Search

Found 26,315 results in 8874ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-6253 medium 5.9 5.9 FIX debian debian sleswindows windows haxxgoogle 24d ago curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for differ…
CVE-2026-5773 high 7.5 7.5 FIX debian debian sleswindows windows haxxgoogle 24d ago libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avo…
CVE-2026-5545 medium 6.5 6.5 FIX debian debian sleswindows windows haxxgoogle 24d ago libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a …
CVE-2026-4873 medium 5.9 5.9 FIX debian debian sleswindows windows haxxgoogle 24d ago A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SM…
CVE-2026-41051 medium 5.0 5.0 FIX debian debian sles 24d ago csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories.
CVE-2026-45793 high 8.0 FIX debian debian 25d ago Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
CVE-2026-40164 high 7.5 7.5 FIX rheldebian debian sles 25d ago Important: jq security update
CVE-2026-39979 high 8.0 FIX rheldebian debian sles 25d ago Important: jq security update
CVE-2026-33985 medium 5.5 FIX rheldebian debian sles 25d ago Moderate: freerdp security update
CVE-2026-31885 medium 5.5 FIX rheldebian debian sles 25d ago Moderate: freerdp security update
CVE-2026-31884 medium 5.5 FIX rheldebian debian sles 25d ago Moderate: freerdp security update
CVE-2026-31883 medium 5.5 FIX rheldebian debian sles 25d ago Moderate: freerdp security update
CVE-2026-29775 medium 5.5 FIX rheldebian debian sles 25d ago Moderate: freerdp security update
CVE-2026-27951 medium 5.5 FIX rheldebian debian sles 25d ago Moderate: freerdp security update
CVE-2026-26986 medium 5.5 FIX rheldebian debian sles 25d ago Moderate: freerdp security update
CVE-2026-25952 medium 5.5 FIX rheldebian debian sles 25d ago Moderate: freerdp security update
CVE-2026-44660 high 7.5 7.5 debian debian ultrajson_project 25d ago UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an excepti…
CVE-2026-44301 high 8.1 8.1 FIX debian debian gohugo 25d ago Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, TailwindCSS), Hugo invoked the configured Node tools with…
CVE-2026-44296 high 7.5 7.5 FIX debian debian 25d ago Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow servers running with TLS enabled (the default). Whe…
CVE-2026-42268 high 7.5 7.5 FIX slesdebian debian owasp 25d ago ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused …
CVE-2026-44240 high 7.5 7.5 FIX debian debian 25d ago basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
CVE-2026-45185 critical 9.8 9.8 FIX debian debian sles exim 25d ago Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a C…
CVE-2026-42338 medium 6.1 6.1 debian debian beaugunderson 25d ago ip-address has XSS in Address6 HTML-emitting methods
CVE-2026-8430 high 8.1 8.1 FIX debian debian 25d ago SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the co…
CVE-2026-8429 high 8.8 8.8 FIX debian debian 25d ago SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context of the web server. Attackers can exploi…
CVE-2026-42177 medium 5.3 5.3 FIX debian debian 25d ago linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter i…
CVE-2026-31236 critical 9.8 9.8 debian debian 25d ago llm CLI tool contains a code injection vulnerability via `--functions` command-line argument
CVE-2026-5089 high 7.3 7.3 FIX debian debian 25d ago YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#base60 handlers. Whe…
CVE-2026-43515 critical 9.1 9.1 FIX slesdebian debian apache 25d ago Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21,…
CVE-2026-43514 low 3.7 3.7 FIX slesdebian debian apache 25d ago Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M…
CVE-2026-43513 high 7.5 7.5 FIX slesdebian debian apache 25d ago Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 …
CVE-2026-43512 critical 9.8 9.8 FIX slesdebian debian apache 25d ago DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, fr…
CVE-2026-42498 high 7.3 7.3 FIX slesdebian debian apache 25d ago Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1…
CVE-2026-41293 critical 9.8 9.8 FIX slesdebian debian apache 25d ago Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0…
CVE-2026-41284 high 7.5 7.5 FIX slesdebian debian apache 25d ago Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 t…
CVE-2026-8368 medium 6.5 6.5 FIX debian debian sleswindows windows 25d ago LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before …
CVE-2026-8390 high 7.3 7.3 FIX debian debian mozilla 25d ago Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
CVE-2026-8389 high 8.8 8.8 FIX debian debian mozilla 25d ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.
