Search

Found 12,389 results in 943ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-23111 high 7.8 7.8 FIX rhel slesdebian debian 2mo ago Moderate: kernel security update
CVE-2025-15270 high 8.0 FIX rheldebian debian sles 2mo ago Important: fontforge security update
CVE-2026-31404 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: NFSD: Defer sub-object cleanup in export put callbacks svc_export_put() calls path_put() and auth_domain_put() immediately when t…
CVE-2026-31403 high 7.8 7.8 FIX slesdebian debian linux-kernel google 2mo ago In the Linux kernel, the following vulnerability has been resolved: NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd The /proc/fs/nfs/exports proc entry is created at module ini…
CVE-2026-31401 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: HID: bpf: prevent buffer overflow in hid_hw_request right now the returned value is considered to be always valid. However, when …
CVE-2026-31399 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: nvdimm/bus: Fix potential use after free in asynchronous initialization Dingisoul with KASAN reports a use after free if device_a…
CVE-2026-31398 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: mm/rmap: fix incorrect pte restoration for lazyfree folios We batch unmap anonymous lazyfree folios by folio_unmap_pte_batch. If…
CVE-2026-31397 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix use of NULL folio in move_pages_huge_pmd() move_pages_huge_pmd() handles UFFDIO_MOVE for both normal THPs and…
CVE-2026-31396 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net: macb: fix use-after-free access to PTP clock PTP clock is registered on every opening of the interface and destroyed on ever…
CVE-2026-31395 high 7.1 7.1 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler The ASYNC_EVENT_CMPL_EVENT_ID_DBG_BUF_PRODUCER handler in bnxt_as…
CVE-2026-31393 high 8.1 8.1 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access l2cap_information_rsp() checks that cmd_len covers the fix…
CVE-2026-31392 high 8.1 8.1 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: smb: client: fix krb5 mount with username option Customer reported that some of their krb5 mounts were failing against a single s…
CVE-2026-31389 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregister from driver core also in the unlikely event th…
CVE-2026-23466 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: drm/xe: Open-code GGTT MMIO access protection GGTT MMIO access is currently protected by hotplug (drm_dev_enter), which works cor…
CVE-2026-23462 high 8.8 8.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: Fix possible UAF This fixes the following trace caused by not dropping l2cap_conn reference when user->remove ca…
CVE-2026-23461 high 8.8 8.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user After commit ab4eedb790ca ("Bluetooth: L2CAP: Fix corrupted list in…
CVE-2026-23459 high 8.2 8.2 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_…
CVE-2026-23458 high 7.8 7.8 FIX slesdebian debian linux-kernel google 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() ctnetlink_dump_exp_ct() stores a conntrack pointer in cb->dat…
CVE-2026-23457 high 8.6 8.6 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() sip_help_tcp() parses the SIP Content-Length hea…
CVE-2026-23456 high 8.2 8.2 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read…
CVE-2026-23455 critical 9.1 9.1 FIX sles rheldebian debian 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit leng…
CVE-2026-23454 high 7.0 7.0 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown A potential race condition exists in mana_hwc_…
CVE-2026-23453 high 7.5 7.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: Fix memory leak in XDP_DROP for non-zero-copy mode Page recycling was removed from the XDP_DROP path in em…
CVE-2026-23451 high 7.5 7.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_parse() can loop if a stack of two bonding devices is…
CVE-2026-23450 critical 9.8 9.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_…
CVE-2026-23449 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: Fix double-free in teql_master_xmit Whenever a TEQL devices has a lockless Qdisc as root, qdisc_reset should be …
CVE-2026-23448 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check cdc_ncm_rx_verify_ndp16() validates that the NDP header and its DP…
CVE-2026-23444 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure ieee80211_tx_prepare_skb() has three error paths, but only …
CVE-2026-34877 critical 9.8 9.8 FIX debian debian armtrustedfirmware 2mo ago An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the ser…
CVE-2026-34876 high 7.5 7.5 FIX debian debian trustedfirmware 2mo ago An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation …
CVE-2026-5246 high 8.1 8.1 FIX debian debian cesanta 2mo ago A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handler. Executing a mani…
CVE-2026-5245 high 8.1 8.1 FIX debian debian cesanta 2mo ago A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the ar…
CVE-2026-5244 critical 9.8 9.8 FIX debian debian cesanta 2mo ago A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pu…
CVE-2026-5317 high 8.8 8.8 debian debian nothings 2mo ago A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_vorbis.c. The manipulation results in out-of-bounds write. The attack may be pe…
CVE-2026-5315 high 8.8 8.8 debian debian nothings 2mo ago A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the library stb_truetype.h of the component TTF File Handler. Executing a manipulati…
CVE-2026-4177 high 8.0 FIX debian debian rocky rhel 2mo ago RHSA-2026:6470: perl-YAML-Syck security update (Important)
CVE-2026-3497 high 7.5 7.5 FIX rocky rhel sles canonicalopenbsd 2mo ago Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH u…
CVE-2026-34829 high 8.0 FIX slesdebian debian 2mo ago Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
CVE-2026-34827 high 8.0 FIX slesdebian debian 2mo ago Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters
CVE-2026-34785 high 8.0 FIX slesdebian debian 2mo ago Rack::Static prefix matching can expose unintended files under the static root
CVE-2026-34230 high 8.0 FIX slesdebian debian 2mo ago Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
CVE-2026-5314 high 8.8 8.8 debian debian nothings 2mo ago A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation resul…
CVE-2026-34873 critical 9.1 9.1 FIX slesdebian debian trustedfirmware 2mo ago An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.
