Search

Found 9,703 results in 767ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-4271 high 7.5 7.5 debian debian sles rhel gnome 3mo ago A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sen…
CVE-2025-61662 high 7.8 7.8 FIX rheldebian debian sles gnu 3mo ago Moderate: grub2 security update
CVE-2026-32597 high 7.5 7.5 FIX rhel sles rocky pyjwt_project 3mo ago RHSA-2026:12176: fence-agents security update (Important)
CVE-2026-27940 high 7.8 7.8 FIX debian debian ggml 3mo ago llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Us…
CVE-2026-23239 high 7.8 7.8 FIX slesdebian debian linux-kernel 3mo ago In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() This issue was discovered during a code audit. After cancel_work_sync() is call…
CVE-2026-2048 high 8.0 FIX rocky rheldebian debian 3mo ago RHSA-2026:5113: gimp:2.8 security update (Important)
CVE-2026-2047 high 8.0 FIX rheldebian debian sles 3mo ago Important: gimp security update
CVE-2026-2045 high 8.0 FIX rocky rheldebian debian 3mo ago RHSA-2026:5113: gimp:2.8 security update (Important)
CVE-2026-2044 high 8.0 FIX rocky rheldebian debian 3mo ago RHSA-2026:5113: gimp:2.8 security update (Important)
CVE-2026-0797 high 8.0 FIX rocky rheldebian debian 3mo ago RHSA-2026:5113: gimp:2.8 security update (Important)
CVE-2026-2219 high 7.5 7.5 FIX debian debian sles debiangoogle 3mo ago It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, wh…
CVE-2025-69654 high 7.5 7.5 debian debian quickjs_project 3mo ago A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-11),`qjs` interpreter using the `-m` option and a low memory…
CVE-2025-69534 high 8.0 FIX rhel slesdebian debian 3mo ago Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-M…
CVE-2026-0847 high 7.5 7.5 FIX debian debian nltk 3mo ago A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and Brac…
CVE-2026-23236 high 7.3 7.3 FIX slesdebian debian linux-kernel 3mo ago In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: properly copy ioctl memory to kernelspace The UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from user…
CVE-2026-2006 high 8.0 FIX rocky rhel sles 3mo ago RHSA-2026:4064: postgresql:12 security update (Important)
CVE-2026-2005 high 8.0 FIX rocky rhel sles 3mo ago RHSA-2026:4064: postgresql:12 security update (Important)
CVE-2026-2004 high 8.0 FIX rocky rhel sles 3mo ago RHSA-2026:4064: postgresql:12 security update (Important)
CVE-2026-2003 high 8.0 FIX rocky rhel sles 3mo ago RHSA-2026:4063: postgresql:16 security update (Important)
CVE-2026-21863 high 8.0 FIX rhel sles rocky 3mo ago Important: valkey security update
CVE-2025-67733 high 8.0 FIX rhel sles rocky 3mo ago Important: valkey security update
CVE-2026-3281 high 7.8 7.8 FIX debian debian libvips 3mo ago A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conversion/bandrank.c. Performing a manipulation of the argument index results in hea…
CVE-2026-22801 high 8.0 FIX rocky rheldebian debian 3mo ago RHSA-2026:4728: libpng security update (Important)
CVE-2026-22695 high 8.0 FIX rocky rheldebian debian 3mo ago RHSA-2026:4728: libpng security update (Important)
CVE-2026-3147 high 7.8 7.8 FIX debian debian libvips 3mo ago A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow.…
CVE-2026-2793 high 8.0 FIX rocky rheldebian debian 3mo ago Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume tha…
CVE-2026-2792 high 8.0 FIX rocky rheldebian debian 3mo ago Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
CVE-2026-2791 high 8.0 FIX rocky rheldebian debian 3mo ago Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2790 high 8.0 FIX rocky rheldebian debian 3mo ago Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2789 high 8.0 FIX rocky rheldebian debian 3mo ago Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2788 high 8.0 FIX rocky rheldebian debian 3mo ago Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2787 high 8.0 FIX rocky rheldebian debian 3mo ago Use-after-free in the DOM: Window and Location component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2785 high 8.0 FIX rocky rheldebian debian 3mo ago Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2784 high 8.0 FIX rocky rheldebian debian 3mo ago Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2783 high 8.0 FIX rocky rheldebian debian 3mo ago Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2782 high 8.0 FIX rocky rheldebian debian 3mo ago Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2781 high 8.0 FIX rocky rheldebian debian 3mo ago Integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, Thunderbird 140.8, and Firefox ESR 115.35.
CVE-2026-2780 high 8.0 FIX rocky rheldebian debian 3mo ago Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2779 high 8.0 FIX rocky rheldebian debian 3mo ago Incorrect boundary conditions in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2778 high 8.0 FIX rocky rheldebian debian 3mo ago Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunder…
CVE-2026-2777 high 8.0 FIX rocky rheldebian debian 3mo ago Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2776 high 8.0 FIX rocky rheldebian debian 3mo ago Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 14…
CVE-2026-2775 high 8.0 FIX rocky rheldebian debian 3mo ago Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2774 high 8.0 FIX rocky rheldebian debian 3mo ago Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2773 high 8.0 FIX rocky rheldebian debian 3mo ago Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2772 high 8.0 FIX rocky rheldebian debian 3mo ago Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2771 high 8.0 FIX rocky rheldebian debian 3mo ago Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2770 high 8.0 FIX rocky rheldebian debian 3mo ago Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2769 high 8.0 FIX rocky rheldebian debian 3mo ago Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2768 high 8.0 FIX rocky rheldebian debian 3mo ago Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2767 high 8.0 FIX rocky rheldebian debian 3mo ago Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2766 high 8.0 FIX rocky rheldebian debian 3mo ago Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2765 high 8.0 FIX rocky rheldebian debian 3mo ago Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2764 high 8.0 FIX rocky rheldebian debian 3mo ago JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2763 high 8.0 FIX rocky rheldebian debian 3mo ago Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2762 high 8.0 FIX rocky rheldebian debian 3mo ago Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2761 high 8.0 FIX rocky rheldebian debian 3mo ago Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2760 high 8.0 FIX rocky rheldebian debian 3mo ago Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thun…
CVE-2026-2759 high 8.0 FIX rocky rheldebian debian 3mo ago Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2758 high 8.0 FIX rocky rheldebian debian 3mo ago Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2757 high 8.0 FIX rocky rheldebian debian 3mo ago Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2447 high 8.0 FIX rocky rheldebian debian 3mo ago Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.
