Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-0662 — Untrusted Search Path Vulnerability when opening max Files

A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path b…

3ds_max | Misconfiguration
Feb 04, 2026 Feb 06, 2026
Feb 04, 2026
Feb 06, 2026
8.4 HIGH
CVE-2026-0661 — Out-of-Bounds Write in RGB File Parsing

A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the c…

3ds_max | Memory Corruption
Feb 04, 2026 Feb 06, 2026
Feb 04, 2026
Feb 06, 2026
8.4 HIGH
CVE-2026-0660 — Stack Based Buffer Overflow in GIF File Parsing

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary cod…

3ds_max | Memory Corruption
Feb 04, 2026 Feb 06, 2026
Feb 04, 2026
Feb 06, 2026
7.8 HIGH
CVE-2026-0659 — USD File Parsing Out-of-Bounds Write Vulnerability

A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to …

3ds_max arnold usd_for_arnold | Memory Corruption
Feb 04, 2026 Feb 05, 2026
Feb 04, 2026
Feb 05, 2026
8.4 HIGH
CVE-2026-0538 — GIF File Parsing Out-of-Bounds Write

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in th…

3ds_max | Memory Corruption
Feb 04, 2026 Feb 06, 2026
Feb 04, 2026
Feb 06, 2026
8.4 HIGH
CVE-2026-0537 — RGB File Parsing Memory Corruption

A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the c…

3ds_max | Memory Corruption
Feb 04, 2026 Feb 06, 2026
Feb 04, 2026
Feb 06, 2026
0.0 NA
CVE-2025-71199 — iio: adc: at91-sama5d2_adc: Fix potential use-after-free in sama5d2_adc driver

In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91-sama5d2_adc: Fix potential use-after-free in sama5d2_adc driver at91_adc_interrupt can call at91_adc_touch_data_ha…

linux_kernel | Memory Corruption
Feb 04, 2026 Feb 06, 2026
Feb 04, 2026
Feb 06, 2026
0.0 NA
CVE-2025-71198 — iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without event detection

In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without event detection The st_lsm6dsx_acc_channels array of struct iio_chan_…

Feb 04, 2026 Feb 05, 2026
Feb 04, 2026
Feb 05, 2026
0.0 NA
CVE-2025-71197 — w1: therm: Fix off-by-one buffer overflow in alarms_store

In the Linux kernel, the following vulnerability has been resolved: w1: therm: Fix off-by-one buffer overflow in alarms_store The sysfs buffer passed to alarms_store() is allocated with 'size + 1' …

linux_kernel | Memory Corruption
Feb 04, 2026 Feb 06, 2026
Feb 04, 2026
Feb 06, 2026
0.0 NA
CVE-2025-71196 — phy: stm32-usphyc: Fix off by one in probe()

In the Linux kernel, the following vulnerability has been resolved: phy: stm32-usphyc: Fix off by one in probe() The "index" variable is used as an index into the usbphyc->phys[] array which has us…

linux_kernel | Memory Corruption
Feb 04, 2026 Feb 06, 2026
Feb 04, 2026
Feb 06, 2026
0.0 NA
CVE-2025-71195 — dmaengine: xilinx: xdma: Fix regmap max_register

In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx: xdma: Fix regmap max_register The max_register field is assigned the size of the register memory region instea…

linux_kernel | Memory Corruption
Feb 04, 2026 Feb 05, 2026
Feb 04, 2026
Feb 05, 2026
0.0 NA
CVE-2025-71194 — btrfs: fix deadlock in wait_current_trans() due to ignored transaction type

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock in wait_current_trans() due to ignored transaction type When wait_current_trans() is called during start_tran…

linux_kernel | Race Condition
Feb 04, 2026 Feb 06, 2026
Feb 04, 2026
Feb 06, 2026
0.0 NA
CVE-2025-71193 — phy: qcom-qusb2: Fix NULL pointer dereference on early suspend

In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qusb2: Fix NULL pointer dereference on early suspend Enabling runtime PM before attaching the QPHY instance as driver d…

linux_kernel | Memory Corruption
Feb 04, 2026 Feb 05, 2026
Feb 04, 2026
Feb 05, 2026
7.7 HIGH
CVE-2025-61917 — n8n Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner

n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to al…

n8n | Remote | Memory Corruption
Feb 04, 2026 Feb 18, 2026
Feb 04, 2026
Feb 18, 2026
0.0 NA
CVE-2026-23048 — udp: call skb_orphan() before skb_attempt_defer_free()

In the Linux kernel, the following vulnerability has been resolved: udp: call skb_orphan() before skb_attempt_defer_free() Standard UDP receive path does not use skb->destructor. But skmsg layer d…

Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
0.0 NA
CVE-2026-23047 — libceph: make calc_target() set t->paused, not just clear it

In the Linux kernel, the following vulnerability has been resolved: libceph: make calc_target() set t->paused, not just clear it Currently calc_target() clears t->paused if the request shouldn't be…

linux_kernel | Race Condition
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
0.0 NA
CVE-2026-23046 — virtio_net: fix device mismatch in devm_kzalloc/devm_kfree

In the Linux kernel, the following vulnerability has been resolved: virtio_net: fix device mismatch in devm_kzalloc/devm_kfree Initial rss_hdr allocation uses virtio_device->device, but virtnet_set…

linux_kernel | Memory Corruption
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
0.0 NA
CVE-2026-23045 — net/ena: fix missing lock when update devlink params

In the Linux kernel, the following vulnerability has been resolved: net/ena: fix missing lock when update devlink params Fix assert lock warning while calling devl_param_driverinit_value_set() in e…

linux_kernel | Race Condition
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
0.0 NA
CVE-2026-23044 — PM: hibernate: Fix crash when freeing invalid crypto compressor

In the Linux kernel, the following vulnerability has been resolved: PM: hibernate: Fix crash when freeing invalid crypto compressor When crypto_alloc_acomp() fails, it returns an ERR_PTR value, not…

linux_kernel | Memory Corruption
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
0.0 NA
CVE-2026-23043 — btrfs: fix NULL pointer dereference in do_abort_log_replay()

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix NULL pointer dereference in do_abort_log_replay() Coverity reported a NULL pointer dereference issue (CID 1666756) in …

linux_kernel | Memory Corruption
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
Showing 20 of 5195 Results