Common Vulnerabilities and Exposures (CVE)

CVE-2026-58093

Aug 26, 2026 05:40:30 UTC

The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently ...

CVE-2026-58094

Aug 26, 2026 05:39:42 UTC

The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after creating the object, before any memory is allocated for the object. The handler checked whet...

CVE-2026-79654

Aug 26, 2026 05:37:38 UTC

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may ...

CVE-2026-15203

Aug 26, 2026 05:36:02 UTC

Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload uns...

CVE-2026-19760

Aug 26, 2026 05:30:46 UTC

The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP Host Header in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. Thi...

CVE-2026-58097

Aug 26, 2026 05:28:17 UTC

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially exec...

CVE-2026-58096

Aug 26, 2026 05:28:09 UTC

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 an...

CVE-2026-58095

Aug 26, 2026 05:28:00 UTC

mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially exec...

CVE-2026-76149

Aug 26, 2026 04:55:14 UTC

CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.

CVE-2026-76148

Aug 26, 2026 04:55:07 UTC

CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.

CVE-2026-73335

Aug 26, 2026 04:54:58 UTC

Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through...

CVE-2026-77998

Aug 26, 2026 04:53:02 UTC

Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps ...

CVE-2026-66916

Aug 26, 2026 04:52:27 UTC

Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view. When a gallery category is protected...

CVE-2026-77997

Aug 26, 2026 04:46:54 UTC

Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules witho...

CVE-2026-58092

Aug 26, 2026 04:46:17 UTC

In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID ...