Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 15 August 2026
RSS1601 vulnerabilities published on 15 August 2026
Severity:
Pandora TAR Archive Extraction Allows Malicious File Writes
CVE-2026-74764
Pandora's TAR archive extraction feature can be exploited by submitting a specially crafted archive. This could allow an attacker to write files outside the intended directory, potentially leading to ...
10.0
Linux Kernel: Insecure MAC Address Reading in VXLAN
CVE-2026-74475
DEBIAN-CVE-2026-74475
UBUNTU-CVE-2026-74475
A bug in the Linux kernel's VXLAN (Virtual Extensible LAN) implementation can cause a system to read an incorrect or partially updated MAC address from a neighbor. This can lead to network connectivit...
10.0
Geneve Software: Unvalidated Data Read
CVE-2026-72408
DEBIAN-CVE-2026-72408
UBUNTU-CVE-2026-72408
A vulnerability in the Geneve software could allow an attacker to access memory outside the allowed range, potentially causing the system to crash or behave unexpectedly. This issue affects systems th...
10.0
Cavium CPT Crypto: DMA Cleanup Error Can Leak Memory
CVE-2026-74279
DEBIAN-CVE-2026-74279
UBUNTU-CVE-2026-74279
A bug in the Cavium CPT crypto module in Linux can cause memory leaks when unmapping DMA buffers. This can lead to system instability and crashes. To fix this issue, update your Linux kernel to the la...
10.0
Linux IPv4 Routing Error: Unreachable Networks Exposed
DEBIAN-CVE-2026-72421
CVE-2026-72421
UBUNTU-CVE-2026-72421
A Linux kernel vulnerability could allow users to access networks they shouldn't be able to reach. This issue affects Linux systems with multiple routing tables enabled. To fix it, update your Linux k...
10.0
Linux kernel Geneve tunnel may mishandle network packets
CVE-2026-72407
DEBIAN-CVE-2026-72407
UBUNTU-CVE-2026-72407
The Linux operating system's networking component for Geneve tunnels could miscalculate where a packet's inner data starts, especially when changes happen at the same time. This can cause the system t...
10.0
Linux Kernel: DMA Buffers Leaked in Octeontx Crypto Module
CVE-2026-74280
DEBIAN-CVE-2026-74280
UBUNTU-CVE-2026-74280
A bug in the Linux kernel's crypto module for Marvell Octeontx hardware can cause DMA buffers to be leaked. This means that some memory is not properly released, which can lead to performance issues a...
10.0
Linux Kernel: Incorrect Interrupt Handling on Octeon EP
CVE-2026-74309
DEBIAN-CVE-2026-74309
UBUNTU-CVE-2026-74309
The Linux kernel's handling of interrupts on Octeon EP devices has been fixed to prevent incorrect ring indexing. This issue could cause unexpected behavior or crashes on systems using these devices. ...
10.0
Linux Kernel: Unregistered Network Device Allows Packet Escape
CVE-2026-72493
DEBIAN-CVE-2026-72493
UBUNTU-CVE-2026-72493
A bug in the Linux kernel allowed packets to be sent to a network device even after it was being shut down. This could cause issues with network communication. To fix this, the kernel has been updated...
9.9
SiYuan before 3.7.4 allows unauthorized access to admin panel
CVE-2026-73046
SiYuan versions before 3.7.4 have a security issue that allows unauthorized users to access the admin panel. This could be exploited by hackers to gain control over the system. To fix this, update SiY...
9.3
WordPress Pods <= 3.3.9 - Unauthenticated Attackers Can Take Over Your Site
CVE-2026-19598
The Pods plugin for WordPress has a security flaw that lets attackers take control of your site without needing a password. This could let them change passwords, delete content, or even lock you out o...
9.8
Dancer2::Plugin::Auth::Extensible password reset link manipulation via Host header
CVE-2026-15689
Dancer2::Plugin::Auth::Extensible versions for Perl, through 0.713, contain a security risk where attackers can manipulate password reset links by exploiting the Host header in email links. This could...
9.8
Linux Kernel: Overflow in SCSI Response Data
CVE-2026-74556
DEBIAN-CVE-2026-74556
UBUNTU-CVE-2026-74556
A Linux kernel vulnerability could cause a buffer overflow when handling a specific type of SCSI response data. This could potentially lead to a system crash or data corruption. To address this issue,...
