Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-65693 — Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates

Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions …

Remote | Injection
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64255 — wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers Three BA session handlers use ffs(ba_data->sta_mask) - …

| Misconfiguration
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64254 — NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR

In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR When BAR_PEER_SPAD and BAR_CONFIG share one PCI BAR…

| Misconfiguration
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64253 — kernel/fork: clear PF_BLOCK_TS in copy_process()

In the Linux kernel, the following vulnerability has been resolved: kernel/fork: clear PF_BLOCK_TS in copy_process() PF_BLOCK_TS is only set in blk_time_get_ns() when current->plug is non-NULL, and…

| Misconfiguration
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64252 — MIPS: DEC: Prevent initial console buffer from landing in XKPHYS

In the Linux kernel, the following vulnerability has been resolved: MIPS: DEC: Prevent initial console buffer from landing in XKPHYS In 64-bit configurations calling the initial console output hand…

Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64251 — pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()

In the Linux kernel, the following vulnerability has been resolved: pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() pwrseq_debugfs_seq_next() declares 'next' with __free(put_device), …

| Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64250 — LoongArch: Report dying CPU to RCU in stop_this_cpu()

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Report dying CPU to RCU in stop_this_cpu() This is a port of MIPS commit 9f3f3bdc6d9dac1 ("MIPS: smp: report dying CPU…

| Race Condition
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64249 — fpga: region: fix use-after-free in child_regions_with_firmware()

In the Linux kernel, the following vulnerability has been resolved: fpga: region: fix use-after-free in child_regions_with_firmware() Move of_node_put(child_region) after the error print to avoid a…

| Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64248 — MIPS: smp: report dying CPU to RCU in stop_this_cpu()

In the Linux kernel, the following vulnerability has been resolved: MIPS: smp: report dying CPU to RCU in stop_this_cpu() smp_send_stop() parks all secondary CPUs in stop_this_cpu(). The function m…

| Denial of Service
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64247 — KVM: x86: hyper-v: Bound the bank index when querying sparse banks

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: hyper-v: Bound the bank index when querying sparse banks When checking if a VP ID is included in a sparse bank set, exp…

| Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64246 — power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()

In the Linux kernel, the following vulnerability has been resolved: power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() Move of_node_put(dn) after the of_match…

| Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64245 — fbdev: modedb: fix a possible UAF in fb_find_mode()

In the Linux kernel, the following vulnerability has been resolved: fbdev: modedb: fix a possible UAF in fb_find_mode() If mode_option is NULL, it is assigned from mode_option_buf: if (!mode_opt…

| Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64244 — drivers/base/memory: set mem->altmap after successful device registration

In the Linux kernel, the following vulnerability has been resolved: drivers/base/memory: set mem->altmap after successful device registration If __add_memory_block() fails at xa_store() (under memo…

Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64243 — ASoC: codecs: simple-mux: Fix enum control bounds check

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: simple-mux: Fix enum control bounds check simple_mux_control_put() rejects values greater than e->items, but enum c…

| Misconfiguration
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64242 — usb: gadget: net2280: Fix double free in probe error path

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: net2280: Fix double free in probe error path usb_initialize_gadget() installs gadget_release() as the release callba…

| Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64241 — gpio: rockchip: teardown bugs and resource leaks

In the Linux kernel, the following vulnerability has been resolved: gpio: rockchip: teardown bugs and resource leaks Address several teardown issues and resource leaks in the driver's remove path a…

Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64240 — media: rc: igorplugusb: fix control request setup packet

In the Linux kernel, the following vulnerability has been resolved: media: rc: igorplugusb: fix control request setup packet Commit eac69475b01f ("media: rc: igorplugusb: heed coherency rules") cha…

| Misconfiguration
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64239 — mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()

In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() DAMON sysfs maintains the DAMOS tried region directory objects vi…

| Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64238 — gpio: shared: fix deadlock on shared proxy's parent removal

In the Linux kernel, the following vulnerability has been resolved: gpio: shared: fix deadlock on shared proxy's parent removal Commit 710abda58055 ("gpio: shared: call gpio_chip::of_xlate() if set…

Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-64237 — Input: elan_i2c - validate firmware size before use

In the Linux kernel, the following vulnerability has been resolved: Input: elan_i2c - validate firmware size before use Ensure that the firmware file is large enough to contain the expected number …

| Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
Showing 20 of 9764 Results