Search

Found 29,623 results in 2744ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-14178 medium 5.5 FIX rockyalmalinux almalinux rhel 4mo ago In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_merge() when the total element count of …
CVE-2025-14177 medium 5.5 FIX rocky rhelalmalinux almalinux 4mo ago In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn se…
CVE-2025-12084 medium 5.5 FIX rocky rheldebian debian 4mo ago Moderate: python3.12 security update
CVE-2026-24686 unknown FIX debian debian sles 4mo ago go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the lo…
CVE-2026-24486 unknown 1.0 EXPFIX slesdebian debian 4mo ago Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_…
CVE-2026-24400 unknown debian debian sles 4mo ago AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion
CVE-2026-24061 unknown 2.5 KEVEXPFIX debian debian 4mo ago GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.
CVE-2018-14634 unknown 2.5 KEVEXPFIX slesdebian debian 4mo ago Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escala…
CVE-2025-71161 medium 5.5 5.5 FIX slesdebian debian linux-kernel google 5mo ago In the Linux kernel, the following vulnerability has been resolved: dm-verity: disable recursive forward error correction There are two problems with the recursive correction: 1. It may cause deni…
CVE-2026-0775 unknown slesdebian debian 5mo ago npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker mu…
CVE-2026-24137 unknown FIX debian debian sles 5mo ago sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. I…
CVE-2026-23954 unknown FIX debian debian 5mo ago Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use d…
CVE-2026-23953 unknown FIX debian debian 5mo ago Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ grou…
CVE-2026-24117 unknown FIX slesdebian debian 5mo ago Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public k…
CVE-2026-23831 unknown FIX slesdebian debian 5mo ago Rekor is a software supply chain transparency log. In versions 1.4.3 and below, the entry implementation can panic on attacker-controlled input when canonicalizing a proposed entry with an empty spec…
CVE-2026-1225 unknown slesdebian debian 5mo ago Logback allows an attacker to instantiate classes already present on the class path
CVE-2026-21933 medium 6.1 6.1 FIX rocky rhel sles oracle 5mo ago RHSA-2026:4832: java-1.8.0-ibm security update (Important)
CVE-2026-21925 medium 4.8 4.8 FIX rocky rhel sles oracle 5mo ago RHSA-2026:4832: java-1.8.0-ibm security update (Important)
CVE-2026-23992 unknown FIX debian debian sles 5mo ago go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signa…
CVE-2026-23991 unknown FIX debian debian sles 5mo ago go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (val…
CVE-2026-22444 unknown FIX debian debian 5mo ago Apache Solr: Insufficient file-access checking in standalone core-creation requests
CVE-2026-22022 unknown FIX debian debian 5mo ago Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
CVE-2026-22977 medium 5.5 5.5 FIX slesdebian debian linux-kernel 5mo ago In the Linux kernel, the following vulnerability has been resolved: net: sock: fix hardened usercopy panic in sock_recv_errqueue skbuff_fclone_cache was created without defining a usercopy region, …
CVE-2026-22976 medium 5.5 5.5 FIX slesdebian debian linux-kernel 5mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset `qfq_class->leaf_qdisc->q.qlen > 0` does not…
CVE-2026-23952 unknown FIX debian debian sles 5mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting La…
CVE-2026-23874 unknown FIX debian debian sles 5mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Languag…
CVE-2025-67726 medium 5.5 FIX rocky slesdebian debian 5mo ago RHSA-2026:0930: pcs security update (Moderate)
CVE-2025-67725 medium 5.5 FIX rocky slesdebian debian 5mo ago RHSA-2026:0930: pcs security update (Moderate)
CVE-2026-22770 unknown FIX debian debian sles 5mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in …
CVE-2025-15537 medium 5.5 5.5 debian debian mapnik 5mo ago A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::string_value of the file plugins/input/shape/dbfile.cpp. Such manipulation leads to…
CVE-2025-15536 medium 5.5 5.5 FIX slesdebian debian byvoid 5mo ago A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes he…
CVE-2026-23528 unknown debian debian 5mo ago Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, and Dask distributed are all run together, it is possible to craft a URL which wi…
CVE-2025-15104 unknown debian debian 5mo ago Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services.…
CVE-2026-0858 medium 6.1 6.1 slesdebian debian plantuml 5mo ago PlantUML is vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams
CVE-2025-46397 medium 5.5 FIX rocky rheldebian debian 5mo ago RHSA-2026:0756: transfig security update (Moderate)
CVE-2025-69725 unknown FIX debian debian sles 5mo ago An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.
