Search

Found 25,864 results in 3368ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-25989 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-on…
CVE-2026-25988 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, sometimes msl.c fails to update the stack index, so an image i…
CVE-2026-25987 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the MAP image …
CVE-2026-25985 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes Imag…
CVE-2026-25983 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted MSL script triggers a heap-use-after-free. The opera…
CVE-2026-25969 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak exists in `coders/ashlar.c`. The `WriteASHLARImage` allocates a…
CVE-2026-25967 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a stack-based buffer overflow exists in the ImageMagick FTXT image reader. A …
CVE-2026-25966 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" security policy includes a rule intended to prevent reading/writing from standard s…
CVE-2026-25965 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw file…
CVE-2026-25898 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index …
CVE-2026-25897 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. O…
CVE-2026-25799 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an inva…
CVE-2026-25798 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a NULL pointer dereference in ClonePixelCacheRepository allows…
CVE-2026-25797 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the ps coders, responsible for writing PostScript files, fails…
CVE-2026-25796 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` …
CVE-2026-25795 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSFWImage()` (`coders/sfw.c`), when temporary file crea…
CVE-2026-25794 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to ver…
CVE-2026-25638 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, memory leak exists in `coders/msl.c`. In the `WriteMSLImage` f…
CVE-2026-25637 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak in the ASHLAR image writer allows an attacker to exhaust proces…
CVE-2026-25576 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw i…
CVE-2026-24485 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the Deco…
CVE-2026-24484 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions t…
CVE-2026-24481 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMag…
CVE-2026-3102 high 8.8 8.8 FIX debian debianmacos macos exiftool_project 3mo ago A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulati…
CVE-2026-26198 unknown FIX debian debian 3mo ago Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by passing user-supplied column names directly into `sq…
CVE-2026-2968 low 3.7 3.7 FIX debian debian cesanta 3mo ago A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handle…
CVE-2026-2967 low 3.7 3.7 FIX debian debian cesanta 3mo ago A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulat…
CVE-2026-2966 low 3.7 3.7 FIX debian debian cesanta 4mo ago A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipu…
CVE-2026-25646 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:9686: java-17-openjdk security update (Important)
CVE-2026-25506 high 8.0 FIX rocky rhel sles 4mo ago RHSA-2026:3032: munge security update (Important)
CVE-2026-23074 high 8.0 FIX slesdebian debianalmalinux almalinux 4mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: Enforce that teql can only be used as root qdisc Design intent of teql is that it is only supposed to be used as root …
CVE-2026-22859 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:3334: freerdp security update (Important)
CVE-2026-22858 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:3334: freerdp security update (Important)
CVE-2026-22855 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:3334: freerdp security update (Important)
CVE-2025-38248 high 8.0 FIX slesdebian debianalmalinux almalinux 4mo ago In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix use-after-free during router port configuration The bridge maintains a global list of ports behind which a mul…
CVE-2026-2913 high 7.0 7.0 FIX slesdebian debian libvips 4mo ago A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation causes heap-based buffe…
CVE-2026-2903 low 3.3 3.3 FIX slesdebian debian 4mo ago A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_rules of the file src/parse/ast.cc. This manipulation causes null pointer dereference. The attack ca…
CVE-2026-2889 low 3.3 3.3 debian debian 4mo ago A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only…
CVE-2026-21620 unknown FIX debian debian sles 4mo ago Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file module…
CVE-2025-68461 unknown 1.5 KEVFIX debian debian 4mo ago RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
CVE-2026-24122 unknown FIX debian debian sles 4mo ago Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be conside…
CVE-2026-2705 high 8.1 8.1 debian debian openbabel 4mo ago A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The ma…
CVE-2026-26318 unknown FIX debian debian 4mo ago systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixe…
CVE-2026-26280 unknown FIX debian debian 4mo ago systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an attacker to execute arb…
CVE-2026-2661 high 7.8 7.8 slesdebian debian squirrel-lang 4mo ago A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. …
CVE-2026-24708 unknown FIX debian debian 4mo ago An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user ma…
CVE-2025-14009 unknown FIX debian debian 4mo ago NLTK has a Zip Slip Vulnerability
CVE-2026-2659 high 7.8 7.8 debian debian squirrel-lang 4mo ago A vulnerability was determined in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTarget of the file src/squirrel/squirrel/sqfuncstate.cpp. Executing a manipulation…
CVE-2026-23230 high 8.8 8.8 FIX slesdebian debian linux-kernel 4mo ago In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid shared-byte RMW races is_open, has_lease and on_list are stored in the same bitf…
CVE-2026-23222 high 7.8 7.8 FIX slesdebian debian linux-kernel 4mo ago In the Linux kernel, the following vulnerability has been resolved: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly The existing allocation of scatterlists in omap_crypto_copy…
