Search

Found 28,486 results in 6538ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-41075 high 8.8 8.8 FIX debian debian 16d ago RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft i…
CVE-2026-41074 high 7.1 7.1 FIX debian debian 16d ago RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in…
CVE-2026-41071 high 8.1 8.1 debian debian sles struktur 16d ago libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chun…
CVE-2025-68817 unknown FIX slesdebian debianubuntu ubuntu 16d ago Linux kernel (Low Latency NVIDIA) vulnerabilities
CVE-2025-68340 unknown FIX slesdebian debianubuntu ubuntu 16d ago Linux kernel (Azure) vulnerabilities
CVE-2025-68211 unknown FIX slesdebian debianubuntu ubuntu 16d ago Linux kernel (Azure) vulnerabilities
CVE-2025-40164 unknown FIX slesdebian debianubuntu ubuntu 16d ago Linux kernel (Low Latency NVIDIA) vulnerabilities
CVE-2025-38408 unknown FIX slesdebian debianubuntu ubuntu 16d ago Linux kernel (Azure) vulnerabilities
CVE-2025-38232 unknown FIX slesdebian debianubuntu ubuntu 16d ago Linux kernel (Azure) vulnerabilities
CVE-2025-38125 unknown FIX slesdebian debianubuntu ubuntu 16d ago Linux kernel (Azure) vulnerabilities
CVE-2025-38057 unknown FIX slesdebian debianubuntu ubuntu 16d ago Linux kernel (Azure) vulnerabilities
CVE-2023-54207 unknown FIX slesdebian debianubuntu ubuntu 16d ago Linux kernel (Azure) vulnerabilities
CVE-2023-53520 unknown FIX slesdebian debianubuntu ubuntu 16d ago Linux kernel (Azure) vulnerabilities
CVE-2023-32629 unknown 1.5 EXPFIX slesdebian debianubuntu ubuntu 16d ago Linux kernel vulnerabilities
CVE-2023-2640 unknown 1.5 EXPFIX debian debianubuntu ubuntu 16d ago Linux kernel vulnerabilities
CVE-2026-39824 low 3.3 3.3 FIX debian debianwindows windows 16d ago NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated strin…
CVE-2026-9256 high 8.1 8.1 FIX slesdebian debianwindows windows 16d ago NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Co…
CVE-2026-39821 critical 9.6 9.6 FIX sleswindows windowsdebian debian golang 16d ago The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com…
CVE-2026-9277 high 8.1 8.1 FIX slesdebian debian 16d ago shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which …
CVE-2026-8997 unknown FIX debian debian 16d ago vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json). This flaw occurs because the application lacks a runtime check on the length …
CVE-2026-46597 high 7.5 7.5 FIX debian debian sleswindows windows golang 17d ago An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
CVE-2026-46595 critical 10.0 10.0 FIX debian debian sleswindows windows golang 17d ago Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would…
CVE-2026-42508 critical 9.1 9.1 FIX debian debian sleswindows windows golang 17d ago Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVE-2026-39834 critical 9.1 9.1 FIX debian debian sleswindows windows golang 17d ago When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty pack…
CVE-2026-39833 critical 9.1 9.1 FIX debian debian sleswindows windows golang 17d ago The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indicatio…
CVE-2026-39832 critical 9.1 9.1 FIX debian debian sleswindows windows golang 17d ago When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forward…
CVE-2026-39831 critical 9.1 9.1 FIX debian debian sleswindows windows golang 17d ago The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch …
CVE-2026-39830 critical 9.1 9.1 FIX debian debian sleswindows windows golang 17d ago A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), r…
CVE-2026-39829 high 7.5 7.5 FIX debian debian sleswindows windows golang 17d ago The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumptio…
CVE-2026-43502 high 7.8 7.8 FIX slesdebian debianwindows windows 17d ago In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but…
CVE-2026-43501 critical 9.8 9.8 FIX slesdebian debianwindows windows 17d ago In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header…
CVE-2026-43499 high 7.8 7.8 FIX slesdebian debianwindows windows google 17d ago In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also use…