CVE-2026-22036 unknown FIX slesdebian debian 5mo ago Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert tho…
CVE-2025-71140 unknown FIX slesdebian debian 5mo ago In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Use spinlock for context list protection lock Previously a mutex was added to protect the encoder and de…
CVE-2025-14242 medium 5.5 FIX rocky rhel sles 5mo ago RHSA-2026:0608: vsftpd security update (Moderate)
CVE-2026-22772 unknown FIX debian debian sles 5mo ago Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() function uses unanchored regex, allowing attackers …
CVE-2026-22702 unknown FIX slesdebian debian 5mo ago virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform sym…
CVE-2026-22701 unknown FIX slesdebian debian 5mo ago filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker …
CVE-2025-68823 medium 5.5 5.5 FIX slesdebian debian linux-kernel 5mo ago In the Linux kernel, the following vulnerability has been resolved: ublk: fix deadlock when reading partition table When one process(such as udev) opens ublk block device (e.g., to read the partiti…
CVE-2026-22703 unknown FIX debian debian sles 5mo ago Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to successfully verify an artifact even if the embedded Reko…
CVE-2025-12817 medium 5.5 FIX rocky rhel sles 5mo ago Moderate: postgresql:15 security update
CVE-2025-40240 medium 5.5 FIX rocky rhel sles 5mo ago Moderate: kernel security update
CVE-2025-39883 medium 5.5 FIX rocky rhel sles 5mo ago Moderate: kernel security update
CVE-2025-39840 medium 5.5 FIX rhel sles rocky 5mo ago Moderate: kernel security update
CVE-2025-12818 medium 5.5 FIX rocky rhel sles 5mo ago Moderate: postgresql:15 security update
CVE-2026-0821 critical 9.8 9.8 debian debian quickjs-ng 5mo ago A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-…
CVE-2026-22610 medium 6.1 6.1 FIX debian debian angular 5mo ago Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cros…
CVE-2025-68158 unknown FIX slesdebian debian 5mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage is not tied to the initiating user session, so CSR…
CVE-2025-61915 medium 5.5 FIX rocky rheldebian debian 5mo ago RHSA-2026:0596: cups security update (Moderate)
CVE-2025-58436 medium 5.5 FIX rocky rheldebian debian 5mo ago RHSA-2026:0596: cups security update (Moderate)
CVE-2026-21885 unknown FIX debian debian 5mo ago Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SS…
CVE-2025-12543 unknown debian debian 5mo ago Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests
CVE-2026-21968 medium 5.5 FIX rocky rhel sles 5mo ago Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vuln…
CVE-2023-52971 medium 5.5 FIX rocky rhel sles 5mo ago MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan.
