Search

Found 28,443 results in 2732ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-6218 unknown 1.5 KEVFIX debian debian 6mo ago RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
CVE-2025-39979 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-39925 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-40281 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto syzbot reported a possible shift-out-of-bounds [1] Blame…
CVE-2025-40280 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_mon_reinit_self(). syzbot reported use-after-free of tipc_net(net)->monitors[] in tipc_mon_reini…
CVE-2025-40278 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak Fix a KMSAN kernel-infoleak detected by the syzbot . …
CVE-2025-66564 unknown FIX debian debian 6mo ago Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (whi…
CVE-2025-66506 unknown FIX debian debian 6mo ago Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.3, function identity.extractIssuerURL splits (via a call to str…
CVE-2025-66516 unknown FIX debian debian 6mo ago Apache Tika has XXE vulnerability
CVE-2025-40264 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pk…
CVE-2025-40263 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: Input: cros_ec_keyb - fix an invalid memory access If cros_ec_keyb_register_matrix() isn't called (due to `buttons_switches_only`…
CVE-2025-40262 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload This is supposed to be "priv" but we accidentally pass "&priv" which is an ad…
CVE-2025-40261 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() nvme_fc_delete_assocation() waits for pending I/O to com…
CVE-2025-40257 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptcp_pm_del_add_timer() can call sk_stop_timer_sync(sk, &entry->add_timer) while a…
CVE-2025-40254 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: remove never-working support for setting nsh fields The validation of the set(nsh(...)) action is completely wr…
CVE-2025-40250 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clean up only new IRQ glue on request_irq() failure The mlx5_irq_alloc() function can inadvertently free the entire rma…
CVE-2025-40214 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a receive queue of …
CVE-2025-14010 medium 5.5 5.5 FIX debian debian redhat 6mo ago Ansible Community General Collection is vulnerable to exposure of sensitive information
CVE-2024-3884 unknown debian debian 6mo ago Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded
CVE-2025-66453 unknown slesdebian debian 6mo ago Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
CVE-2025-65955 unknown FIX debian debian sles 6mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests …
CVE-2025-4598 medium 4.7 4.7 FIX arch arch rhel sles systemd_projectredhat 6mo ago Moderate: systemd security update
CVE-2025-61727 unknown FIX debian debian sles 6mo ago An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com doe…
CVE-2025-64460 unknown FIX slesdebian debian 6mo ago Django is vulnerable to DoS via XML serializer text extraction
CVE-2025-13372 unknown FIX slesdebian debian 6mo ago Django is vulnerable to SQL injection in column aliases
CVE-2025-66412 medium 5.4 5.4 FIX debian debian angular 6mo ago Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scriptin…
CVE-2025-9714 medium 5.5 5.5 FIX rheldebian debian sles xmlsoft 6mo ago Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPat…
CVE-2025-40186 medium 5.5 FIX slesdebian debian rhel 6mo ago In the Linux kernel, the following vulnerability has been resolved: tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). syzbot reported the splat below in tcp_conn_request(). [0] If a l…
CVE-2025-40185 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-40058 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-39981 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-39955 medium 5.5 FIX rocky rhel sles 6mo ago Moderate: kernel security update
CVE-2025-39918 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-12183 unknown debian debian 6mo ago LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS
CVE-2025-66382 low 2.9 2.9 debian debian sles libexpat_project 6mo ago In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
CVE-2025-66035 unknown FIX debian debian 6mo ago Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF tok…
CVE-2025-9624 unknown debian debian 6mo ago OpenSearch is vulnerable to DoS via complex query_string inputs
CVE-2025-39843 medium 5.5 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-58183 medium 5.5 FIX rocky rheldebian debian 7mo ago Moderate: image-builder security update
CVE-2025-47914 unknown FIX debian debian sles 7mo ago SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
CVE-2025-58181 unknown FIX debian debian sles 7mo ago SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
CVE-2025-12119 unknown FIX debian debian 7mo ago A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVE-2025-13223 unknown 1.5 KEVFIX debian debian 7mo ago Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-61664 medium 4.9 4.9 FIX debian debian sles 7mo ago A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when it…
CVE-2025-54771 medium 4.9 4.9 FIX debian debian sles 7mo ago A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invali…
CVE-2025-54770 medium 4.9 4.9 FIX debian debian sles 7mo ago A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the net_set_vlan…
CVE-2025-65015 unknown FIX debian debian 7mo ago joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 and from 1.4.0 to before 1.4.2, the …
CVE-2025-65073 unknown FIX debian debian 7mo ago OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.
CVE-2025-40047 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: always prune wait queue entry in io_waitid_wait() For a successful return, always remove our entry from the wait…
CVE-2025-39983 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix UAF in hci_conn_tx_dequeue This fixes the following UAF caused by not properly locking hdev when proces…
CVE-2025-39982 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync This fixes the following UFA in hci_acl_create_conn_sync where a connec…
CVE-2025-39973 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: i40e: add validation for ring_len param The `ring_len` parameter provided by the virtual function (VF) is assigned directly to th…
CVE-2025-39971 medium 5.5 FIX rocky rhel sles 7mo ago In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in config queues msg Ensure idx is within range of active/initialized TCs when iterating over vf->ch[idx…
CVE-2025-39881 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: kernfs: Fix UAF in polling when open file is released A use-after-free (UAF) vulnerability was identified in the PSI (Pressure St…
CVE-2025-39697 medium 4.7 4.7 FIX rocky rhel sles 7mo ago In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a race when updating an existing write After nfs_lock_and_join_requests() tests for whether the request is still attache…
CVE-2025-13120 medium 5.5 5.5 debian debian mruby 7mo ago A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use after free. An attack has to be approache…
CVE-2025-64507 unknown FIX debian debian 7mo ago Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a c…
CVE-2025-64500 unknown FIX debian debian 7mo ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Start…
CVE-2025-63396 unknown debian debian 7mo ago An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (D…
CVE-2025-40163 unknown FIX slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Stop dl_server before CPU goes offline IBM CI tool reported kernel warning[1] when running a CPU removal operatio…
CVE-2026-23205 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: smb/client: fix memory leak in smb2_open_file() Reproducer: 1. server: directories are exported read-only 2. client: mount -…
CVE-2026-23146 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix null-ptr-deref in hci_uart_write_work hci_uart_set_proto() sets HCI_UART_PROTO_INIT before calling hci_u…
CVE-2025-38438 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid memleak. sof_pdata->tplg_filename can have address allocated by kstrdup() and …
CVE-2025-38396 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-38322 medium 5.5 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix crash in icl_update_topdown_event() The perf_fuzzer found a hard-lockup crash on a RaptorLake machine: Oop…
CVE-2025-38288 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Fix smp_processor_id() call trace for preemptible kernels Correct kernel call trace when calling smp_processor_id…
CVE-2025-38234 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: sched/rt: Fix race in push_rt_task Overview ======== When a CPU chooses to call push_rt_task and picks a task to push to another …
CVE-2025-38127 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: ice: fix Tx scheduler error handling in XDP callback When the XDP program is loaded, the XDP callback adds new Tx queues. This me…
CVE-2025-38116 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-38075 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix timeout on deleted connection NOPIN response timer may expire on a deleted connection and crash with suc…
CVE-2025-38013 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Set n_channels after allocating struct cfg80211_scan_request Make sure that n_channels is set after allocating th…
CVE-2025-37994 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-37849 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we…
CVE-2025-37825 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: nvmet: fix out-of-bounds access in nvmet_enable_port When trying to enable a port that has no transport configured yet, nvmet_ena…
CVE-2025-23129 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Clear affinity hint before calling ath11k_pcic_free_irq() in error path If a shared IRQ is used by the driver due t…
CVE-2025-22247 medium 5.5 FIX rocky rhel sles 7mo ago RHBA-2026:0860: open-vm-tools bug fix and enhancement update (Moderate)
CVE-2025-22119 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: init wiphy_work before allocating rfkill fails syzbort reported a uninitialize wiphy_work_lock in cfg80211_dev_fr…
CVE-2025-22116 medium 5.5 FIX rhel slesdebian debian google 7mo ago In the Linux kernel, the following vulnerability has been resolved: idpf: check error for register_netdev() on init Current init logic ignores the error code from register_netdev(), which will caus…
CVE-2025-22111 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: net: Remove RTNL dance for SIOCBRADDIF and SIOCBRDELIF. SIOCBRDELIF is passed to dev_ioctl() first and later forwarded to br_ioct…
CVE-2025-22092 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: PCI: Fix NULL dereference in SR-IOV VF creation error path Clean up when virtfn setup fails to prevent NULL pointer dereference d…
CVE-2025-22089 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Don't expose hw_counters outside of init net namespace Commit 467f432a521a ("RDMA/core: Split port and device counter …
CVE-2025-22086 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow When cur_qp isn't NULL, in order to avoid fetching the QP from the radix tree a…
CVE-2025-22056 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21902 medium 5.5 FIX rhel sles rocky 7mo ago In the Linux kernel, the following vulnerability has been resolved: acpi: typec: ucsi: Introduce a ->poll_cci method For the ACPI backend of UCSI the UCSI "registers" are just a memory copy of the …
CVE-2025-21864 medium 5.5 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21861 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21855 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21853 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21851 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21848 medium 5.5 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21847 medium 5.5 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21846 medium 5.5 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21844 medium 5.5 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21839 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21829 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21828 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21826 medium 5.5 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21806 medium 5.5 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21795 medium 5.5 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21791 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update