U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2021-23134 - Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.
    Published: May 12, 2021; 7:15:07 PM -0400

    V2.0: 4.6 MEDIUM

  • CVE-2021-20322 - A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypa... read CVE-2021-20322
    Published: February 18, 2022; 1:15:09 PM -0500

    V3.1: 7.4 HIGH
    V2.0: 5.8 MEDIUM

  • CVE-2021-23133 - A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.a... read CVE-2021-23133
    Published: April 22, 2021; 2:15:08 PM -0400

    V3.1: 7.0 HIGH
    V2.0: 6.9 MEDIUM

  • CVE-2021-27364 - An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
    Published: March 07, 2021; 12:15:13 AM -0500

    V3.1: 7.1 HIGH
    V2.0: 3.6 LOW

  • CVE-2021-27365 - An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated ... read CVE-2021-27365
    Published: March 07, 2021; 12:15:13 AM -0500

    V3.1: 7.8 HIGH
    V2.0: 4.6 MEDIUM

  • CVE-2023-4244 - A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set element garbage ... read CVE-2023-4244
    Published: September 06, 2023; 10:15:11 AM -0400

    V3.1: 7.0 HIGH

  • CVE-2026-60846 - Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker w... read CVE-2026-60846
    Published: July 21, 2026; 6:18:22 PM -0400

  • CVE-2026-60852 - Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker... read CVE-2026-60852
    Published: July 21, 2026; 6:18:22 PM -0400

  • CVE-2026-60854 - Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access... read CVE-2026-60854
    Published: July 21, 2026; 6:18:22 PM -0400

  • CVE-2026-60855 - Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network acces... read CVE-2026-60855
    Published: July 21, 2026; 6:18:22 PM -0400

  • CVE-2026-60859 - Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network acces... read CVE-2026-60859
    Published: July 21, 2026; 6:18:23 PM -0400

  • CVE-2026-60862 - Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with ... read CVE-2026-60862
    Published: July 21, 2026; 6:18:23 PM -0400

  • CVE-2026-60864 - Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n... read CVE-2026-60864
    Published: July 21, 2026; 6:18:23 PM -0400

  • CVE-2026-60872 - Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n... read CVE-2026-60872
    Published: July 21, 2026; 6:18:24 PM -0400

  • CVE-2026-63308 - Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in ... read CVE-2026-63308
    Published: July 17, 2026; 1:17:17 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-53994 - ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 causes a... read CVE-2026-53994
    Published: July 18, 2026; 4:17:30 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-18017 - Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
    Published: July 29, 2026; 9:17:06 PM -0400

  • CVE-2026-18012 - Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
    Published: July 29, 2026; 9:17:05 PM -0400

  • CVE-2026-17993 - Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)
    Published: July 29, 2026; 9:17:03 PM -0400

  • CVE-2026-17989 - Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
    Published: July 29, 2026; 9:17:03 PM -0400

Created September 20, 2022 , Updated August 27, 2024