9.8
Windows File System (NTFS) Data Corruption Risk on Linux
CVE-2026-74570
DEBIAN-CVE-2026-74570
UBUNTU-CVE-2026-74570
A Linux kernel update fixes a bug that could cause Windows file systems to become corrupted. This is a concern for Linux users who access Windows files. To stay protected, ensure your Linux system is ...
9.8
Linux Kernel: SIP Message Rewrite Vulnerability
CVE-2026-74569
DEBIAN-CVE-2026-74569
UBUNTU-CVE-2026-74569
A vulnerability in the Linux kernel's SIP message rewrite function can cause a use-after-free error, potentially leading to system crashes. This issue affects systems using the SIP protocol, particula...
9.8
Linux Kernel: Double Free of Network Data on DMA Failure
CVE-2026-74545
DEBIAN-CVE-2026-74545
UBUNTU-CVE-2026-74545
A vulnerability in the Linux kernel's network handling could cause data corruption or crashes when a network packet fails to be sent due to a memory mapping error. This affects Linux systems with netw...
9.8
Linux Kernel: Bridge Fast-Leave Can Crash System
CVE-2026-74480
DEBIAN-CVE-2026-74480
UBUNTU-CVE-2026-74480
A bug in the Linux kernel's bridge feature can cause a crash if a network port group is deleted while a fast-leave operation is in progress. This issue can be fixed by updating the Linux kernel, which...
9.8
Linux Kernel GRE and L2TPv3 Transport Fix: Prevent Use-After-Free
CVE-2026-74478
DEBIAN-CVE-2026-74478
UBUNTU-CVE-2026-74478
A security issue in the Linux kernel's GRE and L2TPv3 transport protocols can cause a data corruption error when receiving certain types of packets. This issue allows an unauthorized peer to trigger t...
9.8
Linux Kernel SMC Socket Use-After-Free Fix
DEBIAN-CVE-2026-74493
CVE-2026-74493
UBUNTU-CVE-2026-74493
A fix has been made to prevent a situation where a Linux kernel's SMC socket is accidentally deleted while still being used, potentially causing system crashes or errors. This issue is resolved in the...
9.8
Linux Kernel: Vulnerability in VxLAN Packet Handling
CVE-2026-74473
DEBIAN-CVE-2026-74473
UBUNTU-CVE-2026-74473
A Linux kernel vulnerability affects VxLAN packet handling, potentially allowing unauthorized access to network data. This issue is resolved in updated Linux kernel versions. It is recommended to upda...
9.8
Linux Driver Leak: Unmapped TX Data May Remain in Memory
CVE-2026-74495
DEBIAN-CVE-2026-74495
UBUNTU-CVE-2026-74495
A Linux driver for network cards may leak data in memory if it encounters an error while sending data. This could potentially allow unauthorized access to sensitive information. Affected system admini...
9.8
Linux Kernel: Vulnerability in Vxlan Header Processing
CVE-2026-74474
DEBIAN-CVE-2026-74474
UBUNTU-CVE-2026-74474
A bug in the Linux kernel's Vxlan (Virtual Extensible LAN) processing could allow an attacker to access network headers that should be hidden. This issue has been fixed in a recent Linux kernel update...
6.6
Linux Kernel: Vxlan IP Header Data Exposure
A bug in the Linux kernel's vxlan feature could allow an attacker to access sensitive data in the IP header. This is a security risk because it could be used to steal information or disrupt network co...
9.8
Old Perl DBI versions allow data corruption on 32-bit systems
CVE-2026-73193
GHSA-wj3v-c3hh-mhqr
ROOT-OS-DEBIAN-12-CVE-2026-73193
DEBIAN-CVE-2026-73193
Old versions of the Perl DBI library have a security issue that can cause data corruption on 32-bit systems. This can happen when an attacker passes a very long piece of data to the library, which can...
9.8
TrueBooker plugin for WordPress: Unauthenticated Account Email Change
CVE-2026-16142
The TrueBooker plugin for WordPress allows unauthorized users to change any account's email address. This could lead to account takeover if an attacker gains control of the email address associated wi...
9.8