Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2025-71273 — wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band() Simplify the code by using device managed memory allocations. This a…

linux_kernel | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
0.0 NA
CVE-2025-71272 — most: core: fix resource leak in most_register_interface error paths

In the Linux kernel, the following vulnerability has been resolved: most: core: fix resource leak in most_register_interface error paths The function most_register_interface() did not correctly rel…

linux_kernel | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
0.0 NA
CVE-2025-71271 — hfsplus: ensure sb->s_fs_info is always cleaned up

In the Linux kernel, the following vulnerability has been resolved: hfsplus: ensure sb->s_fs_info is always cleaned up When hfsplus was converted to the new mount api a bug was introduced by changi…

linux_kernel | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
2.7 LOW
CVE-2025-62345 — HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” …

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component contains a security weakness in its input handling implementation, increasing the …

Remote | Misconfiguration
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
8.8 HIGH
CVE-2025-31951 — HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smugg…

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized comma…

Remote | Injection
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
6.3 MEDIUM
CVE-2026-6420 — Keylime: keylime: security bypass due to hardcoded tpm quote nonce

A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hard…

| Cryptography
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
6.1 MEDIUM
CVE-2025-59854 — HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit b…

dfxanalytics | Remote | Misconfiguration
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
5.3 MEDIUM
CVE-2025-59853 — HCL DFXAnalytics is affected by an Improper Error Handling vulnerability

HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the appl…

dfxanalytics | Remote | Information Disclosure
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
9.1 CRITICAL
CVE-2025-59852 — HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise t…

dfxanalytics | Remote | Cryptography
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
9.8 CRITICAL
CVE-2025-59851 — HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability

HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, which could allow an attacker to identify and …

dfxanalytics | Remote | Supply Chain
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
6.1 MEDIUM
CVE-2025-31970 — HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability

HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could al…

dfxanalytics | Remote | Misconfiguration
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
6.9 MEDIUM
CVE-2026-6860 — Apache TLS Server Name Spoofing Vulnerability

A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accep…

vert.x | Remote | Misconfiguration
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
6.5 MEDIUM
CVE-2026-43975 — Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager

FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to wri…

wicket | Remote | Path Traversal
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.5 HIGH
CVE-2026-43646 — Apache Wicket: crafted URLs can bypass PackageResourceGuard

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, from 10.0.0 through…

wicket | Remote | Information Disclosure
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.8 HIGH
CVE-2026-43120 — RDMA/irdma: Fix double free related to rereg_user_mr

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix double free related to rereg_user_mr If IB_MR_REREG_TRANS is set during rereg_user_mr, the umem will be released …

linux_kernel | Memory Corruption
May 06, 2026 May 08, 2026
May 06, 2026
May 08, 2026
0.0 NA
CVE-2026-43119 — Bluetooth: hci_sync: annotate data-races around hdev->req_status

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: annotate data-races around hdev->req_status __hci_cmd_sync_sk() sets hdev->req_status under hdev->req_lock: …

linux_kernel | Race Condition
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
5.5 MEDIUM
CVE-2026-43118 — btrfs: fix zero size inode with non-zero size after log replay

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix zero size inode with non-zero size after log replay When logging that an inode exists, as part of logging a new name o…

linux_kernel | Denial of Service
May 06, 2026 May 08, 2026
May 06, 2026
May 08, 2026
9.1 CRITICAL
CVE-2026-43117 — btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file()

In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() If overlay is used on top of btrfs, dentry->d_s…

linux_kernel | Remote | Misconfiguration
May 06, 2026 May 08, 2026
May 06, 2026
May 08, 2026
7.8 HIGH
CVE-2026-43116 — netfilter: ctnetlink: ensure safe access to master conntrack

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference on the expectation is not sufficient, the master c…

linux_kernel | Race Condition
May 06, 2026 May 08, 2026
May 06, 2026
May 08, 2026
5.5 MEDIUM
CVE-2026-43115 — srcu: Use irq_work to start GP in tiny SRCU

In the Linux kernel, the following vulnerability has been resolved: srcu: Use irq_work to start GP in tiny SRCU Tiny SRCU's srcu_gp_start_if_needed() directly calls schedule_work(), which acquires …

linux_kernel | Race Condition
May 06, 2026 May 08, 2026
May 06, 2026
May 08, 2026
Showing 20 of 5779 Results