U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-7007 - The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.c) before completing a mount. The validator checked the magic number, block size, revision and feature flags, but did not verif... read CVE-2026-7007
    Published: 七月 24, 2026; 11:19:08 上午 -0400

  • CVE-2026-3482 - IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a... read CVE-2026-3482
    Published: 七月 22, 2026; 3:17:03 下午 -0400

  • CVE-2026-11980 - IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
    Published: 七月 30, 2026; 11:16:24 上午 -0400

  • CVE-2026-16463 - A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context ... read CVE-2026-16463
    Published: 七月 29, 2026; 12:17:50 下午 -0400

  • CVE-2026-14973 - IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
    Published: 七月 28, 2026; 5:17:26 下午 -0400

  • CVE-2026-11904 - IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote at... read CVE-2026-11904
    Published: 七月 30, 2026; 3:17:04 下午 -0400

    V3.1: 5.3 MEDIUM

  • CVE-2026-10545 - IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of s... read CVE-2026-10545
    Published: 七月 30, 2026; 3:17:01 下午 -0400

    V3.1: 7.5 HIGH

  • CVE-2025-13394 - The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cooki... read CVE-2025-13394
    Published: 八月 06, 2026; 4:16:28 上午 -0400

  • CVE-2025-13736 - When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original ... read CVE-2025-13736
    Published: 八月 06, 2026; 4:16:28 上午 -0400

  • CVE-2026-18382 - A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator ... read CVE-2026-18382
    Published: 七月 30, 2026; 8:17:27 上午 -0400

  • CVE-2025-15039 - The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attack... read CVE-2025-15039
    Published: 八月 06, 2026; 4:16:29 上午 -0400

  • CVE-2026-0637 - When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access t... read CVE-2026-0637
    Published: 八月 06, 2026; 4:16:29 上午 -0400

  • CVE-2026-18381 - A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-... read CVE-2026-18381
    Published: 七月 30, 2026; 8:17:27 上午 -0400

    V3.1: 7.6 HIGH

  • CVE-2026-50472 - Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
    Published: 八月 11, 2026; 1:18:02 下午 -0400

  • CVE-2026-64230 - In the Linux kernel, the following vulnerability has been resolved: regulator: tps65219: fix irq_data.rdev not being assigned Commit 64a6b577490c ("regulator: tps65219: Remove debugging helper function") removed the tps65219_get_rdev_by_name() h... read CVE-2026-64230
    Published: 七月 24, 2026; 12:16:52 下午 -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-64231 - In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: don't dump registers past the mapped region On DSI 6G platforms the IO address space is internally adjusted by io_offset. Later this adjusted address might be used ... read CVE-2026-64231
    Published: 七月 24, 2026; 12:16:52 下午 -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-64232 - In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_insert_cloned_request blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "the queue ... read CVE-2026-64232
    Published: 七月 24, 2026; 12:16:52 下午 -0400

  • CVE-2026-64233 - In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind uvc_function_bind() walks &opts->extension_units twice without holding opts->lock: - directly, for the ... read CVE-2026-64233
    Published: 七月 24, 2026; 12:16:52 下午 -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-64234 - In the Linux kernel, the following vulnerability has been resolved: tty: serial: pch_uart: add check for dma_alloc_coherent() Add a check for dma_alloc_coherent() failure to prevent a potential NULL pointer dereference in dma_handle_rx(). Proper... read CVE-2026-64234
    Published: 七月 24, 2026; 12:16:52 下午 -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-64235 - In the Linux kernel, the following vulnerability has been resolved: x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines With CONFIG_CALL_DEPTH_TRACKING enabled on an x86 retbleed-affected platform (eg: Skylake), with retbleed=s... read CVE-2026-64235
    Published: 七月 24, 2026; 12:16:52 下午 -0400

Created September 20, 2022 , Updated August 27, 2024