Search

Found 12,390 results in 4891ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-21945 high 7.5 7.5 FIX rocky rhel sles oracle 5mo ago RHSA-2026:4832: java-1.8.0-ibm security update (Important)
CVE-2025-61729 high 8.0 FIX rocky rheldebian debian google 5mo ago Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string con…
CVE-2025-14425 high 8.0 FIX rheldebian debian sles 5mo ago Important: gimp security update
CVE-2025-14424 high 8.0 FIX rheldebian debian sles 5mo ago Important: gimp security update
CVE-2025-14423 high 8.0 FIX rheldebian debian sles 5mo ago Important: gimp security update
CVE-2025-14422 high 8.0 FIX rocky rheldebian debian 5mo ago RHSA-2026:1574: gimp:2.8 security update (Important)
CVE-2025-13601 high 7.7 7.7 FIX rocky rheldebian debian redhatgnome 5mo ago A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of u…
CVE-2026-21932 high 7.4 7.4 FIX slesdebian debian oraclegoogle 5mo ago Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX). Supported versions that are affected are Oracle Jav…
CVE-2026-1145 high 8.8 8.8 debian debian quickjs-ng 5mo ago A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. This manipulation causes heap-based buffe…
CVE-2026-1144 high 8.8 8.8 debian debian quickjs-ng 5mo ago A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free…
CVE-2025-68287 high 8.0 FIX rhel sles rocky 5mo ago Important: kernel security update
CVE-2025-68285 high 8.0 FIX rocky rhel sles 5mo ago Important: kernel security update
CVE-2025-67269 high 8.0 FIX rheldebian debian rocky 5mo ago Important: gpsd-minimal security update
CVE-2025-67268 high 8.0 FIX rheldebian debian rocky 5mo ago Important: gpsd-minimal security update
CVE-2025-66566 high 8.0 rhel rockydebian debian 5mo ago yawkat LZ4 Java has a possible information leak in Java safe decompressor
CVE-2025-40277 high 8.0 FIX rocky rhel sles 5mo ago Important: kernel security update
CVE-2025-39933 high 8.0 FIX rocky rhel sles 5mo ago Important: kernel security update
CVE-2025-38703 high 8.0 FIX rhel sles rocky 5mo ago Important: kernel security update
CVE-2025-38051 high 8.0 FIX rocky slesdebian debian 5mo ago In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_fill_dirent There is a race condition in the readdir concurrency process, which may acces…
CVE-2025-15538 high 7.8 7.8 debian debian sles assimp 5mo ago A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerability is the function Assimp::LWOImporter::FindUVChannels of the file /src/assimp/…
CVE-2026-23490 high 8.0 FIX rocky rhel sles 5mo ago Important: fence-agents security update
CVE-2026-0891 high 8.0 FIX rocky rheldebian debian 5mo ago Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
CVE-2026-0890 high 8.0 FIX rocky rheldebian debian 5mo ago Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVE-2026-0887 high 8.0 FIX rocky rheldebian debian 5mo ago Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVE-2026-0886 high 8.0 FIX rocky rheldebian debian 5mo ago Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVE-2026-0885 high 8.0 FIX rocky rheldebian debian 5mo ago Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVE-2026-0884 high 8.0 FIX rocky rheldebian debian 5mo ago Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVE-2026-0883 high 8.0 FIX rocky rheldebian debian 5mo ago Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVE-2026-0882 high 8.0 FIX rocky rheldebian debian 5mo ago Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVE-2026-0880 high 8.0 FIX rocky rheldebian debian 5mo ago Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVE-2026-0879 high 8.0 FIX rocky rheldebian debian 5mo ago Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140…
CVE-2026-0878 high 8.0 FIX rocky rheldebian debian 5mo ago Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVE-2026-0877 high 8.0 FIX rocky rheldebian debian 5mo ago Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVE-2025-68973 high 8.0 FIX rocky rheldebian debian 5mo ago RHSA-2026:0728: gnupg2 security update (Important)
CVE-2025-68615 high 8.0 FIX rocky rhel sles 5mo ago RHSA-2026:0750: net-snmp security update (Important)
CVE-2025-14327 high 8.0 FIX rocky rheldebian debian 5mo ago Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7.
CVE-2025-71066 high 7.5 7.5 FIX slesdebian debian 5mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change zdi-disclosures@trendmicro.com says: Th…
CVE-2025-47913 high 8.0 FIX rocky rheldebian debian 5mo ago RHSA-2026:0753: container-tools:rhel8 security update (Important)
CVE-2025-39993 high 8.0 FIX rocky slesdebian debian 5mo ago In the Linux kernel, the following vulnerability has been resolved: media: rc: fix races with imon_disconnect() Syzbot reports a KASAN issue as below: BUG: KASAN: use-after-free in __create_pipe in…
CVE-2025-39806 high 7.1 7.1 FIX rhel sles rocky 5mo ago Moderate: kernel security update
CVE-2025-14523 high 8.0 FIX rocky rhel sles 5mo ago RHSA-2026:1509: spice-client-win security update (Important)
CVE-2026-0822 high 8.8 8.8 debian debian quickjs-ng 5mo ago A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Rem…
CVE-2026-0821 critical 9.8 9.8 debian debian quickjs-ng 5mo ago A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-…
CVE-2026-21441 high 8.0 FIX rocky rhel sles 5mo ago Important: fence-agents security update
CVE-2025-66293 high 8.0 FIX rocky rheldebian debian 5mo ago RHSA-2026:9686: java-17-openjdk security update (Important)
CVE-2025-65018 high 8.0 FIX rocky rheldebian debian 5mo ago RHSA-2026:0932: java-1.8.0-openjdk security update (Important)
CVE-2025-64720 high 8.0 FIX rocky rheldebian debian 5mo ago RHSA-2026:0932: java-1.8.0-openjdk security update (Important)
CVE-2025-13699 high 8.0 FIX rocky rhel sles 5mo ago MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MariaDB. Intera…
CVE-2025-15412 high 7.8 7.8 debian debian webassembly 5mo ago A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component …
CVE-2025-15411 high 7.8 7.8 debian debian webassembly 5mo ago A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-dec…
CVE-2023-54035 high 8.0 FIX rhel slesdebian debian 5mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix underflow in chain reference counter Set element addition error path decrements reference counter on ch…
CVE-2025-68696 high 8.2 8.2 FIX debian debian jnunemaker 6mo ago httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to interna…
CVE-2025-68156 high 8.0 FIX rheldebian debian sles 6mo ago Important: opentelemetry-collector security update
CVE-2025-66200 high 8.0 FIX rockydebian debian rhel 6mo ago mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an u…
CVE-2025-65082 high 8.0 FIX rockydebian debian rhel 6mo ago Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables cal…
CVE-2025-58098 high 8.0 FIX rockydebian debian rhel 6mo ago Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects A…
CVE-2025-55753 high 8.0 FIX debian debian rocky rhel 6mo ago An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certi…
CVE-2025-26625 high 8.0 FIX rocky rheldebian debian 6mo ago Git LFS may write to arbitrary files via crafted symlinks
CVE-2025-14956 high 7.1 7.1 debian debian webassembly 6mo ago A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReader::readExport of the file src/wasm/wasm-binary.cpp. This manipulation causes he…
CVE-2025-6075 high 8.0 FIX rockyalmalinux almalinux rhel 6mo ago Important: python3.12 security update
CVE-2025-6069 high 8.0 FIX rocky rheldebian debian 6mo ago The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.
CVE-2025-43541 high 8.0 FIX rocky rhel sles 6mo ago A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Process…
CVE-2025-43536 high 8.0 FIX rocky rhel sles 6mo ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciou…
CVE-2025-43535 high 8.0 FIX rocky rhel sles 6mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciou…
CVE-2025-43531 high 8.0 FIX rocky rhel sles 6mo ago A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, wa…
CVE-2025-43529 high 9.5 KEVFIX rocky rhel sles 6mo ago Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could…
CVE-2025-43501 high 8.0 FIX rocky rhel sles 6mo ago A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Proce…
CVE-2025-14174 high 9.5 KEVFIX rheldebian debian sles 6mo ago Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security sever…
CVE-2025-11083 high 7.8 7.8 FIX rocky rheldebian debian gnu 6mo ago RHSA-2026:2627: gcc-toolset-14-binutils security update (Moderate)
CVE-2024-5642 high 8.0 FIX rocky rhel sles 6mo ago CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-re…
CVE-2025-4516 high 8.0 FIX rocky slesdebian debian 6mo ago There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To…
CVE-2025-40176 high 8.0 FIX rhel sles rocky 6mo ago Important: kernel security update
CVE-2025-39966 high 8.0 FIX rhel sles rocky 6mo ago Important: kernel security update
CVE-2025-13499 high 8.0 FIX rhel sles rocky 6mo ago Important: wireshark security update
CVE-2025-55752 high 7.5 7.5 FIX rocky rhel sles apache 6mo ago Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the po…
CVE-2025-31651 high 8.0 FIX rocky rhel sles 6mo ago Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to…
CVE-2025-14333 high 8.0 FIX rocky rheldebian debian 6mo ago Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
CVE-2025-14331 high 8.0 FIX rocky rheldebian debian 6mo ago Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14330 high 8.0 FIX rocky rheldebian debian 6mo ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14329 high 8.0 FIX rocky rheldebian debian 6mo ago Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14328 high 8.0 FIX rocky rheldebian debian 6mo ago Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14325 high 8.0 FIX rocky rheldebian debian 6mo ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14324 high 8.0 FIX rocky rheldebian debian 6mo ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14323 high 8.0 FIX rocky rheldebian debian 6mo ago Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14322 high 8.0 FIX rocky rheldebian debian 6mo ago Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Th…
CVE-2025-14321 high 8.0 FIX rocky rheldebian debian 6mo ago Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-66287 high 8.0 FIX rocky rhel sles 6mo ago A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.
CVE-2025-43458 high 8.0 FIX rocky rhel sles 6mo ago This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, wat…
CVE-2025-43443 high 8.0 FIX rocky rhel sles 6mo ago This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Pr…
CVE-2025-43441 high 8.0 FIX rhel slesdebian debian 6mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processi…
CVE-2025-43440 high 8.0 FIX rocky rhel sles 6mo ago This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted w…
CVE-2025-43438 high 8.0 FIX rhel slesdebian debian 6mo ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watc…
CVE-2025-43434 high 8.0 FIX rocky rhel sles 6mo ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watc…
CVE-2025-43433 high 8.0 FIX rhel slesdebian debian 6mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS …
CVE-2025-43432 high 8.0 FIX rocky rhel sles 6mo ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processin…
CVE-2025-43431 high 8.0 FIX rocky rhel sles 6mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS …
CVE-2025-43430 high 8.0 FIX rocky rhel sles 6mo ago This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciou…
CVE-2025-43429 high 8.0 FIX rocky rhel sles 6mo ago A buffer overflow was addressed with improved bounds checking. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, …
CVE-2025-43427 high 8.0 FIX rocky rhel sles 6mo ago This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted we…
CVE-2025-43425 high 8.0 FIX rocky rhel sles 6mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously c…