CVE-2026-43498 high 7.8 7.8 FIX slesdebian debian 17d ago In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Disallow re-exporting imported GEM objects Prevent re-exporting of imported GEM buffers by adding a custom prime_hand…
CVE-2026-43497 high 7.3 7.3 FIX slesdebian debianwindows windows 17d ago In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free dlfb_ops_mmap() uses remap_pfn_range() to map vmalloc framebu…
CVE-2026-43496 unknown FIX slesdebian debianwindows windows 17d ago In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked When red qdisc has children (eg qfq qdisc) who…
CVE-2026-43495 high 8.8 8.8 FIX slesdebian debianwindows windows 17d ago In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler t7xx_port_enum_msg_handler() uses the m…
CVE-2026-43494 high 7.8 7.8 FIX slesdebian debianwindows windows 17d ago Linux kernel vulnerabilities
CVE-2026-42002 high 7.5 7.5 FIX debian debian powerdns 18d ago Concurrency and locking defects in GSS-TSIG
CVE-2026-42001 high 7.5 7.5 FIX debian debian powerdns 18d ago Insufficient Validation of Autoprimary SOA Queries
CVE-2026-42000 high 8.6 8.6 FIX debian debian powerdns 18d ago Insufficient Validation of Names During AXFR
CVE-2026-7837 low 3.7 3.7 FIX slesdebian debian 18d ago A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited da…
CVE-2026-44075 low 3.7 3.7 FIX slesdebian debian 18d ago A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session op…
CVE-2026-44074 low 3.7 3.7 FIX slesdebian debian 18d ago Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker…
CVE-2026-44071 low 3.7 3.7 FIX slesdebian debian 18d ago Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of servic…
CVE-2026-44057 low 3.1 3.1 FIX slesdebian debian 18d ago A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authen…
CVE-2026-7836 low 3.1 3.1 FIX slesdebian debian 18d ago An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handling allows a remote authenticated attacker to cause limited data modification v…
CVE-2026-7835 low 3.1 3.1 FIX slesdebian debian 18d ago A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string pro…
CVE-2026-44072 low 3.0 3.0 FIX slesdebian debian 18d ago Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended commands or cause a minor …
CVE-2026-44070 low 3.1 3.1 FIX slesdebian debian 18d ago An unbounded memory reallocation in the charset conversion code in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted character convers…
CVE-2026-44069 low 3.9 3.9 FIX slesdebian debian 18d ago An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a minor service disruption vi…
CVE-2026-44068 high 7.6 7.6 FIX slesdebian debian 18d ago Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via…
CVE-2026-44066 high 7.1 7.1 FIX slesdebian debian 18d ago Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to obtain sensitive information or cause a minor servic…
CVE-2026-44064 high 7.1 7.1 FIX slesdebian debian 18d ago An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker to obtain limited information or cause a denial of service via a crafted ASP request.
CVE-2026-44062 high 7.5 7.5 FIX slesdebian debian 18d ago A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted …
CVE-2026-44060 high 7.5 7.5 FIX slesdebian debian 18d ago An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to cause a denial of service via a crafted DSI write request.
CVE-2026-44058 high 7.2 7.2 FIX slesdebian debian 18d ago An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenticate as an arbitrary user via the admin auth user mechanism.
CVE-2026-44055 high 7.5 7.5 FIX slesdebian debian 18d ago A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attacker to inject OS commands and execute arbitrary code.
CVE-2026-44053 high 7.4 7.4 FIX slesdebian debian 18d ago Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote attacker to obtain authentication credentials or impersonate a user via cryptanalytic at…
CVE-2026-44052 high 7.5 7.5 FIX slesdebian debian 18d ago Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files to obtain LDAP credentials.
CVE-2026-44051 high 8.1 8.1 FIX slesdebian debian 18d ago An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite arbitrary files via attacker-controlled symlink c…
CVE-2026-44050 critical 9.9 9.9 FIX slesdebian debian 18d ago A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause…
CVE-2026-44049 high 7.5 7.5 FIX slesdebian debian 18d ago An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of serv…
CVE-2026-44048 high 8.8 8.8 FIX slesdebian debian 18d ago A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of servi…
CVE-2026-44047 high 8.8 8.8 FIX slesdebian debian 18d ago An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, or cause a denial o…
CVE-2026-47372 critical 9.1 9.1 FIX debian debian 18d ago Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
CVE-2026-8632 high 7.8 7.8 FIX debian debian sles hp 18d ago A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution v…
CVE-2026-8631 critical 9.8 9.8 FIX debian debian sles hp 18d ago A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution v…
CVE-2026-47373 high 7.5 7.5 FIX debian debian 18d ago Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying has…
CVE-2026-9126 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 18d ago Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-9123 high 7.5 7.5 FIX debian debian linux-kernelwindows windows google 18d ago Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traff…
CVE-2026-9121 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 18d ago Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-9120 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 18d ago Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2026-9119 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 18d ago Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H…
CVE-2026-9118 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 18d ago Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2026-9117 high 7.5 7.5 FIX debian debian linux-kernelwindows windows google 18d ago Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a craf…
CVE-2026-9114 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 18d ago Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Hig…
CVE-2026-9112 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 18d ago Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hi…
CVE-2026-9111 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 18d ago Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-5946 high 7.5 7.5 FIX debian debian sleswindows windows isc 18d ago Bind vulnerabilities
CVE-2026-40215 unknown FIX debian debianubuntu ubuntu 18d ago OpenVPN vulnerabilities
CVE-2026-35058 unknown FIX debian debianubuntu ubuntu 18d ago OpenVPN vulnerabilities
CVE-2026-3593 critical 9.8 9.8 FIX debian debian sleswindows windows isc 18d ago Bind vulnerabilities
CVE-2026-3039 high 7.5 7.5 FIX debian debian sleswindows windows isc 18d ago Bind vulnerabilities
CVE-2026-29518 high 7.0 7.0 FIX slesdebian debianwindows windows samba 18d ago rsync vulnerabilities
CVE-2026-5056 unknown FIX debian debian slesubuntu ubuntu 18d ago GStreamer Good Plugins vulnerability
CVE-2026-9064 high 7.5 7.5 debian debian sles rhel redhat 19d ago A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated a…
CVE-2026-42960 critical 10.0 10.0 FIX slesdebian debianwindows windows nlnetlabs 19d ago Unbound vulnerabilities
CVE-2026-42959 high 7.5 7.5 FIX slesdebian debianwindows windows nlnetlabs 19d ago Unbound vulnerabilities
CVE-2026-42944 high 7.5 7.5 FIX slesdebian debianwindows windows nlnetlabs 19d ago Unbound vulnerabilities
CVE-2026-41292 high 7.5 7.5 FIX slesdebian debianwindows windows nlnetlabs 19d ago Unbound vulnerabilities
CVE-2026-41054 high 7.8 7.8 FIX debian debian sleswindows windows 19d ago haveged vulnerability
CVE-2026-40622 high 7.5 7.5 FIX slesdebian debianwindows windows nlnetlabs 19d ago Unbound vulnerabilities
CVE-2026-33278 critical 9.8 9.8 FIX slesdebian debianwindows windows nlnetlabs 19d ago Unbound vulnerabilities
CVE-2026-47732 unknown FIX debian debian 19d ago Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
CVE-2026-47730 unknown FIX debian debian 19d ago Twig: XSS in profiler HtmlDumper via unescaped template and profile names
CVE-2026-47212 unknown FIX debian debian 19d ago Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification
CVE-2026-46640 high 8.0 FIX debian debian 19d ago Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
CVE-2026-46639 high 8.0 FIX debian debian 19d ago Twig: Sandbox property and method bypass via object-destructuring assignment
CVE-2026-46637 low 2.5 FIX debian debian 19d ago Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
CVE-2026-46635 low 2.5 FIX debian debian 19d ago Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)