Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 15 August 2026

RSS

1601 vulnerabilities published on 15 August 2026

Severity:
Pandora TAR Archive Extraction Allows Malicious File Writes
CVE-2026-74764
Pandora's TAR archive extraction feature can be exploited by submitting a specially crafted archive. This could allow an attacker to write files outside the intended directory, potentially leading to ...
10.0
Linux Kernel: Insecure MAC Address Reading in VXLAN
CVE-2026-74475 DEBIAN-CVE-2026-74475 UBUNTU-CVE-2026-74475
A bug in the Linux kernel's VXLAN (Virtual Extensible LAN) implementation can cause a system to read an incorrect or partially updated MAC address from a neighbor. This can lead to network connectivit...
10.0
Geneve Software: Unvalidated Data Read
CVE-2026-72408 DEBIAN-CVE-2026-72408 UBUNTU-CVE-2026-72408
A vulnerability in the Geneve software could allow an attacker to access memory outside the allowed range, potentially causing the system to crash or behave unexpectedly. This issue affects systems th...
10.0
Cavium CPT Crypto: DMA Cleanup Error Can Leak Memory
CVE-2026-74279 DEBIAN-CVE-2026-74279 UBUNTU-CVE-2026-74279
A bug in the Cavium CPT crypto module in Linux can cause memory leaks when unmapping DMA buffers. This can lead to system instability and crashes. To fix this issue, update your Linux kernel to the la...
10.0
Linux IPv4 Routing Error: Unreachable Networks Exposed
DEBIAN-CVE-2026-72421 CVE-2026-72421 UBUNTU-CVE-2026-72421
A Linux kernel vulnerability could allow users to access networks they shouldn't be able to reach. This issue affects Linux systems with multiple routing tables enabled. To fix it, update your Linux k...
10.0
Linux kernel Geneve tunnel may mishandle network packets
CVE-2026-72407 DEBIAN-CVE-2026-72407 UBUNTU-CVE-2026-72407
The Linux operating system's networking component for Geneve tunnels could miscalculate where a packet's inner data starts, especially when changes happen at the same time. This can cause the system t...
10.0
Linux Kernel: DMA Buffers Leaked in Octeontx Crypto Module
CVE-2026-74280 DEBIAN-CVE-2026-74280 UBUNTU-CVE-2026-74280
A bug in the Linux kernel's crypto module for Marvell Octeontx hardware can cause DMA buffers to be leaked. This means that some memory is not properly released, which can lead to performance issues a...
10.0
Linux Kernel: Incorrect Interrupt Handling on Octeon EP
CVE-2026-74309 DEBIAN-CVE-2026-74309 UBUNTU-CVE-2026-74309
The Linux kernel's handling of interrupts on Octeon EP devices has been fixed to prevent incorrect ring indexing. This issue could cause unexpected behavior or crashes on systems using these devices. ...
10.0
Linux Kernel: Unregistered Network Device Allows Packet Escape
CVE-2026-72493 DEBIAN-CVE-2026-72493 UBUNTU-CVE-2026-72493
A bug in the Linux kernel allowed packets to be sent to a network device even after it was being shut down. This could cause issues with network communication. To fix this, the kernel has been updated...
9.9
SiYuan before 3.7.4 allows unauthorized access to admin panel
CVE-2026-73046
SiYuan versions before 3.7.4 have a security issue that allows unauthorized users to access the admin panel. This could be exploited by hackers to gain control over the system. To fix this, update SiY...
9.3
WordPress Pods <= 3.3.9 - Unauthenticated Attackers Can Take Over Your Site
CVE-2026-19598
The Pods plugin for WordPress has a security flaw that lets attackers take control of your site without needing a password. This could let them change passwords, delete content, or even lock you out o...
9.8
Dancer2::Plugin::Auth::Extensible password reset link manipulation via Host header
CVE-2026-15689
Dancer2::Plugin::Auth::Extensible versions for Perl, through 0.713, contain a security risk where attackers can manipulate password reset links by exploiting the Host header in email links. This could...
9.8
Linux Kernel: Overflow in SCSI Response Data
CVE-2026-74556 DEBIAN-CVE-2026-74556 UBUNTU-CVE-2026-74556