CVE-2026-42006 medium 4.3 4.3 FIX debian debian sles dovecotopen-xchange 25d ago An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left op…
CVE-2026-40020 medium 4.3 4.3 FIX debian debian sles dovecotopen-xchange 25d ago Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is lim…
CVE-2026-40016 medium 6.5 6.5 FIX debian debian sles dovecotopen-xchange 25d ago Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to deg…
CVE-2026-33603 medium 5.3 5.3 FIX debian debian sles dovecotopen-xchange 25d ago Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the c…
CVE-2026-27851 critical 9.1 9.1 FIX debian debian sles dovecotopen-xchange 25d ago When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP …
CVE-2026-8162 high 7.5 7.5 FIX debian debian pillarjs 25d ago multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing
CVE-2026-8161 high 7.5 7.5 FIX debian debian pillarjs 25d ago multiparty: Denial of Service via Prototype Pollution leads to Uncaught Exception
CVE-2026-8159 high 7.5 7.5 FIX debian debian pillarjs 25d ago multiparty vulnerable to ReDoS via filename parsing
CVE-2026-4887 high 7.1 7.1 FIX rheldebian debian sles gimp 26d ago Important: gimp security update
CVE-2026-43284 high 8.8 9.8 EXPFIX rhel slesdebian debian awsgoogle 26d ago Important: kernel security update
CVE-2026-4154 high 8.0 FIX rheldebian debian sles 26d ago Important: gimp security update
CVE-2026-4153 high 8.0 FIX rheldebian debian sles 26d ago Important: gimp security update
CVE-2026-4152 high 8.0 FIX rheldebian debian sles 26d ago Important: gimp security update
CVE-2026-4151 high 8.0 FIX rheldebian debian sles 26d ago Important: gimp security update
CVE-2026-4150 high 8.0 FIX rheldebian debian sles 26d ago Important: gimp security update
CVE-2026-7010 medium 6.5 6.5 FIX debian debian 26d ago HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request line, the URL host t…
CVE-2026-42046 high 7.8 7.8 FIX debian debian sles 26d ago libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-boun…
CVE-2026-37630 high 7.3 7.3 FIX debian debian 26d ago An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function
CVE-2026-42050 medium 5.5 5.5 FIX debian debian sles imagemagick 26d ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9.13-46, a malicious MIFF file could trigger an overflow when a user opens it in…
CVE-2026-41159 medium 5.3 5.3 debian debian mermaid_project 26d ago Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows injecting CSS that applies…
CVE-2026-41150 medium 5.3 5.3 debian debian mermaid_project 26d ago Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, i…
CVE-2026-7790 high 7.5 7.5 debian debianwindows windows ninenines 26d ago Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding parser in cow_http_te accepts an unbounded number …
CVE-2026-43969 low 3.2 3.2 FIX debian debianwindows windows ninenines 26d ago cowlib: Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
CVE-2026-43968 medium 4.0 4.0 FIX debian debianwindows windows ninenines 26d ago ninenines cowlib: Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability allows SSE event splitting and injection via unvalidated field values
CVE-2026-7210 critical 9.8 9.8 slesdebian debianwindows windows libexpat_projectpython 26d ago `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this…
CVE-2026-5172 high 7.3 7.3 FIX debian debian sleswindows windows 26d ago A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advanc…
CVE-2026-44777 medium 5.5 5.5 FIX debian debian sleswindows windows jqlang 26d ago jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.
