The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2021-23134 - Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.
Published: May 12, 2021; 7:15:07 PM -0400V2.0: 4.6 MEDIUM
-
CVE-2021-20322 - A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypa... read CVE-2021-20322
Published: February 18, 2022; 1:15:09 PM -0500V3.1: 7.4 HIGH
V2.0: 5.8 MEDIUM
-
CVE-2021-23133 - A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.a... read CVE-2021-23133
Published: April 22, 2021; 2:15:08 PM -0400V3.1: 7.0 HIGH
V2.0: 6.9 MEDIUM
-
CVE-2021-27364 - An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
Published: March 07, 2021; 12:15:13 AM -0500 -
CVE-2021-27365 - An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated ... read CVE-2021-27365
Published: March 07, 2021; 12:15:13 AM -0500V3.1: 7.8 HIGH
V2.0: 4.6 MEDIUM
-
CVE-2023-4244 - A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set element garbage ... read CVE-2023-4244
Published: September 06, 2023; 10:15:11 AM -0400V3.1: 7.0 HIGH
-
CVE-2026-60846 - Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker w... read CVE-2026-60846
Published: July 21, 2026; 6:18:22 PM -0400 -
CVE-2026-60852 - Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker... read CVE-2026-60852
Published: July 21, 2026; 6:18:22 PM -0400 -
CVE-2026-60854 - Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access... read CVE-2026-60854
Published: July 21, 2026; 6:18:22 PM -0400 -
CVE-2026-60855 - Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network acces... read CVE-2026-60855
Published: July 21, 2026; 6:18:22 PM -0400 -
CVE-2026-60859 - Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network acces... read CVE-2026-60859
Published: July 21, 2026; 6:18:23 PM -0400 -
CVE-2026-60862 - Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with ... read CVE-2026-60862
Published: July 21, 2026; 6:18:23 PM -0400 -
CVE-2026-60864 - Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n... read CVE-2026-60864
Published: July 21, 2026; 6:18:23 PM -0400 -
CVE-2026-60872 - Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n... read CVE-2026-60872
Published: July 21, 2026; 6:18:24 PM -0400 -
CVE-2026-63308 - Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in ... read CVE-2026-63308
Published: July 17, 2026; 1:17:17 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-53994 - ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 causes a... read CVE-2026-53994
Published: July 18, 2026; 4:17:30 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-18017 - Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: July 29, 2026; 9:17:06 PM -0400 -
CVE-2026-18012 - Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Published: July 29, 2026; 9:17:05 PM -0400 -
CVE-2026-17993 - Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)
Published: July 29, 2026; 9:17:03 PM -0400 -
CVE-2026-17989 - Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: July 29, 2026; 9:17:03 PM -0400