A Linux kernel vulnerability could cause a buffer overflow when handling a specific type of SCSI response data. This could potentially lead to a system crash or data corruption. To address this issue,...
9.8
Windows File System (NTFS) Data Corruption Risk on Linux
CVE-2026-74570 DEBIAN-CVE-2026-74570 UBUNTU-CVE-2026-74570
A Linux kernel update fixes a bug that could cause Windows file systems to become corrupted. This is a concern for Linux users who access Windows files. To stay protected, ensure your Linux system is ...
9.8
Linux Kernel: SIP Message Rewrite Vulnerability
CVE-2026-74569 DEBIAN-CVE-2026-74569 UBUNTU-CVE-2026-74569
A vulnerability in the Linux kernel's SIP message rewrite function can cause a use-after-free error, potentially leading to system crashes. This issue affects systems using the SIP protocol, particula...
9.8
Linux Kernel: Double Free of Network Data on DMA Failure
CVE-2026-74545 DEBIAN-CVE-2026-74545 UBUNTU-CVE-2026-74545
A vulnerability in the Linux kernel's network handling could cause data corruption or crashes when a network packet fails to be sent due to a memory mapping error. This affects Linux systems with netw...
9.8
Linux Kernel: Bridge Fast-Leave Can Crash System
CVE-2026-74480 DEBIAN-CVE-2026-74480 UBUNTU-CVE-2026-74480
A bug in the Linux kernel's bridge feature can cause a crash if a network port group is deleted while a fast-leave operation is in progress. This issue can be fixed by updating the Linux kernel, which...
9.8
Linux Kernel GRE and L2TPv3 Transport Fix: Prevent Use-After-Free
CVE-2026-74478 DEBIAN-CVE-2026-74478 UBUNTU-CVE-2026-74478
A security issue in the Linux kernel's GRE and L2TPv3 transport protocols can cause a data corruption error when receiving certain types of packets. This issue allows an unauthorized peer to trigger t...
9.8
Linux Kernel SMC Socket Use-After-Free Fix
DEBIAN-CVE-2026-74493 CVE-2026-74493 UBUNTU-CVE-2026-74493
A fix has been made to prevent a situation where a Linux kernel's SMC socket is accidentally deleted while still being used, potentially causing system crashes or errors. This issue is resolved in the...
9.8
Linux Kernel: Vulnerability in VxLAN Packet Handling
CVE-2026-74473 DEBIAN-CVE-2026-74473 UBUNTU-CVE-2026-74473
A Linux kernel vulnerability affects VxLAN packet handling, potentially allowing unauthorized access to network data. This issue is resolved in updated Linux kernel versions. It is recommended to upda...
9.8
Linux Driver Leak: Unmapped TX Data May Remain in Memory
CVE-2026-74495 DEBIAN-CVE-2026-74495 UBUNTU-CVE-2026-74495
A Linux driver for network cards may leak data in memory if it encounters an error while sending data. This could potentially allow unauthorized access to sensitive information. Affected system admini...
9.8
Linux Kernel: Vulnerability in Vxlan Header Processing
CVE-2026-74474 DEBIAN-CVE-2026-74474 UBUNTU-CVE-2026-74474
A bug in the Linux kernel's Vxlan (Virtual Extensible LAN) processing could allow an attacker to access network headers that should be hidden. This issue has been fixed in a recent Linux kernel update...
6.6
Linux Kernel: Vxlan IP Header Data Exposure
A bug in the Linux kernel's vxlan feature could allow an attacker to access sensitive data in the IP header. This is a security risk because it could be used to steal information or disrupt network co...
9.8
Old Perl DBI versions allow data corruption on 32-bit systems
CVE-2026-73193 GHSA-wj3v-c3hh-mhqr ROOT-OS-DEBIAN-12-CVE-2026-73193 DEBIAN-CVE-2026-73193
Old versions of the Perl DBI library have a security issue that can cause data corruption on 32-bit systems. This can happen when an attacker passes a very long piece of data to the library, which can...
9.8
TrueBooker plugin for WordPress: Unauthenticated Account Email Change
CVE-2026-16142
The TrueBooker plugin for WordPress allows unauthorized users to change any account's email address. This could lead to account takeover if an attacker gains control of the email address associated wi...
9.8