CVE-2026-43896 medium 5.5 5.5 FIX debian debian sleswindows windows jqlang 26d ago jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachab…
CVE-2026-43895 medium 4.4 4.4 FIX debian debian sleswindows windows jqlang 26d ago jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during mo…
CVE-2026-43894 medium 5.5 5.5 FIX debian debian sleswindows windows jqlang 26d ago jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic.…
CVE-2026-41257 medium 5.5 5.5 FIX debian debian sleswindows windows jqlang 26d ago jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator …
CVE-2026-41256 medium 5.5 5.5 FIX debian debian sleswindows windows jqlang 26d ago jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter fil…
CVE-2026-40612 medium 5.5 5.5 FIX debian debian sleswindows windows jqlang 26d ago jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with…
CVE-2026-34095 medium 6.1 6.1 FIX debian debian mediawiki 26d ago Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/ActionEntryPoint.Php, includes/Request/FauxResponse.Php. This issue affects …
CVE-2026-34094 low 3.8 3.8 FIX debian debian mediawiki 26d ago Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-34093 medium 5.3 5.3 FIX debian debian mediawiki 26d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Specials/SpecialUserRights.P…
CVE-2026-34092 high 7.5 7.5 FIX debian debian mediawiki 26d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Skin/Skin.Php. This issue…
CVE-2026-34091 high 7.5 7.5 FIX debian debian mediawiki 26d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-34090 high 7.5 7.5 FIX debian debian mediawiki 26d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue affects CheckUser: from 1.45.0 before 1.45.2.
CVE-2026-34088 high 7.5 7.5 FIX debian debian mediawiki 26d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-34087 high 7.5 7.5 FIX debian debian mediawiki 26d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue affects OATHAuth: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-4802 high 8.0 8.0 FIX debian debian rhel sles 26d ago A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links i…
CVE-2026-43500 high 7.8 8.8 EXPFIX slesdebian debian linux-kernel 26d ago In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and th…
CVE-2026-8276 low 3.7 3.7 debian debian sles 27d ago bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go
CVE-2026-8275 low 3.7 3.7 debian debian 27d ago bettercap Has an Integer Coercion Error in the ippReadChunkedBody Function
CVE-2026-8261 medium 5.9 5.9 debian debian 27d ago A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attac…
CVE-2026-8258 medium 5.3 5.3 debian debian 27d ago A flaw has been found in Squirrel up to 3.2. Impacted is the function validate_format in the library sqstdlib/sqstdstring.cpp. Executing a manipulation can lead to stack-based buffer overflow. The at…
CVE-2026-8257 medium 5.5 5.5 debian debian webassembly 27d ago A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a…
CVE-2026-8177 high 7.5 7.5 FIX debian debian sleswindows windows 27d ago XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UT…
CVE-2026-45191 medium 6.5 6.5 FIX debian debian sles 27d ago Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass. Mask forms like "/00" and "/01" pass validatio…
CVE-2026-45190 medium 6.5 6.5 FIX debian debian sles 27d ago Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass. Inputs containing a trailing newline or non-ASCII digit chara…
CVE-2026-45186 high 7.5 7.5 FIX debian debian sleswindows windows libexpat_project 28d ago RHSA-2026:23230: expat security update (Important)
CVE-2026-7263 high 7.5 7.5 FIX slesdebian debian php 28d ago In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML docu…
CVE-2026-6104 critical 9.1 9.1 FIX slesdebian debian php 28d ago In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectl…
CVE-2026-7568 high 7.5 7.5 FIX slesdebian debianwindows windows php 28d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the cur…
CVE-2026-7262 high 7.5 7.5 FIX slesdebian debianwindows windows php 28d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which check…
CVE-2026-7261 critical 9.8 9.8 FIX slesdebian debianwindows windows php 28d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted acr…
CVE-2026-7259 medium 6.5 6.5 FIX slesdebian debianwindows windows php 28d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, re…
CVE-2026-7258 high 7.5 7.5 FIX slesdebian debianwindows windows php 28d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On…
CVE-2026-6735 medium 6.1 6.1 FIX slesdebian debianwindows windows php 28d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause t…
CVE-2026-6722 critical 9.8 9.8 FIX slesdebian debianwindows windows php 28d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global m…
CVE-2025-14179 critical 9.8 9.8 FIX slesdebian debianwindows windows php 28d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by…