CVE-2026-34874 high 7.5 7.5 FIX slesdebian debian trustedfirmware 2mo ago An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.
CVE-2026-25835 high 7.7 7.7 FIX slesdebian debian armlinarotrustedfirmware 2mo ago Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
CVE-2026-25833 high 7.5 7.5 FIX slesdebian debian trustedfirmware 2mo ago Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function
CVE-2026-34875 critical 9.8 9.8 FIX slesdebian debian trustedfirmware 2mo ago An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
CVE-2026-34159 critical 9.8 9.8 FIX debian debian ggml 2mo ago llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthentica…
CVE-2026-5272 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 2mo ago Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2026-31806 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-24684 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-24683 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-24681 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-24679 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-24676 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-24675 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-24491 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-23948 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-23732 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-22856 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-22854 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-22852 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6918: freerdp security update (Important)
CVE-2026-33526 high 8.0 FIX rhel rocky sles 2mo ago RHSA-2026:8317: squid:4 security update (Important)
CVE-2026-32748 high 8.0 FIX rhel rocky sles 2mo ago RHSA-2026:8317: squid:4 security update (Important)
CVE-2026-4371 high 8.0 FIX rhel rocky sles 2mo ago RHSA-2026:6917: thunderbird security update (Important)
CVE-2026-3889 high 8.0 FIX rhel rocky sles 2mo ago RHSA-2026:6917: thunderbird security update (Important)
CVE-2026-26965 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6005: freerdp security update (Important)
CVE-2026-26955 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:6005: freerdp security update (Important)
CVE-2026-23171 high 7.8 7.8 FIX rhel sles rocky google 2mo ago Moderate: kernel security update
CVE-2018-25222 high 8.4 8.4 debian debian 2mo ago SC v7.16 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft ma…
CVE-2016-20040 high 8.4 8.4 debian debian 2mo ago TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an …
CVE-2026-34040 high 8.0 FIX debian debian sles google 2mo ago Moby has AuthZ plugin bypass when provided oversized request bodies
CVE-2026-24031 high 8.2 8.2 FIX debian debian sles dovecotopen-xchange 2mo ago Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_…
CVE-2025-59028 high 7.5 7.5 FIX debian debian sles dovecotopen-xchange 2mo ago When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable serv…
CVE-2026-34060 critical 9.8 9.8 FIX debian debian shopify 2mo ago Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rubyLsp.branch VS Code workspace setting was interpol…
CVE-2014-125112 critical 9.8 9.8 FIX debian debian miyagawa 2mo ago Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows …
CVE-2026-4721 high 8.0 FIX rocky rheldebian debian 2mo ago Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume tha…
CVE-2026-4720 high 8.0 FIX rocky rheldebian debian 2mo ago Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
CVE-2026-4719 high 8.0 FIX rocky rheldebian debian 2mo ago Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4718 high 8.0 FIX rocky rheldebian debian 2mo ago Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4717 high 8.0 FIX rocky rheldebian debian 2mo ago Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4716 high 8.0 FIX rocky rheldebian debian 2mo ago Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4715 high 8.0 FIX rocky rheldebian debian 2mo ago Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4714 high 8.0 FIX rocky rheldebian debian 2mo ago Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4713 high 8.0 FIX rocky rheldebian debian 2mo ago Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4712 high 8.0 FIX rocky rheldebian debian 2mo ago Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4711 high 8.0 FIX rocky rheldebian debian 2mo ago Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4710 high 8.0 FIX rocky rheldebian debian 2mo ago Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4709 high 8.0 FIX rocky rheldebian debian 2mo ago Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4708 high 8.0 FIX rocky rheldebian debian 2mo ago Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4707 high 8.0 FIX rocky rheldebian debian 2mo ago Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4706 high 8.0 FIX rocky rheldebian debian 2mo ago Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4705 high 8.0 FIX rocky rheldebian debian 2mo ago Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4704 high 8.0 FIX rocky rheldebian debian 2mo ago Denial-of-service in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4702 high 8.0 FIX rocky rheldebian debian 2mo ago JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4701 high 8.0 FIX rocky rheldebian debian 2mo ago Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4700 high 8.0 FIX rocky rheldebian debian 2mo ago Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4699 high 8.0 FIX rocky rheldebian debian 2mo ago Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4698 critical 9.8 9.8 FIX rocky rheldebian debian mozilla 2mo ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4697 high 8.0 FIX rocky rheldebian debian 2mo ago Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.