Search

Found 5,388 results in 603ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-0968 low 3.1 3.1 FIX rheldebian debian sles libssh 16d ago Moderate: libssh security update
CVE-2026-0966 high 8.2 8.2 FIX rheldebian debian sles libsshredhat 16d ago Moderate: libssh security update
CVE-2026-0965 low 3.3 3.3 FIX rheldebian debian sles libssh 16d ago Moderate: libssh security update
CVE-2026-0672 high 8.0 FIX rhel slesdebian debian 16d ago When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and para…
CVE-2025-9615 low 3.3 3.3 FIX rhel slesdebian debian 16d ago Low: NetworkManager security update
CVE-2025-8277 low 3.1 3.1 FIX rheldebian debian sles 16d ago Moderate: libssh security update
CVE-2025-68121 critical 10.0 10.0 FIX rocky rheldebian debian golanggoogle 16d ago RHSA-2026:22714: osbuild-composer security update (Important)
CVE-2025-61726 high 8.0 FIX rocky rheldebian debian google 16d ago RHSA-2026:22714: osbuild-composer security update (Important)
CVE-2025-55754 critical 9.6 9.6 FIX rhel slesdebian debian apache 16d ago Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Win…
CVE-2025-55668 high 8.0 FIX rhel slesdebian debian 16d ago Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Old…
CVE-2025-4878 low 3.6 3.6 FIX rheldebian debian sles 16d ago Moderate: libssh security update
CVE-2025-46701 high 8.0 FIX arch arch rhel sles 16d ago Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to th…
CVE-2025-46299 high 8.0 FIX rhel slesdebian debian 16d ago A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Proc…
CVE-2025-43511 high 8.0 FIX rhel slesdebian debian 16d ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watc…
CVE-2025-43457 high 8.0 FIX rhel slesdebian debian 16d ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing malicious…
CVE-2025-43214 high 8.0 FIX rhel slesdebian debian 16d ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously …
CVE-2025-43213 high 8.0 FIX rhel slesdebian debian 16d ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously …
CVE-2025-39866 high 7.8 7.8 FIX rhel slesdebian debian 16d ago In the Linux kernel, the following vulnerability has been resolved: fs: writeback: fix use-after-free in __mark_inode_dirty() An use-after-free issue occurred when __mark_inode_dirty() get the bdi_…
CVE-2025-15284 high 8.0 FIX rheldebian debian 16d ago Important: linux-sgx security update
CVE-2025-15282 high 8.0 FIX rhel slesdebian debian 16d ago User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.
CVE-2025-13837 high 8.0 FIX rhel slesdebian debian 16d ago When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
CVE-2025-11234 high 7.5 7.5 FIX rocky rhel sles 16d ago A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use…
CVE-2026-42009 high 7.5 7.5 FIX debian debian sleswindows windows 17d ago RHSA-2026:20612: gnutls security update (Important)
CVE-2026-42945 high 8.1 8.1 FIX rhel slesdebian debian 17d ago RHSA-2026:18041: nginx:1.24 security update (Critical)
CVE-2026-41316 high 8.1 8.1 FIX rhel slesdebian debian google 17d ago ERB has an @_init deserialization guard bypass via
CVE-2026-40164 high 7.5 7.5 FIX rheldebian debian sles 22d ago Important: jq security update
CVE-2026-39979 high 8.0 FIX rheldebian debian sles 22d ago Important: jq security update
CVE-2026-4887 high 7.1 7.1 FIX rheldebian debian sles gimp 23d ago Important: gimp security update
CVE-2026-43284 high 8.8 9.8 EXPFIX rhel slesdebian debian awsgoogle 23d ago In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks…
CVE-2026-4154 high 8.0 FIX rheldebian debian sles 23d ago Important: gimp security update
CVE-2026-4153 high 8.0 FIX rheldebian debian sles 23d ago Important: gimp security update
CVE-2026-4152 high 8.0 FIX rheldebian debian sles 23d ago Important: gimp security update
CVE-2026-4151 high 8.0 FIX rheldebian debian sles 23d ago Important: gimp security update
CVE-2026-4150 high 8.0 FIX rheldebian debian sles 23d ago Important: gimp security update
CVE-2026-4802 high 8.0 8.0 FIX debian debian rhel sles 24d ago A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links i…
CVE-2026-45186 high 7.5 7.5 FIX debian debian sleswindows windows libexpat_project 25d ago RHSA-2026:22721: expat security update (Important)
