Search

Found 25,857 results in 1299ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-21711 high 8.0 FIX rhel slesdebian debian 2mo ago RHSA-2026:7670: nodejs:24 security update (Important)
CVE-2026-21710 high 8.0 FIX rocky rhel sles 2mo ago RHSA-2026:8339: nodejs:20 security update (Important)
CVE-2026-1528 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:7670: nodejs:24 security update (Important)
CVE-2026-1527 high 8.0 FIX rheldebian debianalmalinux almalinux 2mo ago RHSA-2026:7670: nodejs:24 security update (Important)
CVE-2026-1526 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:7670: nodejs:24 security update (Important)
CVE-2026-1525 high 8.0 FIX rocky rheldebian debian 2mo ago RHSA-2026:7670: nodejs:24 security update (Important)
CVE-2026-5915 high 8.1 8.1 FIX debian debian linux-kernelmacos macos google 2mo ago Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium secur…
CVE-2026-5914 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Ext…
CVE-2026-5913 high 8.1 8.1 FIX debian debian linux-kernelmacos macos google 2mo ago Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-5912 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 2mo ago Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-5910 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)
CVE-2026-5909 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)
CVE-2026-5908 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)
CVE-2026-5883 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 2mo ago Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-5879 high 8.8 8.8 FIX debian debianmacos macos google 2mo ago Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chrom…
CVE-2026-5865 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-5863 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H…
CVE-2026-5860 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-39892 unknown FIX slesdebian debian 2mo ago Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs
CVE-2026-39883 unknown FIX debian debian google 2mo ago OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command us…
CVE-2026-39882 unknown FIX debian debian 2mo ago OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a si…
CVE-2026-5795 unknown debian debian sles 2mo ago Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
CVE-2026-34588 high 8.0 FIX rhel slesdebian debian 2mo ago Important: openexr security update
CVE-2026-39395 unknown FIX debian debian sles 2mo ago Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with…
CVE-2026-35611 high 8.0 slesdebian debian google 2mo ago Addressable has a Regular Expression Denial of Service in Addressable templates
CVE-2026-32289 unknown FIX debian debian sles google 2mo ago Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS …
CVE-2026-32288 unknown FIX debian debian sles google 2mo ago tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
CVE-2026-28390 high 7.5 7.5 FIX slesdebian debian rhel opensslgoogle 2mo ago Moderate: openssl security update
CVE-2026-28389 high 7.5 7.5 FIX slesdebian debian opensslgoogle 2mo ago Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlle…
CVE-2026-28388 high 7.5 7.5 FIX debian debian opensslgoogle 2mo ago Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A …
CVE-2026-28387 high 8.1 8.1 FIX slesdebian debian opensslgoogle 2mo ago Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-…
CVE-2026-35406 unknown FIX debian debian sles 2mo ago Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable…
CVE-2026-29181 unknown FIX debian debian google 2mo ago OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across va…
CVE-2025-14821 high 7.0 7.0 FIX debian debian libsshredhat 2mo ago A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a si…
CVE-2026-4292 unknown FIX slesdebian debian 2mo ago Django vulnerable to privilege abuse in ModelAdmin.list_editable
CVE-2026-4277 unknown FIX slesdebian debian 2mo ago Django vulnerable to privilege abuse in GenericInlineModelAdmin
CVE-2026-3902 unknown FIX slesdebian debian 2mo ago Django vulnerable to ASGI header spoofing via underscore/hyphen conflation
CVE-2026-33034 unknown FIX slesdebian debian 2mo ago Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
CVE-2026-33033 unknown FIX slesdebian debian 2mo ago Django has potential DoS via MultiPartParser through crafted multipart uploads
CVE-2026-28808 unknown FIX debian debian sles 2mo ago Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a U…
CVE-2026-32144 unknown FIX debian debian sles 2mo ago Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification. The OCSP respons…
CVE-2026-31842 high 7.5 7.5 debian debian tinyproxy_project 2mo ago Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer() function u…
CVE-2026-34197 unknown 2.5 KEVEXP debian debian 2mo ago Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CVE-2026-33227 unknown debian debian 2mo ago Apache ActiveMQ: Improper validation and restriction of a classpath path name
CVE-2026-28810 unknown FIX debian debian sles 2mo ago Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The built-in DNS resolver (inet_res) uses a sequential, pr…
CVE-2026-32647 high 8.0 FIX rhelalmalinux almalinux rocky 2mo ago Important: nginx security update
CVE-2026-27784 high 8.0 FIX rhelalmalinux almalinux rocky 2mo ago Important: nginx security update
CVE-2026-27654 high 8.0 FIX rhel rocky sles 2mo ago Important: nginx security update
CVE-2026-27651 high 8.0 FIX rhel rocky sles 2mo ago Important: nginx security update
CVE-2026-35172 high 7.5 7.5 debian debian sles distribution 2mo ago Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation
CVE-2026-5673 high 7.1 7.1 debian debian sles rhel xiph 2mo ago A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local att…
CVE-2026-31409 high 8.8 8.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->binding on failed binding request When a multichannel SMB2_SESSION_SETUP request with SMB2_SESSION_REQ_FLAG_BI…
CVE-2026-31408 high 8.8 8.8 FIX sles rheldebian debian 2mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold sco_recv_frame() reads conn->sk under sco_conn_lo…
CVE-2026-31407 high 7.1 7.1 FIX slesdebian debian linux-kernel google 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: add missing netlink policy validations Hyunwoo Kim reports out-of-bounds access in sctp and ctnetlink. The…
CVE-2026-31406 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() After cancel_delayed_work_sync() is called from xfrm_nat…
CVE-2026-23231 high 7.8 8.8 EXPFIX rhel slesdebian debian 2mo ago Moderate: kernel security update
CVE-2026-23111 high 7.8 7.8 FIX rhel slesdebian debian 2mo ago Moderate: kernel security update
CVE-2025-15270 high 8.0 FIX rheldebian debian sles 2mo ago Important: fontforge security update
CVE-2026-35166 unknown FIX debian debian sles 2mo ago Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or…
CVE-2026-31404 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: NFSD: Defer sub-object cleanup in export put callbacks svc_export_put() calls path_put() and auth_domain_put() immediately when t…
CVE-2026-31403 high 7.8 7.8 FIX slesdebian debian linux-kernel google 2mo ago In the Linux kernel, the following vulnerability has been resolved: NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd The /proc/fs/nfs/exports proc entry is created at module ini…
CVE-2026-31401 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: HID: bpf: prevent buffer overflow in hid_hw_request right now the returned value is considered to be always valid. However, when …
CVE-2026-31399 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: nvdimm/bus: Fix potential use after free in asynchronous initialization Dingisoul with KASAN reports a use after free if device_a…
CVE-2026-31398 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: mm/rmap: fix incorrect pte restoration for lazyfree folios We batch unmap anonymous lazyfree folios by folio_unmap_pte_batch. If…
CVE-2026-31397 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix use of NULL folio in move_pages_huge_pmd() move_pages_huge_pmd() handles UFFDIO_MOVE for both normal THPs and…
CVE-2026-31396 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net: macb: fix use-after-free access to PTP clock PTP clock is registered on every opening of the interface and destroyed on ever…
CVE-2026-31395 high 7.1 7.1 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler The ASYNC_EVENT_CMPL_EVENT_ID_DBG_BUF_PRODUCER handler in bnxt_as…
CVE-2026-31393 high 8.1 8.1 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access l2cap_information_rsp() checks that cmd_len covers the fix…
CVE-2026-31392 high 8.1 8.1 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: smb: client: fix krb5 mount with username option Customer reported that some of their krb5 mounts were failing against a single s…
CVE-2026-31389 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregister from driver core also in the unlikely event th…
CVE-2026-23466 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: drm/xe: Open-code GGTT MMIO access protection GGTT MMIO access is currently protected by hotplug (drm_dev_enter), which works cor…
CVE-2026-23462 high 8.8 8.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: Fix possible UAF This fixes the following trace caused by not dropping l2cap_conn reference when user->remove ca…
CVE-2026-23461 high 8.8 8.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user After commit ab4eedb790ca ("Bluetooth: L2CAP: Fix corrupted list in…
CVE-2026-23459 high 8.2 8.2 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_…
CVE-2026-23458 high 7.8 7.8 FIX slesdebian debian linux-kernel google 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() ctnetlink_dump_exp_ct() stores a conntrack pointer in cb->dat…
CVE-2026-23457 high 8.6 8.6 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() sip_help_tcp() parses the SIP Content-Length hea…
CVE-2026-23456 high 8.2 8.2 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read…
CVE-2026-23454 high 7.0 7.0 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown A potential race condition exists in mana_hwc_…
CVE-2026-23453 high 7.5 7.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: Fix memory leak in XDP_DROP for non-zero-copy mode Page recycling was removed from the XDP_DROP path in em…
CVE-2026-23451 high 7.5 7.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_parse() can loop if a stack of two bonding devices is…
CVE-2026-23449 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: Fix double-free in teql_master_xmit Whenever a TEQL devices has a lockless Qdisc as root, qdisc_reset should be …
CVE-2026-23448 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check cdc_ncm_rx_verify_ndp16() validates that the NDP header and its DP…
CVE-2026-23444 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure ieee80211_tx_prepare_skb() has three error paths, but only …
CVE-2026-35545 unknown FIX debian debian 2mo ago An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure …
CVE-2026-35544 unknown FIX debian debian 2mo ago An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass vi…
CVE-2026-35543 unknown FIX debian debian 2mo ago An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead …
CVE-2026-35542 unknown FIX debian debian 2mo ago An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. Thi…
CVE-2026-35541 unknown FIX debian debian 2mo ago An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing …
CVE-2026-35540 unknown FIX debian debian 2mo ago An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if s…
CVE-2026-35539 unknown FIX debian debian 2mo ago An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.
CVE-2026-35538 unknown FIX debian debian 2mo ago An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
CVE-2026-35537 unknown FIX debian debian 2mo ago An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated atta…
CVE-2026-34876 high 7.5 7.5 FIX debian debian trustedfirmware 2mo ago An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation …
CVE-2026-5246 high 8.1 8.1 FIX debian debian cesanta 2mo ago A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handler. Executing a mani…
CVE-2026-5245 high 8.1 8.1 FIX debian debian cesanta 2mo ago A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the ar…
CVE-2026-5317 high 8.8 8.8 debian debian nothings 2mo ago A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_vorbis.c. The manipulation results in out-of-bounds write. The attack may be pe…
CVE-2026-5315 high 8.8 8.8 debian debian nothings 2mo ago A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the library stb_truetype.h of the component TTF File Handler. Executing a manipulati…
CVE-2026-4177 high 8.0 FIX debian debian rocky rhel 2mo ago RHSA-2026:6470: perl-YAML-Syck security update (Important)
CVE-2026-3497 high 7.5 7.5 FIX rocky rhel sles canonicalopenbsd 2mo ago Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH u…
CVE-2026-34829 high 8.0 FIX slesdebian debian 2mo ago Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads