Search

Found 9,906 results in 850ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-8715 high 8.0 FIX rhel rocky sles 9mo ago RHSA-2025:15115: postgresql:12 security update (Important)
CVE-2025-8714 high 8.0 FIX rhel rocky sles 9mo ago RHSA-2025:15115: postgresql:12 security update (Important)
CVE-2025-8713 high 8.0 FIX rhel slesdebian debian 9mo ago PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy inten…
CVE-2025-4207 high 8.0 FIX arch arch rhel sles 9mo ago RHSA-2025:15022: postgresql:15 security update (Important)
CVE-2025-38676 high 7.8 7.8 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Avoid stack buffer overflow from kernel cmdline While the kernel command line is considered trusted in most environmen…
CVE-2025-9185 high 8.0 FIX rhel rockydebian debian 10mo ago Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evid…
CVE-2025-9182 high 8.0 FIX rhel rockydebian debian 10mo ago Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderbird 140.2.
CVE-2025-9181 high 8.0 FIX rhel rockydebian debian 10mo ago Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
CVE-2025-9180 high 8.0 FIX rhel rockydebian debian 10mo ago Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128…
CVE-2025-9179 high 8.0 FIX rhel rockydebian debian 10mo ago An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the con…
CVE-2025-54389 high 8.0 FIX debian debian rhel rocky 10mo ago RHSA-2025:14573: aide security update (Important)
CVE-2025-38417 high 8.0 FIX rhel sles rocky 10mo ago Important: kernel security update
CVE-2025-37914 high 8.0 FIX rhel sles rocky 10mo ago Important: kernel security update
CVE-2025-22058 high 8.0 FIX rhel sles rocky 10mo ago Important: kernel security update
CVE-2025-38670 high 7.1 7.1 FIX slesdebian debian linux-kernel 10mo ago In the Linux kernel, the following vulnerability has been resolved: arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack() `cpu_switch_to()` and `call_on_irq_stack()` manipulate SP to chang…
CVE-2025-38627 high 7.8 7.8 FIX slesdebian debian linux-kernel 10mo ago In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_free_dic The decompress_io_ctx may be released asynchronously after I/O comple…
CVE-2025-9300 high 7.8 7.8 FIX debian debian saitoha 10mo ago A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation res…
CVE-2025-5914 high 7.8 7.8 FIX rhel rockydebian debian 10mo ago A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to…
CVE-2025-53506 high 8.0 FIX rhel rocky sles 10mo ago Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue …
CVE-2025-52520 high 8.0 FIX rhel rocky sles 10mo ago For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0…
CVE-2025-52434 high 8.0 FIX rhel rocky sles 10mo ago Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with c…
CVE-2025-49125 high 8.0 FIX arch arch rhel rocky 10mo ago Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web application, it was possib…
CVE-2025-48989 high 7.5 7.5 FIX rhel rocky sles apache 10mo ago Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0…
CVE-2025-48988 high 8.0 FIX arch arch rhel rocky 10mo ago Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 th…
CVE-2025-48976 high 8.0 FIX arch arch rhel rocky 10mo ago Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; fr…
CVE-2025-38584 high 7.8 7.8 FIX slesdebian debian linux-kernel google 10mo ago In the Linux kernel, the following vulnerability has been resolved: padata: Fix pd UAF once and for all There is a race condition/UAF in padata_reorder that goes back to the initial commit. A refe…
CVE-2025-47907 high 8.0 rheldebian debian sles google 10mo ago Incorrect results returned from Rows.Scan in database/sql
CVE-2025-4674 high 8.0 FIX rhel rockydebian debian google 10mo ago Important: golang security update
CVE-2025-38471 high 7.8 7.8 FIX rhel slesdebian debian 10mo ago Important: kernel security update
CVE-2025-38250 high 7.8 7.8 FIX rhel slesdebian debian 10mo ago Important: kernel security update
CVE-2025-38159 high 8.0 FIX rhel rocky sles 10mo ago Important: kernel security update
CVE-2025-38085 high 8.0 FIX rhel rocky sles 10mo ago Important: kernel security update
CVE-2025-38084 high 8.0 FIX rhel slesdebian debian 10mo ago Important: kernel security update
CVE-2025-38552 high 7.8 7.8 FIX slesdebian debian linux-kernel 10mo ago In the Linux kernel, the following vulnerability has been resolved: mptcp: plug races between subflow fail and subflow creation We have races similar to the one addressed by the previous patch betw…
CVE-2025-38502 high 7.1 7.1 FIX slesdebian debian linux-kernel siemens 10mo ago In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial reported that an out-of-bounds access in cgroup local storage can be crafted v…
CVE-2025-6558 high 9.5 KEVFIX rhel rockydebian debian 10mo ago Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page.…
CVE-2025-43265 high 8.0 FIX rhel rocky sles 10mo ago An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing…
CVE-2025-43240 high 8.0 FIX rhel rocky sles 10mo ago A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.
CVE-2025-43227 high 8.0 FIX rhel rocky sles 10mo ago This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing malicio…
CVE-2025-43216 high 8.0 FIX rhel rocky sles 10mo ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS…
CVE-2025-43212 high 8.0 FIX rhel rocky sles 10mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously …
CVE-2025-43211 high 8.0 FIX rhel rocky sles 10mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processi…
CVE-2025-31278 high 8.0 FIX rhel rocky sles 10mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processi…
CVE-2025-31273 high 8.0 FIX rhel rocky sles 10mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously …
CVE-2025-8846 high 7.8 7.8 debian debian nasm 10mo ago A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. The attack needs to b…
CVE-2025-8845 high 7.8 7.8 debian debian nasm 10mo ago A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer overflow. It is possibl…
CVE-2025-8843 high 7.8 7.8 slesdebian debian nasm 10mo ago A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file outmacho.c. The manipulation leads to heap-based buffer overflow. Local access is…
CVE-2025-8842 high 7.8 7.8 slesdebian debian nasm 10mo ago A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free. An attack has to …
CVE-2025-38079 high 7.8 7.8 FIX rhel rocky sles 10mo ago Moderate: kernel security update
CVE-2025-47219 high 8.1 8.1 FIX debian debian sles gstreamer 10mo ago In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.
CVE-2025-38087 high 8.0 FIX rhel sles rocky 10mo ago Important: kernel security update
CVE-2025-38052 high 8.0 FIX rhel rocky sles 10mo ago Important: kernel security update
CVE-2025-37890 high 8.0 FIX rhel rocky sles 10mo ago Important: kernel security update
CVE-2025-22020 high 8.0 FIX rhel rocky sles 10mo ago Important: kernel security update
CVE-2025-21962 high 8.0 FIX rhel sles rocky 10mo ago Important: kernel security update
CVE-2025-21929 high 8.0 FIX rhel sles rocky 10mo ago Important: kernel security update
CVE-2025-21928 high 8.0 FIX rhel rocky sles 10mo ago Important: kernel security update
CVE-2025-21727 high 7.8 7.8 FIX rhel rocky sles 10mo ago Important: kernel security update
CVE-2025-21726 high 7.8 7.8 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2022-49788 high 8.0 FIX rhel rocky sles 10mo ago Important: kernel security update
CVE-2025-7425 high 7.8 7.8 FIX rheldebian debian sles 10mo ago A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragm…
CVE-2025-52999 high 8.0 FIX rhel rockydebian debian 10mo ago RHSA-2025:14126: pki-deps:10.6 security update (Important)
CVE-2025-6965 high 9.0 EXPFIX rhel rocky sles 10mo ago RHSA-2025:14101: mingw-sqlite security update (Important)
CVE-2025-5994 high 8.0 FIX rhel sles rocky 10mo ago RHSA-2025:11884: unbound security update (Important)
CVE-2025-27151 high 8.0 FIX rhel sles rocky 10mo ago Important: redis:7 security update
CVE-2025-8035 high 8.0 FIX almalinux almalinux rhel rocky 11mo ago Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corru…
CVE-2025-8034 high 8.0 FIX rhelalmalinux almalinux rocky 11mo ago Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evid…
CVE-2025-8033 high 8.0 FIX rhelalmalinux almalinux rocky 11mo ago The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefo…
CVE-2025-8032 high 8.0 FIX rhelalmalinux almalinux rocky 11mo ago XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thun…
CVE-2025-8031 high 8.0 FIX almalinux almalinux rhel rocky 11mo ago The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 12…
CVE-2025-8030 high 8.0 FIX rhelalmalinux almalinux rocky 11mo ago Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox …
CVE-2025-8029 high 8.0 FIX almalinux almalinux rhel rocky 11mo ago Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13…
CVE-2025-8028 high 8.0 FIX rhel rockydebian debian 11mo ago On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulne…
CVE-2025-8027 high 8.0 FIX rhel rockydebian debian 11mo ago On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability was fixed in Firefox 141, Firefo…
CVE-2025-48385 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2025-48384 high 9.5 KEVFIX rhel rockydebian debian 11mo ago Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.
CVE-2025-48367 high 8.0 FIX rhel rocky sles 11mo ago RHSA-2025:12006: redis:6 security update (Important)
CVE-2025-46835 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2025-38425 high 8.0 FIX rhel slesdebian debian 11mo ago In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: check msg length in SMBUS block read For SMBUS block read, do not continue to read if the message length passed from …
CVE-2025-38089 high 8.0 FIX rhel slesdebian debian 11mo ago Important: kernel security update
CVE-2025-32023 high 9.0 EXPFIX rhel rocky sles 11mo ago RHSA-2025:12006: redis:6 security update (Important)
CVE-2025-27614 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2025-27613 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2024-58002 high 8.0 FIX rhel rocky sles 11mo ago Important: kernel security update
CVE-2024-52006 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2024-50349 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2025-50106 high 8.0 FIX rhelalmalinux almalinux rocky 11mo ago Important: java-1.8.0-openjdk security update
CVE-2025-30761 high 8.0 FIX rhelalmalinux almalinux rocky 11mo ago Important: java-1.8.0-openjdk security update
CVE-2025-30754 high 8.0 FIX rhel rocky sles 11mo ago Important: java-1.8.0-openjdk security update
CVE-2025-30749 high 8.0 FIX rhel rocky sles 11mo ago Important: java-1.8.0-openjdk security update
CVE-2025-53816 high 7.5 7.5 FIX debian debian sles 7-zip 11mo ago 7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Ve…
CVE-2025-31650 high 9.0 EXPFIX arch arch rhel rocky 11mo ago Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory …
CVE-2024-56337 high 8.0 FIX rhel rocky sles 11mo ago Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 throu…
CVE-2025-50059 high 8.0 FIX rhel rocky sles 11mo ago RHSA-2025:10873: java-21-openjdk security update (Important)
CVE-2024-6174 high 8.0 FIX rheldebian debian sles 11mo ago RHSA-2025:11324: cloud-init security update (Important)
CVE-2025-7546 high 7.8 7.8 FIX debian debian sles gnu 11mo ago A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation le…
CVE-2025-7545 high 7.8 7.8 FIX debian debian sles gnu 11mo ago A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-ba…
CVE-2025-7424 high 7.5 7.5 FIX debian debian sles rhel xmlsoftredhat 11mo ago A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allow…
CVE-2025-38342 high 7.1 7.1 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: software node: Correct a OOB check in software_node_get_reference_args() software_node_get_reference_args() wants to get @index-t…
CVE-2025-38280 high 7.8 7.8 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid __bpf_prog_ret0_warn when jit fails syzkaller reported an issue: WARNING: CPU: 3 PID: 217 at kernel/bpf/core.c:2357 _…