 22, 2026
6.5 MEDIUM
CVE-2026-42946 — NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured…

nginx_plus nginx_open_source | Remote | Memory Corruption
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
9.2 CRITICAL
CVE-2026-42945 — NGINX ngx_http_rewrite_module vulnerability

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an…

nginx_plus nginx_open_source | Remote | Memory Corruption
May 13, 2026 May 21, 2026
May 13, 2026
May 21, 2026
6.5 MEDIUM
CVE-2026-42937 — iControl REST and tmsh vulnerability

Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attack…

May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
4.8 MEDIUM
CVE-2026-42934 — NGINX ngx_http_charset_module vulnerability

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives ar…

May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
8.7 HIGH
CVE-2026-42930 — Appliance mode iControl REST vulnerability

When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.  Note: Software versions which have …

big-ip_access_policy_manager | Remote | Authorization
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
5.8 MEDIUM
CVE-2026-42926 — NGINX ngx_http_proxy_v2_module vulnerability

When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the…

nginx_open_source | Remote | Injection
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
8.7 HIGH
CVE-2026-42924 — BIG-IP iControl SOAP vulnerability

An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions…

big-ip_access_policy_manager | Remote | Authorization
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
7.5 HIGH
CVE-2026-42920 — BIG-IP DTLS Vulnerability

When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software …

big-ip_access_policy_manager | Remote | Denial of Service
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
6.7 MEDIUM
CVE-2026-42919 — F5 BIG-IP Appliance Mode Vulnerability

A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a secur…

big-ip_access_policy_manager | Remote | Authentication
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
6.5 MEDIUM
CVE-2026-42781 — BIG-IP FastL4 virtual server vulnerability

When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utiliz…

big-ip_access_policy_manager | Denial of Service
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
4.9 MEDIUM
CVE-2026-42780 — BIG-IP SSL Orchestrator vulnerability

A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files.  Note: Software …

May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
9.6 CRITICAL
CVE-2026-42557 — jupyterlab: Command linker attributes in HTML enable one-click command execution from unt…

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlink…

notebook jupyterlab | Remote | Cross-Site Scripting
May 13, 2026 Jun 02, 2026
May 13, 2026
Jun 02, 2026
7.5 HIGH
CVE-2026-42409 — BIG-IP HTTP/2 vulnerability

When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) …

May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
Showing 20 of 7171 Results