Vulnerabilities
Summary — last 7 days
New vulnerabilities2,737▼ 484 vs. last week
Critical / high1,302▼ 187 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)227▼ 275 vs. last week
402,859 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | Unscored | 0.21% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: core: Cancel SDIO IRQ work before freeing host A host controller that uses sdio_signal_irq() schedules host->sdio_irq_work from its interrupt handler. That work is only cancelled on the suspend path (mmc_sdio_suspend()), not on the remove/free… | |
| Received | Unscored | 0.21% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: hsq: Fix use-after-free in retry work mmc_hsq_pump_requests() queues retry_work when request_atomic() returns -EBUSY; today sdhci-sprd is the only consumer that implements request_atomic(). The work is embedded in a devm-allocated mmc_hsq, but is… | |
| Received | Unscored | 0.21% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: mmci: Fix use-after-free in busy-timeout work ux500_busy_complete() can queue ux500_busy_timeout_work for an R1b command, but mmci_remove() never cancels it. The work can subsequently dereference the devm-allocated mmci_host after it has been… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: mxcmmc: cancel data work and watchdog on remove mxcmci_remove() frees the host through the devm tail, but neither it nor mmc_remove_host() drains the driver's own asynchronous state. host->watchdog, a 10 s timer armed on the DMA path in… | |
| Received | Unscored | 0.22% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-of-aspeed: Remove children before releasing SDC resources Probe failure and removal leave SDHCI child devices registered after the parent clock and managed resources are released. Unregister the OF children in reverse order before disabling… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: sdio_uart: fix xmit_fifo leak when the port table is full sdio_uart_add_port() allocates the transmit fifo before claiming a slot in sdio_uart_table[]. When all UART_NR slots are taken, it returns -EBUSY with the fifo still allocated, but the… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: spi: reset bytes_xfered before retrying CRC failures mmc_spi_data_do() updates data->bytes_xfered after each block has been transferred successfully. If a later block in the same data request fails with a CRC error, data->bytes_xfered may… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: Input: cyttsp5 - clamp the HID report size before memcpy The size field comes from the device and is used as the memcpy() length into response_buf, which is CY_MAX_INPUT bytes. | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: Input: evdev - zero absinfo before partial copy in EVIOCSABS The EVIOCSABS handler copies at most the user supplied ioctl size into an uninitialized on-stack struct input_absinfo: The size comes from _IOC_SIZE() of the ioctl command and is therefore… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() When chunking writes into SMBus blocks in rmi_smb_write_block(), the loop calculates block_len using the original total length (len) instead of the remaining length (cur_len). If len… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: Input: soc_button_array - check btns_desc->package.count Check that btns_desc->package.count is not 0 before accessing btns_desc->package.elements[0]. | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Transport drivers (such as rmi_i2c and rmi_spi) invoke rmi_driver_suspend() and rmi_driver_resume() on their child rmi_dev device during system power management events. However,… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: Input: zero ff_effect before compat copy in input_ff_effect_from_user In the compat path input_ff_effect_from_user() aliases the caller's native struct ff_effect with the smaller struct ff_effect_compat and copies only the compat sized prefix: The… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show() nsensor->current_state is dynamically replaced as the sensor's state changes. update_numeric_sensor_from_wobj() does this by freeing the old string and installing a new one: This function… | |
| Received | Unscored | 0.17% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) increase number of phases and add new mask Increase the number of phases to 16 as a new upcoming device supports such a number. While at it, add a new mask for controlling the source of the output voltage. Note (groeck): This patch… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (pwm-fan) Stop RPM timer before freeing tach data sample_timer() rearms the RPM timer and accesses the devm-managed ctx->tachs and ctx->pulses_per_revolution arrays. The cleanup action which stops the timer is registered before those arrays are… | |
| Received | High (7) | 0.12% | — | Linux KernelAI | 10/6/2026 | 10/7/2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove When the fan/pwm 4-5 pins are not used as GPIO, w83791d_probe() creates the w83791d_group_fanpwm45 sysfs group on the I2C client device. The probe error path removes this group when a later… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmsmac: fix UAF in brcms_free_timer() brcms_free_timer() calls brcms_del_timer() which uses the non-synchronous cancel_delayed_work() to cancel the timer's underlying delayed work. If the work callback (_brcms_timer) is already running,… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlegacy: fix broadcast stations deallocation On the error path of __il4965_up(), il_dealloc_bcast_stations() clears only IL_STA_UCODE_ACTIVE, leaving IL_STA_BCAST set. This causes the same broadcast stations to be deallocated again by… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: libertas_tf: fix UAF in lbtf_free_adapter() lbtf_free_adapter() calls lbtf_free_cmd_buffer() to free the command buffers before calling timer_delete_sync() to wait for the command timer callback. If the timer callback (command_timer_fn) is… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: libipw: reject TKIP frames without a full MIC libipw_michael_mic_verify() assumes that an skb contains an eight-byte Michael MIC. A short TKIP frame makes the unsigned payload length wrap, causing michael_mic() to read past the skb. Check that… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown wcn36xx_dxe_deinit() tears down the TX ack timer with timer_delete(), which only dequeues the timer and does not wait for a callback that is already executing; the preceding… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: release runtime PM ref on regdomain config failure wlcore_regdomain_config() gets a runtime PM reference before sending the regulatory-domain command. When wlcore_cmd_regdomain_config_locked() fails, the function queues recovery and… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix out-of-bounds read in P2P public action frames wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once ieee80211_is_public_action() returns true. That helper only verifies the frame is long enough for the action category field,… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext() wilc_wlan_handle_isr_ext() takes the RX transfer size from the device-reported interrupt status register (a 15-bit field shifted left by 2, up to 131068 bytes) and reads that many… |