CVE-2026-7568 high 7.5 7.5 FIX slesdebian debianwindows windows php 25d ago Important: php:8.2 security update
CVE-2026-7262 high 7.5 7.5 FIX slesdebian debianwindows windows php 25d ago Important: php:8.2 security update
CVE-2026-7258 high 7.5 7.5 FIX slesdebian debianwindows windows php 25d ago Important: php:8.2 security update
CVE-2026-43303 high 7.8 7.8 FIX sles rheldebian debian 27d ago In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: clear page->private in free_pages_prepare() Several subsystems (slub, shmem, ttm, etc.) use page->private but don'…
CVE-2026-42011 high 7.4 7.4 FIX debian debian sleswindows windows 28d ago RHSA-2026:20612: gnutls security update (Important)
CVE-2026-42010 high 7.1 7.1 FIX debian debian sles rhel gnuredhat 28d ago RHSA-2026:20612: gnutls security update (Important)
CVE-2026-33636 high 8.0 FIX rheldebian debian sles 28d ago RHSA-2026:9345: thunderbird security update (Important)
CVE-2026-33554 high 7.5 7.5 FIX rheldebian debian sles 28d ago ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform m…
CVE-2026-43190 high 8.2 8.2 FIX sles rheldebian debian 29d ago In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68)…
CVE-2026-43158 high 8.8 8.8 FIX sles rheldebian debian 29d ago In the Linux kernel, the following vulnerability has been resolved: xfs: fix freemap adjustments when adding xattrs to leaf blocks xfs/592 and xfs/794 both trip this assertion in the leaf block fre…
CVE-2026-43110 high 8.8 8.8 FIX sles rheldebian debian 29d ago In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: validate bsscfg indices in IF events brcmf_fweh_handle_if_event() validates the firmware-provided interface index…
CVE-2026-30922 high 7.5 7.5 FIX rhel sles rocky pyasn1 29d ago RHSA-2026:13902: resource-agents security update (Important)
CVE-2026-28780 critical 9.8 9.8 FIX debian debian rhel sles apache 29d ago Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy…
CVE-2026-35092 high 7.5 7.5 FIX rheldebian debian sles corosyncredhat 1mo ago A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) pac…
CVE-2026-35091 high 8.2 8.2 FIX rheldebian debian sles corosyncredhat 1mo ago A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User…
CVE-2026-27858 high 7.5 7.5 FIX rheldebian debian sles dovecotopen-xchange 1mo ago Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeated…
CVE-2026-27857 high 7.5 7.5 FIX rheldebian debian sles dovecotopen-xchange 1mo ago Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer t…
CVE-2026-26007 high 8.0 FIX rhel sles rocky 1mo ago RHSA-2026:12176: fence-agents security update (Important)
CVE-2026-25679 high 8.0 FIX rocky rheldebian debian google 1mo ago RHSA-2026:22714: osbuild-composer security update (Important)
CVE-2025-68724 high 8.0 FIX sles rheldebian debian 1mo ago In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id Use check_add_overflow() to guard against potential inte…
CVE-2025-59032 high 7.5 7.5 FIX rheldebian debian sles dovecotopen-xchange 1mo ago ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access t…
CVE-2025-40252 high 8.0 FIX slesdebian debian rhel 1mo ago In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() The loops in 'qede_tpa_cont()' and 'qede…
CVE-2026-34059 high 7.5 7.5 FIX debian debian rhel sles apache 1mo ago Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
CVE-2026-33846 high 7.5 7.5 FIX debian debian sleswindows windows 1mo ago RHSA-2026:20612: gnutls security update (Important)
CVE-2026-35414 high 8.0 FIX rhel slesdebian debian google 1mo ago Important: openssh security update
CVE-2026-35388 high 8.0 FIX rhel slesdebian debian 1mo ago Important: openssh security update
CVE-2026-35387 high 8.0 FIX rhel slesdebian debian 1mo ago Important: openssh security update
CVE-2026-35386 high 8.0 FIX rhel slesdebian debian google 1mo ago Important: openssh security update
CVE-2026-35385 high 8.0 FIX rhel slesdebian debian google 1mo ago Important: openssh security update
CVE-2026-31431 high 7.8 10.0 KEVEXPFIX rhelarch arch sles redhatsusearista 1mo ago Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
CVE-2026-31402 critical 9.8 9.8 FIX rhel sles rocky 1mo ago In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_…
CVE-2026-24660 high 8.0 FIX debian debian sles rhel 1mo ago RHSA-2026:13284: LibRaw security update (Important)
