Aggregator
2026-05-31: Seven days of scans and probes and web traffic hitting my web server
1 hour 7 minutes hence
CVE-2026-64293 | Linux Kernel up to 6.18.38/7.1.3 iommufd iommufd_veventq_fops_read data_len buffer overflow
1 hour 14 minutes ago
A vulnerability was found in Linux Kernel up to 6.18.38/7.1.3. It has been rated as very critical. This vulnerability affects the function iommufd_veventq_fops_read of the component iommufd. This manipulation of the argument data_len causes buffer overflow.
The identification of this vulnerability is CVE-2026-64293. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-64292 | Linux Kernel up to 6.18.39/7.1.3 iommufd allocation of resources
1 hour 15 minutes ago
A vulnerability was found in Linux Kernel up to 6.18.39/7.1.3. It has been declared as critical. This affects an unknown part of the component iommufd. The manipulation results in allocation of resources.
This vulnerability was named CVE-2026-64292. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-64291 | Linux Kernel up to 6.18.38/7.1.3 iommufd iommufd_veventq_alloc veventq_depth allocation of resources
1 hour 16 minutes ago
A vulnerability was found in Linux Kernel up to 6.18.38/7.1.3. It has been classified as problematic. Affected by this issue is the function iommufd_veventq_alloc of the component iommufd. The manipulation of the argument veventq_depth leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2026-64291. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-64290 | Linux Kernel up to 6.18.38/7.1.3 iommufd iommufd_fault_fops_read infinite loop
1 hour 17 minutes ago
A vulnerability was found in Linux Kernel up to 6.18.38/7.1.3 and classified as critical. Affected by this vulnerability is the function iommufd_fault_fops_read of the component iommufd. Executing a manipulation can lead to infinite loop.
This vulnerability is handled as CVE-2026-64290. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-64289 | Linux Kernel up to 6.12.95/6.18.38/7.1.3 iommufd iommufd_hwpt_invalidate entry_num/entry_len infinite loop
1 hour 18 minutes ago
A vulnerability has been found in Linux Kernel up to 6.12.95/6.18.38/7.1.3 and classified as problematic. Affected is the function iommufd_hwpt_invalidate of the component iommufd. Performing a manipulation of the argument entry_num/entry_len results in infinite loop.
This vulnerability is known as CVE-2026-64289. Attacking locally is a requirement. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-64288 | Linux Kernel up to 6.18.38/7.1.3 KVM arm64 VNCR pseudo-TLB kvm_invalidate_vncr_va null pointer dereference
1 hour 19 minutes ago
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 6.18.38/7.1.3. This impacts the function kvm_invalidate_vncr_va of the component KVM arm64 VNCR pseudo-TLB. Such manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2026-64288. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-64287 | Linux Kernel up to 6.6.144/6.12.96/6.18.39/7.1.3 KVM arm64 pKVM hyp vCPU flush_hyp_vcpu used_lrs out-of-bounds
1 hour 20 minutes ago
A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.6.144/6.12.96/6.18.39/7.1.3. This affects the function flush_hyp_vcpu of the component KVM arm64 pKVM hyp vCPU. This manipulation of the argument used_lrs causes out-of-bounds read.
This vulnerability appears as CVE-2026-64287. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-64286 | Linux Kernel up to 6.6.144/6.12.96/6.18.38/7.1.3 KVM arm64 flush_hyp_vcpu null pointer dereference
1 hour 21 minutes ago
A vulnerability classified as very critical was found in Linux Kernel up to 6.6.144/6.12.96/6.18.38/7.1.3. The impacted element is the function flush_hyp_vcpu of the component KVM arm64. The manipulation results in null pointer dereference.
This vulnerability is reported as CVE-2026-64286. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-64295 | Linux Kernel up to 6.18.38/7.1.3/7.2-rc2 Page Ext Iteration page_ext_iter_next null pointer dereference
1 hour 23 minutes ago
A vulnerability classified as problematic has been found in Linux Kernel up to 6.18.38/7.1.3/7.2-rc2. The affected element is the function page_ext_iter_next of the component Page Ext Iteration. The manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2026-64295. The attack needs to be performed locally. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-64294 | Linux Kernel up to 7.2-rc2 mm file_owner_or_capable/owner_or_capable permission
1 hour 25 minutes ago
A vulnerability described as very critical has been identified in Linux Kernel up to 6.6.144/6.12.95/6.18.38/7.1.3/7.2-rc2. Impacted is the function file_owner_or_capable/owner_or_capable of the component mm. Executing a manipulation can lead to permission issues.
This vulnerability is registered as CVE-2026-64294. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-66012 | siyuan-note SiYuan up to 3.7.1 MCP Kernel model.CheckAuth improper authorization
1 hour 46 minutes ago
A vulnerability marked as critical has been reported in siyuan-note SiYuan up to 3.7.1. This issue affects the function model.CheckAuth of the component MCP Kernel. Performing a manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2026-66012. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-66013 | OpenRemote up to 1.26.1 Console Registration API improper authentication
1 hour 47 minutes ago
A vulnerability labeled as critical has been found in OpenRemote up to 1.26.1. This vulnerability affects unknown code of the component Console Registration API. Such manipulation leads to improper authentication.
This vulnerability is listed as CVE-2026-66013. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-66011 | ImageMagick up to 7.1.2-26 Command-Line Interface memory allocation
1 hour 48 minutes ago
A vulnerability identified as problematic has been detected in ImageMagick. This affects an unknown part of the component Command-Line Interface. This manipulation causes uncontrolled memory allocation.
This vulnerability is tracked as CVE-2026-66011. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-64281 | Linux Kernel svcrdma svc_rdma_sq_wait locking
1 hour 49 minutes ago
A vulnerability categorized as critical has been discovered in Linux Kernel. Affected by this issue is the function svc_rdma_sq_wait of the component svcrdma. The manipulation results in improper locking.
This vulnerability is identified as CVE-2026-64281. The attack can be executed remotely. There is not any exploit available.
It is advisable to implement a patch to correct this issue.
vuldb.com
CVE-2026-64282 | Linux Kernel up to 6.18.38/7.1.3 KVM kvm_translate_vncr information disclosure
1 hour 50 minutes ago
A vulnerability was found in Linux Kernel up to 6.18.38/7.1.3. It has been rated as problematic. Affected by this vulnerability is the function kvm_translate_vncr of the component KVM. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-64282. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-17434 | nanocoai NanoClaw up to 2.0.64 add_mcp_server request.ts handleAddMcpServer improper authorization (Issue 2762)
1 hour 50 minutes ago
A vulnerability was found in nanocoai NanoClaw up to 2.0.64. It has been declared as critical. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization.
The identification of this vulnerability is CVE-2026-17434. The attack may be launched remotely. Furthermore, there is an exploit available.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2026-17433 | nanocoai NanoClaw up to 2.0.64 MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization (Issue 2761)
1 hour 50 minutes ago
A vulnerability was found in nanocoai NanoClaw up to 2.0.64. It has been classified as critical. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization.
This vulnerability was named CVE-2026-17433. The attack needs to be approached locally. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
CVE-2026-64280 | Linux Kernel up to 6.18.38/7.1.3 dfl-afu afu_dma_map_region length numeric truncation error
1 hour 51 minutes ago
A vulnerability was found in Linux Kernel up to 6.18.38/7.1.3 and classified as very critical. This affects the function afu_dma_map_region of the component dfl-afu. Such manipulation of the argument length leads to numeric truncation error.
This vulnerability is uniquely identified as CVE-2026-64280. Local access is required to approach this attack. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com