Currently trending CVE - Hype Score: 4 - Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Currently trending CVE - Hype Score: 1 - LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. ...
Currently trending CVE - Hype Score: 1 - In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles ...
Currently trending CVE - Hype Score: 1 - In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.
The app contains an `authorize.conf` configuration file ...
Currently trending CVE - Hype Score: 1 - In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain ...
A vulnerability identified as critical has been detected in Linux Kernel up to 6.18.19/6.19.9/7.0-rc4. The affected element is the function synchronize_irq of the component IRQ Handler. Performing a manipulation results in denial of service.
This vulnerability is cataloged as CVE-2026-23469. The attack must originate from the local network. There is no exploit available.
You should upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.18.19/6.19.9/7.0-rc4. Affected by this vulnerability is an unknown functionality of the component amdgpu. Such manipulation of the argument bo_number leads to resource consumption.
This vulnerability is traded as CVE-2026-23468. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.19/6.19.9/7.0-rc2. This affects the function check_bo_args_are_sane of the component xe. Executing a manipulation can lead to memory leak.
This vulnerability is handled as CVE-2026-31390. The attack can only be done within the local network. There is not any exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 7.0-rc4. Impacted is the function match_session of the file /etc/krb5.keytab of the component SMB Client. The manipulation results in password hash with insufficient computational effort.
This vulnerability is known as CVE-2026-31392. Access to the local network is required for this attack. No exploit is available.
You should upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 7.0-rc4 and classified as critical. The affected element is the function l2cap_information_rsp of the component Bluetooth. This manipulation causes out-of-bounds read.
This vulnerability is handled as CVE-2026-31393. The attack can only be done within the local network. There is not any exploit available.
The affected component should be upgraded.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.12.77/6.18.19/6.19.9/7.0-rc4. Impacted is the function disable_irq. Executing a manipulation can lead to deadlock.
This vulnerability is tracked as CVE-2026-23470. The attack is only possible within the local network. No exploit exists.
The affected component should be upgraded.
A vulnerability has been found in Linux Kernel up to 7.0-rc2 and classified as critical. Affected by this issue is the function tfm_count of the component crypto. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2026-31391. Access to the local network is required for this attack to succeed. There is no exploit available.
The affected component should be upgraded.
A vulnerability categorized as critical has been discovered in prompts.chat. This impacts an unknown function. The manipulation results in path traversal.
This vulnerability was named CVE-2026-22661. The attack may be performed from remote. There is no available exploit.
It is advisable to implement a patch to correct this issue.