CVE-2026-21892 unknown FIX debian debian 5mo ago Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. The application constructs SQL queries using unsaf…
CVE-2025-32365 medium 5.5 FIX rocky rhel sles 5mo ago Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
CVE-2025-69230 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is…
CVE-2025-69229 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a …
CVE-2025-69228 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontro…
CVE-2025-69227 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS a…
CVE-2025-69226 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path no…
CVE-2025-69225 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There…
CVE-2025-69224 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII…
CVE-2025-69223 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be a…
CVE-2026-21452 unknown debian debian 5mo ago MessagePack for Java Vulnerable to Remote DoS via Malicious EXT Payload Allocation
CVE-2025-68131 unknown FIX debian debian sles 5mo ago CBORDecoder reuse can leak shareable values across decode calls
CVE-2025-68950 unknown FIX debian debian sles 5mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a …
CVE-2025-68618 unknown FIX debian debian sles 5mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7…
CVE-2025-67746 unknown FIX debian debian sles 5mo ago Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI cont…
CVE-2023-54164 unknown FIX slesdebian debian 5mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix iso_conn related locking and validity issues sk->sk_state indicates whether iso_pi(sk)->conn is valid. Operat…
CVE-2026-0810 unknown debian debian 5mo ago A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `T…
CVE-2023-54130 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: avoid WARN_ON() for sanity check, use proper error handling Commit 55d1cbbbb29e ("hfs/hfsplus: use WARN_ON for sanit…
CVE-2025-68351 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: exfat: fix refcount leak in exfat_find Fix refcount leaks in `exfat_find` related to `exfat_get_dentry_set`. Function `exfat_get…
CVE-2025-14957 medium 5.5 5.5 debian debian webassembly 6mo ago A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBuilder::makeLocalSet/IRBuilder::makeLocalTee of the file src/wasm/wasm-ir-builde…
CVE-2025-68161 unknown FIX debian debian sles 6mo ago Apache Log4j does not verify the TLS hostname in its Socket Appender
CVE-2025-68463 medium 4.9 4.9 FIX debian debian 6mo ago Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
CVE-2025-8291 medium 5.5 FIX rocky rhelalmalinux almalinux 6mo ago The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD re…
CVE-2025-6491 medium 5.5 FIX rockyalmalinux almalinux rhel 6mo ago In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null …
CVE-2025-5987 medium 5.5 FIX rheldebian debian sles 6mo ago Moderate: libssh security update
CVE-2025-1735 medium 5.5 FIX rockyalmalinux almalinux rhel 6mo ago In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This coul…
CVE-2025-1220 medium 5.5 FIX rocky rhelalmalinux almalinux 6mo ago In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null cha…
CVE-2024-29371 unknown FIX slesdebian debian 6mo ago jose4j is vulnerable to DoS via compressed JWE content
CVE-2025-61985 medium 5.5 FIX rocky rhel sles 6mo ago ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
CVE-2025-61984 medium 5.5 FIX rocky rhel sles 6mo ago ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrus…
CVE-2025-38499 medium 5.5 5.5 FIX rhel sles rocky 6mo ago Important: kernel security update
CVE-2025-68154 unknown FIX debian debian 6mo ago systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows syste…
CVE-2025-68146 unknown FIX slesdebian debian 6mo ago filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user …
CVE-2025-68142 unknown FIX debian debian 6mo ago PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a ReDOS bug found within the figure caption extension (`pymdownx.blocks.caption`).…
CVE-2023-53900 medium 6.1 6.1 debian debian spip 6mo ago Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo …
CVE-2025-68315 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to detect potential corrupted nid in free_nid_list As reported, on-disk footer.ino and footer.nid is the same and out-o…
CVE-2025-68307 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs The driver lacks the cleanup of failed transfers of …
CVE-2025-68251 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: erofs: avoid infinite loops due to corrupted subpage compact indexes Robert reported an infinite loop observed by two crafted ima…
CVE-2025-68239 unknown FIX slesdebian debian google 6mo ago In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write access before closing files opened by open_exec() bm_register_write() opens an executable file using o…
CVE-2025-68201 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: remove two invalid BUG_ON()s Those can be triggered trivially by userspace.
CVE-2025-40347 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: net: enetc: fix the deadlock of enetc_mdio_lock After applying the workaround for err050089, the LS1028A platform experiences RCU…
CVE-2025-67735 unknown FIX slesdebian debian 6mo ago Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder