Total
336347 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-26037 | 2026-02-11 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-26036 | 2026-02-11 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-25251 | 2026-02-10 | N/A | N/A | ||
|
Rejected reason: This has been moved to the REJECTED state because the information source is under review. If circumstances change, it is possible that this will be moved to the PUBLISHED state at a later date.
|
|||||
| CVE-2023-53545 | 1 Linux | 1 Linux Kernel | 2026-02-10 | N/A | 5.5 MEDIUM |
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: unmap and remove csa_va properly
Root PD BO should be reserved before unmap and remove
a bo_va from VM otherwise lockdep will complain.
v2: check fpriv->csa_va is not NULL instead of amdgpu_mcbp (christian)
[14616.936827] WARNING: CPU: 6 PID: 1711 at drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c:1762 amdgpu_vm_bo_del+0x399/0x3f0 [amdgpu]
[14616.937096] Call Trace:
[14616.937097] <TASK>
[14616.937102] amdgpu_driver_pos ...
Show More |
|||||
| CVE-2023-53547 | 1 Linux | 1 Linux Kernel | 2026-02-10 | N/A | 5.5 MEDIUM |
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix sdma v4 sw fini error
Fix sdma v4 sw fini error for sdma 4.2.2 to
solve the following general protection fault
[ +0.108196] general protection fault, probably for non-canonical
address 0xd5e5a4ae79d24a32: 0000 [#1] PREEMPT SMP PTI
[ +0.000018] RIP: 0010:free_fw_priv+0xd/0x70
[ +0.000022] Call Trace:
[ +0.000012] <TASK>
[ +0.000011] release_firmware+0x55/0x80
[ +0.000021] amdgpu_ucode_release+0x11/0x20 ...
Show More |
|||||
| CVE-2023-53548 | 1 Linux | 1 Linux Kernel | 2026-02-10 | N/A | 5.5 MEDIUM |
|
In the Linux kernel, the following vulnerability has been resolved:
net: usbnet: Fix WARNING in usbnet_start_xmit/usb_submit_urb
The syzbot fuzzer identified a problem in the usbnet driver:
usb 1-1: BOGUS urb xfer, pipe 3 != type 1
WARNING: CPU: 0 PID: 754 at drivers/usb/core/urb.c:504 usb_submit_urb+0xed6/0x1880 drivers/usb/core/urb.c:504
Modules linked in:
CPU: 0 PID: 754 Comm: kworker/0:2 Not tainted 6.4.0-rc7-syzkaller-00014-g692b7dc87ca6 #0
Hardware name: Google Google Compute Engine/Goo ...
Show More |
|||||
| CVE-2023-53549 | 1 Linux | 1 Linux Kernel | 2026-02-10 | N/A | 5.5 MEDIUM |
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ipset: Rework long task execution when adding/deleting entries
When adding/deleting large number of elements in one step in ipset, it can
take a reasonable amount of time and can result in soft lockup errors. The
patch 5f7b51bf09ba ("netfilter: ipset: Limit the maximal range of
consecutive elements to add/delete") tried to fix it by limiting the max
elements to process at all. However it was not enough, it is still ...
Show More |
|||||
| CVE-2025-20991 | 1 Samsung | 1 Android | 2026-02-10 | N/A | 4.0 MEDIUM |
|
Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable.
|
|||||
| CVE-2025-20992 | 1 Samsung | 1 Android | 2026-02-10 | N/A | 4.0 MEDIUM |
|
Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory.
|
|||||
| CVE-2025-20993 | 1 Samsung | 1 Android | 2026-02-10 | N/A | 4.0 MEDIUM |
|
Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory.
|
|||||
| CVE-2025-20989 | 1 Samsung | 1 Android | 2026-02-10 | N/A | 5.2 MEDIUM |
|
Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac_key.
|
|||||
| CVE-2025-20988 | 1 Samsung | 1 Android | 2026-02-10 | N/A | 5.5 MEDIUM |
|
Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
|
|||||
| CVE-2025-20987 | 1 Samsung | 1 Android | 2026-02-10 | N/A | 5.2 MEDIUM |
|
Improper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a auth_token.
|
|||||
| CVE-2025-20985 | 1 Samsung | 1 Android | 2026-02-10 | N/A | 5.5 MEDIUM |
|
Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse trial items.
|
|||||
| CVE-2025-20981 | 1 Samsung | 1 Android | 2026-02-10 | N/A | 6.2 MEDIUM |
|
Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive information.
|
|||||
| CVE-2026-25560 | 1 Wekan Project | 1 Wekan | 2026-02-10 | N/A | 9.8 CRITICAL |
|
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during authentication.
|
|||||
| CVE-2026-25561 | 1 Wekan Project | 1 Wekan | 2026-02-10 | N/A | 7.5 HIGH |
|
WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId) are consistent and refer to a coherent card/board relationship, enabling attempts to upload attachments with mismatched object relationships.
|
|||||
| CVE-2026-25562 | 1 Wekan Project | 1 Wekan | 2026-02-10 | N/A | 4.3 MEDIUM |
|
WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially exposing attachment metadata to unauthorized users.
|
|||||
| CVE-2026-25563 | 1 Wekan Project | 1 Wekan | 2026-02-10 | N/A | 7.5 HIGH |
|
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating identifiers.
|
|||||
| CVE-2026-25564 | 1 Wekan Project | 1 Wekan | 2026-02-10 | N/A | 7.5 HIGH |
|
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating identifiers.
|
|||||
| CVE-2026-25565 | 1 Wekan Project | 1 Wekan | 2026-02-10 | N/A | 6.5 MEDIUM |
|
WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should require write access.
|
|||||
| CVE-2026-25567 | 1 Wekan Project | 1 Wekan | 2026-02-10 | N/A | 4.3 MEDIUM |
|
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by supplying another user's identifier.
|
|||||
| CVE-2026-25568 | 1 Wekan Project | 1 Wekan | 2026-02-10 | N/A | 4.3 MEDIUM |
|
WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement.
|
|||||
| CVE-2026-25859 | 1 Wekan Project | 1 Wekan | 2026-02-10 | N/A | 8.8 HIGH |
|
Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.
|
|||||
| CVE-2025-62439 | 2026-02-10 | N/A | 4.2 MEDIUM | ||
|
An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests.
|
|||||
| CVE-2025-11004 | 2026-02-10 | N/A | N/A | ||
|
The Simplicity Device Manager Tool has a Reflected XSS (Cross-site-scripting) vulnerability in several API endpoints. The attacker needs to be on the same network to execute this attack. These APIs can affect confidentiality, integrity, and availability of the system that has Simplicity Device Manager tool running in the background.
|
|||||
| CVE-2025-22885 | 2026-02-10 | N/A | 4.7 MEDIUM | ||
|
Improper buffer restrictions in the firmware for the TDX Module may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and availability (none) of the ...
Show More |
|||||
| CVE-2025-20080 | 2026-02-10 | N/A | 6.8 MEDIUM | ||
|
Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel may allow a denial of service. Network adversary with an unauthenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integr ...
Show More |
|||||
| CVE-2025-0029 | 2026-02-10 | N/A | N/A | ||
|
Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively drop guest DMA writes, potentially resulting in a loss of SEV-SNP guest memory integrity
|
|||||
| CVE-2024-36311 | 2026-02-10 | N/A | N/A | ||
|
A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker to bypass input validation and perform an out of bounds read or write, potentially resulting in loss of confidentiality, integrity, or availability.
|
|||||
| CVE-2025-22453 | 2026-02-10 | N/A | 7.5 HIGH | ||
|
Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confiden ...
Show More |
|||||
| CVE-2025-29939 | 2026-02-10 | N/A | N/A | ||
|
Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the reverse map page (RMP) during secure nested paging (SNP) initialization, potentially resulting in a loss of guest memory confidentiality and integrity.
|
|||||
| CVE-2024-36310 | 2026-02-10 | N/A | N/A | ||
|
Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds read or write to SMRAM potentially resulting in loss of confidentiality or integrity.
|
|||||
| CVE-2025-32453 | 2026-02-10 | N/A | 6.7 MEDIUM | ||
|
Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality ( ...
Show More |
|||||
| CVE-2025-27535 | 2026-02-10 | N/A | 5.3 MEDIUM | ||
|
Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before version NVM ver. 3.84 within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability ...
Show More |
|||||
| CVE-2025-20106 | 2026-02-10 | N/A | 6.7 MEDIUM | ||
|
Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolkits before version 2025.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interac ...
Show More |
|||||
| CVE-2025-52534 | 2026-02-10 | N/A | N/A | ||
|
Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integrity.
|
|||||
| CVE-2025-12699 | 2026-02-10 | N/A | 5.5 MEDIUM | ||
|
The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PCR fields (run number, incident, call sign, notes) are interpreted as HTML/JS when the app prints or renders that content. In the proof of concept (POC), injected scripts return local file content, which would allow arbitrary local file reads from the app's runtime context. These local files contain device and user data within the ePCR medical application, and if exposed, would ...
Show More |
|||||
| CVE-2025-0031 | 2026-02-10 | N/A | N/A | ||
|
A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent potentially resulting in loss of integrity.
|
|||||
| CVE-2025-29952 | 2026-02-10 | N/A | N/A | ||
|
Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged attacker to corrupt RMP covered memory, potentially resulting in loss of guest memory integrity
|
|||||