CVE-2026-2653 high 7.8 7.8 debian debian admesh_project 4mo ago A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Performing a manipulation results in heap-based buffer o…
CVE-2026-2644 high 7.8 7.8 debian debian minisat 4mo ago A weakness has been identified in niklasso minisat up to 2.2.0. This issue affects the function Solver::value in the library core/SolverTypes.h of the component DIMACS File Parser. This manipulation …
CVE-2026-2641 low 3.3 3.3 debian debian 4mo ago A weakness has been identified in universal-ctags ctags up to 6.2.1. The affected element is the function parseExpression/parseExprList of the file parsers/v.c of the component V Language Parser. Exe…
CVE-2026-24734 unknown FIX slesdebian debian google 4mo ago Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verific…
CVE-2026-24733 unknown FIX slesdebian debian 4mo ago Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny…
CVE-2025-66614 unknown FIX slesdebian debian 4mo ago Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were…
CVE-2026-25087 unknown FIX debian debian 4mo ago Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-…
CVE-2026-2441 unknown 2.5 KEVEXPFIX debian debian sles 4mo ago Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-21637 high 8.0 FIX rocky rhel sles 4mo ago Important: nodejs:24 security update
CVE-2025-59466 high 8.0 FIX rocky rhel sles 4mo ago Important: nodejs:24 security update
CVE-2025-59465 high 8.0 FIX rocky rhel sles 4mo ago Important: nodejs:24 security update
CVE-2025-55132 high 8.0 FIX rocky rhel sles 4mo ago Important: nodejs:24 security update
CVE-2025-55131 high 8.0 FIX rocky rhel sles 4mo ago Important: nodejs:24 security update
CVE-2025-55130 high 8.0 FIX rocky rhel sles 4mo ago Important: nodejs:24 security update
CVE-2025-61732 high 8.0 FIX rocky rheldebian debian google 4mo ago A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVE-2025-61728 high 8.0 FIX rocky rheldebian debian google 4mo ago archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously construct…
CVE-2025-15059 high 8.0 FIX rheldebian debian sles 4mo ago Important: gimp security update
CVE-2025-71221 high 7.0 7.0 FIX slesdebian debian linux-kernel 4mo ago In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() Add proper locking in mmp_pdma_residue() to prevent use-after-free …
CVE-2025-47911 unknown FIX debian debian sles 4mo ago The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted H…
CVE-2026-26158 high 7.0 7.0 FIX debian debian sles 4mo ago A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or …
CVE-2026-26157 high 7.0 8.0 EXPFIX debian debian sles 4mo ago A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may wr…
CVE-2026-25990 high 7.5 7.5 FIX slesdebian debian python 4mo ago Pillow affected by out-of-bounds write when loading PSD images
CVE-2025-15570 high 7.8 7.8 FIX debian debian ckolivas 4mo ago A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is …
CVE-2026-23901 unknown debian debian 4mo ago Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability
CVE-2026-25934 unknown FIX debian debian sles 4mo ago go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not …
CVE-2026-25639 high 7.5 7.5 FIX debian debian axios 4mo ago Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
CVE-2026-2245 low 3.3 3.3 debian debian 4mo ago A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library src/lib_ccx/ts_tables.c of the component MPEG-TS File Parser. Such manipulation l…
CVE-2026-23903 unknown debian debian 4mo ago Apache Shiro has an Authentication Bypass
CVE-2026-1761 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2215: libsoup security update (Important)
CVE-2026-0719 high 8.0 rocky rheldebian debian 4mo ago RHSA-2026:2215: libsoup security update (Important)
CVE-2025-39760 high 7.1 7.1 FIX rocky rhel sles 4mo ago Moderate: kernel security update
CVE-2026-2069 low 3.3 3.3 debian debian 4mo ago A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the file llama.cpp/src/llama-grammar.cpp of the component GBNF Grammar Handler. This…
CVE-2025-68458 unknown FIX debian debian 4mo ago Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts out…
CVE-2025-68157 unknown FIX debian debian 4mo ago Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, bu…
CVE-2025-58190 unknown FIX debian debian sles 4mo ago The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML …
CVE-2026-23884 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2081: freerdp security update (Important)
CVE-2026-23883 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2081: freerdp security update (Important)
CVE-2026-23534 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2081: freerdp security update (Important)
CVE-2026-23533 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2081: freerdp security update (Important)
CVE-2026-23532 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2081: freerdp security update (Important)
CVE-2026-23531 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2081: freerdp security update (Important)
CVE-2026-23530 high 8.0 FIX rocky rheldebian debian 4mo ago RHSA-2026:2081: freerdp security update (Important)
CVE-2025-15279 high 8.0 rheldebian debian sles 4mo ago RHSA-2026:7677: fontforge security update (Important)
CVE-2025-15275 high 8.0 rheldebian debian sles 4mo ago RHSA-2026:7677: fontforge security update (Important)
CVE-2025-15269 high 8.0 rheldebian debian sles 4mo ago RHSA-2026:7677: fontforge security update (Important)
CVE-2025-22873 low 2.5 FIX arch archdebian debian sles 4mo ago It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape o…
CVE-2026-23066 high 7.8 7.8 FIX slesdebian debian linux-kernel 4mo ago In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix recvmsg() unconditional requeue If rxrpc_recvmsg() fails because MSG_DONTWAIT was specified but the call at the front …
CVE-2026-24049 high 8.0 FIX rocky rhel sles 4mo ago RHSA-2026:2090: python3.12-wheel security update (Important)
CVE-2026-1312 unknown FIX slesdebian debian 4mo ago Django has an SQL Injection issue
CVE-2026-1287 unknown FIX slesdebian debian 4mo ago Django has an SQL Injection issue