CVE-2026-3102 high 8.8 8.8 FIX debian debianmacos macos exiftool_project 3mo ago A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulati…
CVE-2026-25646 high 8.0 FIX rocky rheldebian debian 3mo ago RHSA-2026:9686: java-17-openjdk security update (Important)
CVE-2026-25506 high 8.0 FIX rocky rhel sles 3mo ago RHSA-2026:3032: munge security update (Important)
CVE-2026-23074 high 8.0 FIX slesdebian debianalmalinux almalinux 3mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: Enforce that teql can only be used as root qdisc Design intent of teql is that it is only supposed to be used as root …
CVE-2026-22859 high 8.0 FIX rocky rheldebian debian 3mo ago RHSA-2026:3334: freerdp security update (Important)
CVE-2026-22858 high 8.0 FIX rocky rheldebian debian 3mo ago RHSA-2026:3334: freerdp security update (Important)
CVE-2026-22855 high 8.0 FIX rocky rheldebian debian 3mo ago RHSA-2026:3334: freerdp security update (Important)
CVE-2025-38248 high 8.0 FIX slesdebian debianalmalinux almalinux 3mo ago In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix use-after-free during router port configuration The bridge maintains a global list of ports behind which a mul…
CVE-2026-2913 high 7.0 7.0 FIX slesdebian debian libvips 3mo ago A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation causes heap-based buffe…
CVE-2026-2705 high 8.1 8.1 debian debian openbabel 4mo ago A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The ma…
CVE-2026-2661 high 7.8 7.8 slesdebian debian squirrel-lang 4mo ago A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. …
CVE-2026-2659 high 7.8 7.8 debian debian squirrel-lang 4mo ago A vulnerability was determined in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTarget of the file src/squirrel/squirrel/sqfuncstate.cpp. Executing a manipulation…
CVE-2026-23230 high 8.8 8.8 FIX slesdebian debian linux-kernel 4mo ago In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid shared-byte RMW races is_open, has_lease and on_list are stored in the same bitf…
CVE-2026-23222 high 7.8 7.8 FIX slesdebian debian linux-kernel 4mo ago In the Linux kernel, the following vulnerability has been resolved: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly The existing allocation of scatterlists in omap_crypto_copy…
CVE-2026-2653 high 7.8 7.8 debian debian admesh_project 4mo ago A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Performing a manipulation results in heap-based buffer o…
CVE-2026-2644 high 7.8 7.8 debian debian minisat 4mo ago A weakness has been identified in niklasso minisat up to 2.2.0. This issue affects the function Solver::value in the library core/SolverTypes.h of the component DIMACS File Parser. This manipulation …
CVE-2026-21637 high 8.0 FIX rocky rhel sles 4mo ago Important: nodejs:24 security update
CVE-2025-59466 high 8.0 FIX rocky rhel sles 4mo ago Important: nodejs:24 security update
CVE-2025-59465 high 8.0 FIX rocky rhel sles 4mo ago Important: nodejs:24 security update
CVE-2025-55132 high 8.0 FIX rocky rhel sles 4mo ago Important: nodejs:24 security update
CVE-2025-55131 high 8.0 FIX rocky rhel sles 4mo ago Important: nodejs:24 security update
CVE-2025-55130 high 8.0 FIX rocky rhel sles 4mo ago Important: nodejs:24 security update
CVE-2025-61732 high 8.0 FIX rocky rheldebian debian google 4mo ago A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVE-2025-61728 high 8.0 FIX rocky rheldebian debian google 4mo ago archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously construct…
CVE-2025-15059 high 8.0 FIX rheldebian debian sles 4mo ago Important: gimp security update
CVE-2025-71221 high 7.0 7.0 FIX slesdebian debian linux-kernel 4mo ago In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() Add proper locking in mmp_pdma_residue() to prevent use-after-free …
CVE-2026-26158 high 7.0 7.0 FIX debian debian sles 4mo ago A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or …
CVE-2026-26157 high 7.0 8.0 EXPFIX debian debian sles 4mo ago A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may wr…
CVE-2026-25990 high 7.5 7.5 FIX slesdebian debian python 4mo ago Pillow affected by out-of-bounds write when loading PSD images
CVE-2025-15570 high 7.8 7.8 FIX debian debian ckolivas 4mo ago A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is …
CVE-2026-25639 high 7.5 7.5 FIX debian debian axios 4mo ago Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
CVE-2026-1761 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2215: libsoup security update (Important)
CVE-2026-0719 high 8.0 rocky rheldebian debian 4mo ago RHSA-2026:2215: libsoup security update (Important)
CVE-2025-39760 high 7.1 7.1 FIX rocky rhel sles 4mo ago Moderate: kernel security update
CVE-2026-23884 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2081: freerdp security update (Important)
CVE-2026-23883 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2081: freerdp security update (Important)
CVE-2026-23534 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2081: freerdp security update (Important)
CVE-2026-23533 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2081: freerdp security update (Important)