Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-45760 — Apache Camel K: Camel K Cross-Namespace Build Deputy Attack

(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can c…

Remote | Authorization
May 21, 2026 May 23, 2026
May 21, 2026
May 23, 2026
7.8 HIGH
CVE-2026-43502 — net/rds: handle zerocopy send cleanup before the message is queued

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but…

linux_kernel | Memory Corruption
May 21, 2026 Jun 01, 2026
May 21, 2026
Jun 01, 2026
9.8 CRITICAL
CVE-2026-43501 — ipv6: rpl: reserve mac_len headroom when recompressed SRH grows

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header…

linux_kernel | Remote | Memory Corruption
May 21, 2026 Jun 01, 2026
May 21, 2026
Jun 01, 2026
7.8 HIGH
CVE-2026-43499 — rtmutex: Use waiter::task instead of current in remove_waiter()

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also use…

linux_kernel | Race Condition
May 21, 2026 Jun 01, 2026
May 21, 2026
Jun 01, 2026
7.8 HIGH
CVE-2026-43498 — accel/ivpu: Disallow re-exporting imported GEM objects

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Disallow re-exporting imported GEM objects Prevent re-exporting of imported GEM buffers by adding a custom prime_hand…

linux_kernel | Misconfiguration
May 21, 2026 May 30, 2026
May 21, 2026
May 30, 2026
7.3 HIGH
CVE-2026-43497 — fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free

In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free dlfb_ops_mmap() uses remap_pfn_range() to map vmalloc framebu…

linux_kernel | Memory Corruption
May 21, 2026 Jun 01, 2026
May 21, 2026
Jun 01, 2026
0.0 NA
CVE-2026-43496 — net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked When red qdisc has children (eg qfq qdisc) who…

May 21, 2026 Jun 01, 2026
May 21, 2026
Jun 01, 2026
8.8 HIGH
CVE-2026-43495 — net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler

In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler t7xx_port_enum_msg_handler() uses the m…

linux_kernel | Memory Corruption
May 21, 2026 May 30, 2026
May 21, 2026
May 30, 2026
7.8 HIGH
CVE-2026-43494 — net/rds: reset op_nents when zerocopy page pin fails

In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinne…

linux_kernel | Memory Corruption
May 21, 2026 Jun 01, 2026
May 21, 2026
Jun 01, 2026
6.9 MEDIUM
CVE-2026-0393 — CODESYS Visualization - Insufficiently Protected Credentials

The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerabil…

visualization | Remote | Authentication
May 21, 2026 Jun 01, 2026
May 21, 2026
Jun 01, 2026
7.5 HIGH
CVE-2026-45255 — Remote code execution via installer Wi-Fi access point scans

When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and use bsddialog(1) to prompt the user to select a network. This is implemented us…

freebsd | Injection
May 21, 2026 May 21, 2026
May 21, 2026
May 21, 2026
6.5 MEDIUM
CVE-2026-45254 — Incorrect libcap_net limitation list manipulation

In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" instead of being rejected. In certain scenarios, an…

freebsd | Remote | Authorization
May 21, 2026 May 21, 2026
May 21, 2026
May 21, 2026
8.4 HIGH
CVE-2026-45253 — Missing validation in ptrace(PT_SC_REMOTE)

ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls. As a result, a user with the ability to debug a process may trigger arbitrary code …

freebsd | Memory Corruption
May 21, 2026 May 21, 2026
May 21, 2026
May 21, 2026
7.5 HIGH
CVE-2026-45252 — Heap overflow in FUSE_LISTXATTR

When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a given file. The FUSE …

freebsd | Remote | Memory Corruption
May 21, 2026 May 21, 2026
May 21, 2026
May 21, 2026
7.8 HIGH
CVE-2026-45251 — Kernel use-after-free via file descriptor syscalls

A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. Because the blocked thread does not hold a reference to the underlying object, t…

freebsd | Memory Corruption
May 21, 2026 May 21, 2026
May 21, 2026
May 21, 2026
6.5 MEDIUM
CVE-2026-42396 — Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

authoritative | Remote | Misconfiguration
May 21, 2026 May 26, 2026
May 21, 2026
May 26, 2026
7.5 HIGH
CVE-2026-42002 — Concurrency and locking defects in GSS-TSIG

Concurrency and locking defects in GSS-TSIG

authoritative | Remote | Race Condition
May 21, 2026 May 26, 2026
May 21, 2026
May 26, 2026
7.5 HIGH
CVE-2026-42001 — Insufficient Validation of Autoprimary SOA Queries

Insufficient Validation of Autoprimary SOA Queries

authoritative | Remote | Misconfiguration
May 21, 2026 May 26, 2026
May 21, 2026
May 26, 2026
8.6 HIGH
CVE-2026-42000 — Insufficient Validation of Names During AXFR

Insufficient Validation of Names During AXFR

authoritative | Remote | Misconfiguration
May 21, 2026 May 26, 2026
May 21, 2026
May 26, 2026
4.8 MEDIUM
CVE-2026-41999 — Incorrect Behaviour of Views with TCP PROXY Requests

Incorrect Behaviour of Views with TCP PROXY Requests

authoritative | Remote
May 21, 2026 May 26, 2026
May 21, 2026
May 26, 2026
Showing 20 of 6702 Results