CVE-2026-23270 high 7.8 7.8 FIX rhel sles rocky 1mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks As Paolo said earlier [1]: "Since the blamed com…
CVE-2026-23136 high 8.0 FIX rhel slesdebian debian 1mo ago In the Linux kernel, the following vulnerability has been resolved: libceph: reset sparse-read state in osd_fault() When a fault occurs, the connection is abandoned, reestablished, and any pending …
CVE-2026-20889 high 8.0 FIX debian debian sles rhel 1mo ago RHSA-2026:13284: LibRaw security update (Important)
CVE-2026-43051 high 8.1 8.1 FIX sles rheldebian debian 1mo ago In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq The wacom_intuos_bt_irq() function processes Bluetooth HID reports with…
CVE-2026-43027 high 7.8 7.8 FIX sles rheldebian debian google 1mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_helper: pass helper to expect cleanup nf_conntrack_helper_unregister() calls nf_ct_expect_iterate_destroy…
CVE-2026-43023 high 7.8 7.8 FIX sles rheldebian debian 1mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: fix race conditions in sco_sock_connect() sco_sock_connect() checks sk_state and sk_type without holding the sock…
CVE-2026-43020 high 7.8 7.8 FIX sles rheldebian debian 1mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate LTK enc_size on load Load Long Term Keys stores the user-provided enc_size and later uses it to size fi…
CVE-2026-31709 high 8.8 8.8 FIX sles rheldebian debian google 1mo ago In the Linux kernel, the following vulnerability has been resolved: smb: client: validate the whole DACL before rewriting it in cifsacl build_sec_desc() and id_mode_to_cifs_acl() derive a DACL poin…
CVE-2026-3832 low 3.7 3.7 FIX debian debian rhel gnuredhat 1mo ago RHSA-2026:20612: gnutls security update (Important)
CVE-2026-33845 high 7.5 7.5 FIX debian debian sles rhel gnuredhat 1mo ago RHSA-2026:20612: gnutls security update (Important)
CVE-2026-4775 high 7.8 7.8 FIX rhel sles rocky libtiffredhat 1mo ago RHSA-2026:20585: compat-libtiff3 security update (Important)
CVE-2026-35535 high 7.8 7.8 FIX rhel sles rocky sudo_projectsiemens 1mo ago In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
CVE-2026-42198 high 7.5 7.5 FIX debian debian sles rhel postgresql 1mo ago RHSA-2026:22304: postgresql-jdbc security update (Important)
CVE-2026-41651 high 8.8 8.8 FIX rhel sles rocky packagekit_project 1mo ago Important: PackageKit security update
CVE-2026-34982 high 8.0 FIX rhel sles rocky 1mo ago RHSA-2026:11509: vim security update (Important)
CVE-2026-24450 high 8.0 FIX rheldebian debian sles 1mo ago Important: LibRaw security update
CVE-2026-21413 high 8.0 FIX rheldebian debian sles 1mo ago Important: LibRaw security update
CVE-2026-6786 high 7.5 7.5 FIX rheldebian debian rocky mozilla 1mo ago Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
CVE-2026-6785 high 7.5 7.5 FIX rheldebian debian rocky mozilla 1mo ago Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume tha…
CVE-2026-6776 high 8.0 FIX rheldebian debian rocky 1mo ago Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6772 high 8.0 FIX rheldebian debian rocky 1mo ago Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6771 high 8.0 FIX rheldebian debian rocky 1mo ago Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6770 high 8.0 FIX rheldebian debian rocky 1mo ago Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6769 high 8.0 FIX rheldebian debian rocky 1mo ago Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6767 high 8.0 FIX rheldebian debian rocky 1mo ago Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6766 high 8.0 FIX rheldebian debian rocky 1mo ago Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6765 high 8.0 FIX rheldebian debian rocky 1mo ago Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6764 high 8.0 FIX rheldebian debian rocky 1mo ago Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6763 high 8.0 FIX rheldebian debian rocky 1mo ago Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6762 high 8.0 FIX rheldebian debian rocky 1mo ago Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6761 high 8.0 FIX rheldebian debian rocky 1mo ago Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6759 high 8.0 FIX rheldebian debian rocky 1mo ago Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.