|
1
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: file: Use kzalloc_flex for aio_cmd
The target_core_file doesn't initialize the aio_cmd->iocb for the
ki_write_strea…
Update
|
NVD-CWE-noinfo
|
CVE-2026-43055
|
2026-05-8 03:58 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
vxlan: validate ND option lengths in vxlan_na_create
vxlan_na_create() walks ND options according to option-provided
lengths. A m…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31738
|
2026-05-8 03:58 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: ftgmac100: fix ring allocation unwind on open failure
ftgmac100_alloc_rings() allocates rx_skbs, tx_skbs, rxdes, txdes, and
…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31737
|
2026-05-8 03:55 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-8081
|
2026-05-8 03:51 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controller…
New
|
CWE-284
Improper Access Control
|
CVE-2026-37709
|
2026-05-8 03:50 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6
|
- |
|
-
|
-
|
npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().
New
|
-
|
CVE-2025-63703
|
2026-05-8 03:50 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7
|
- |
|
-
|
-
|
NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.
New
|
-
|
CVE-2025-63704
|
2026-05-8 03:50 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
8
|
7.5 |
HIGH
Network
|
-
|
-
|
Regex Denial of Service in youtube-regex npm package through version 1.0.5.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-65122
|
2026-05-8 03:50 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
9
|
6.8 |
MEDIUM
Physics
|
-
|
-
|
Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal.
New
|
CWE-1263
Improper Physical Access Control
|
CVE-2025-4386
|
2026-05-8 03:46 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
10
|
6.8 |
MEDIUM
Physics
|
-
|
-
|
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.
New
|
CWE-313
Cleartext Storage in a File or on Disk
|
CVE-2025-4397
|
2026-05-8 03:46 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|