|
281
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net/sched: cls_fw: fix NULL pointer dereference on shared blocks
The old-method path in fw_classify() calls tcf_block_q() and
der…
|
-
|
CVE-2026-31421
|
2026-04-18 18:16 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ipset: drop logically empty buckets in mtype_del
mtype_del() counts empty slots below n->pos in k, but it only drops t…
|
-
|
CVE-2026-31418
|
2026-04-18 18:16 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net/x25: Fix overflow when accumulating packets
Add a check to ensure that `x25_sock.fraglen` does not overflow.
The `fraglen` a…
|
-
|
CVE-2026-31417
|
2026-04-18 18:16 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink_log: account for netlink header size
This is a followup to an old bug fix: NLMSG_DONE needs to account
for t…
|
-
|
CVE-2026-31416
|
2026-04-18 18:16 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ipv6: avoid overflows in ip6_datagram_send_ctl()
Yiming Qian reported :
<quote>
I believe I found a locally triggerable kernel b…
|
-
|
CVE-2026-31415
|
2026-04-18 18:16 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286
|
4.0 |
MEDIUM
Local
|
-
|
-
|
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
|
CWE-696
Incorrect Behavior Order
|
CVE-2026-41254
|
2026-04-18 16:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287
|
6.9 |
MEDIUM
Local
|
-
|
-
|
In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a malicious file whose name is valid output from the conduct…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-41253
|
2026-04-18 15:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288
|
8.8 |
HIGH
Network
|
-
|
-
|
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `c…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-6518
|
2026-04-18 14:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget's button URL `custom_attributes` field in all versions up to, and including, 2…
|
CWE-79
Cross-site Scripting
|
CVE-2026-6048
|
2026-04-18 14:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via external iCal feed data in all versions up to, and including, 3.1.16 due to insuffic…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4801
|
2026-04-18 14:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|