Search

Found 27,140 results in 4724ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-49570 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2024-47727 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2024-47679 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2024-46689 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2024-45777 medium 5.5 FIX rheldebian debian sles 7mo ago Moderate: grub2 security update
CVE-2023-54318 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: net/smc: use smc_lgr_list.lock to protect smc_lgr_list.list iterate in smcr_port_add While doing smcr_port_add, there maybe linkg…
CVE-2023-54237 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: net/smc: fix potential panic dues to unprotected smc_llc_srv_add_link() There is a certain chance to trigger the following panic:…
CVE-2023-54152 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: can: j1939: prevent deadlock by moving j1939_sk_errqueue() This commit addresses a deadlock situation that can occur in certain s…
CVE-2023-54119 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: inotify: Avoid reporting event with invalid wd When inotify_freeing_mark() races with inotify_handle_inode_event() it can happen …
CVE-2023-53781 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: smc: Fix use-after-free in tcp_write_timer_handler(). With Eric's ref tracker, syzbot finally found a repro for use-after-free in…
CVE-2023-53426 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: xsk: Fix xsk_diag use-after-free error during socket cleanup Fix a use-after-free error that is possible if the xsk_diag interfac…
CVE-2023-52941 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: can: isotp: split tx timer into transmission and timeout The timer for the transmission of isotp PDUs formerly had two functions:…
CVE-2023-52355 medium 5.5 FIX rhel slesdebian debian 7mo ago Moderate: libtiff security update
CVE-2022-50504 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: powerpc/rtas: avoid scheduling in rtas_os_term() It's unsafe to use rtas_busy_delay() to handle a busy status from the ibm,os-ter…
CVE-2022-50143 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: intel_th: Fix a resource leak in an error handling path If an error occurs after calling 'pci_alloc_irq_vectors()', 'pci_free_irq…
CVE-2022-49845 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49672 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49670 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49657 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49648 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49643 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49627 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49623 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49443 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49437 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49432 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49357 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49353 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49269 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-49024 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2022-48830 medium 5.5 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2018-17828 medium 5.5 rhel sles rocky 7mo ago RHSA-2020:1653: zziplib security update (Moderate)
CVE-2025-60876 medium 6.5 6.5 FIX debian debian sles busybox 7mo ago BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to b…
CVE-2025-40300 medium 5.5 5.5 FIX rocky rhel sles 7mo ago Moderate: kernel security update
CVE-2025-7700 medium 5.3 5.3 FIX debian debian sles 7mo ago A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files.…
CVE-2025-10966 medium 4.3 4.3 FIX debian debian sles haxx 7mo ago curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and…
CVE-2025-67897 unknown FIX debian debian 7mo ago In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted me…
CVE-2025-64459 unknown 1.0 EXPFIX debian debian 7mo ago Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
CVE-2025-64458 unknown FIX debian debian 7mo ago Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-27144 medium 5.5 FIX rheldebian debian sles 7mo ago Moderate: buildah security update
CVE-2023-52970 medium 5.5 FIX rocky rhel sles 7mo ago MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where.
CVE-2023-52969 medium 5.5 FIX rocky rhel sles 7mo ago MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This may be related to make_aggr_tables_info an…
CVE-2023-53494 medium 5.5 FIX rhel slesdebian debian 7mo ago Moderate: kernel security update
CVE-2023-53257 medium 5.5 FIX slesdebian debian rhel 7mo ago In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check S1G action frame size Before checking the action code, check that it even exists in the frame.
CVE-2023-53226 medium 5.5 FIX slesdebian debian rhel 7mo ago In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix OOB and integer underflow when rx packets Make sure mwifiex_process_mgmt_packet, mwifiex_process_sta_rx_packet…
CVE-2022-50367 medium 5.5 FIX rocky rhel sles 7mo ago Moderate: kernel security update
CVE-2025-12464 medium 6.2 6.2 FIX slesdebian debian 7mo ago A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems…
CVE-2025-57108 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector me…
CVE-2025-57107 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accesso…
CVE-2025-57106 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing…
CVE-2025-13327 unknown FIX slesdebian debian 7mo ago A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that …
CVE-2025-61724 unknown FIX debian debian sles 7mo ago The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.
CVE-2025-58188 unknown FIX debian debian sles google 7mo ago Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arb…
CVE-2025-58186 unknown FIX debian debian sles 7mo ago Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP …
CVE-2025-58185 unknown FIX debian debian sles 7mo ago Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
CVE-2025-47912 unknown FIX debian debian sles 7mo ago The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host compon…
CVE-2025-61723 unknown FIX debian debian sles google 7mo ago The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs.
CVE-2025-58189 unknown FIX debian debian sles 7mo ago When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
CVE-2025-58187 unknown FIX debian debian sles google 7mo ago Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate ar…
CVE-2025-61725 unknown FIX debian debian sles 7mo ago The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.
CVE-2025-62727 unknown FIX slesdebian debian 7mo ago Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-ti…
CVE-2025-62171 unknown FIX debian debian sles 7mo ago ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exis…
CVE-2025-40039 unknown FIX slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix race condition in RPC handle list access The 'sess->rpc_handle_list' XArray manages RPC handles within a ksmbd session…
CVE-2025-62594 unknown FIX debian debian sles 7mo ago ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and div…
CVE-2025-61795 medium 5.3 5.3 FIX slesdebian debian apache 7mo ago Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded …
CVE-2025-12207 medium 5.5 5.5 debian debian kamailio 7mo ago A vulnerability has been found in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the component Grammar Rule Handler. Such manipulation leads to null pointer derefere…
CVE-2025-12206 medium 5.5 5.5 debian debian kamailio 7mo ago A flaw has been found in Kamailio 5.5. The impacted element is the function rve_is_constant of the file src/core/rvalue.c. This manipulation causes null pointer dereference. The attack needs to be la…
CVE-2025-39819 medium 5.5 5.5 FIX rhel sles rocky 7mo ago In the Linux kernel, the following vulnerability has been resolved: fs/smb: Fix inconsistent refcnt update A possible inconsistent update of refcount was identified in `smb2_compound_op`. Such inco…
CVE-2025-39730 medium 5.5 FIX rhel sles rocky 7mo ago In the Linux kernel, the following vulnerability has been resolved: NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() The function needs to check the minimal filehandle length before it can…
CVE-2025-39718 medium 5.5 5.5 FIX rhel sles rocky 7mo ago In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Validate length in packet header before skb_put() When receiving a vsock packet in the guest, only the virtqueue bu…
CVE-2025-22122 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: block: fix adding folio to bio >4GB folio is possible on some ARCHs, such as aarch64, 16GB hugepage is supported, then 'offset' o…
CVE-2025-22045 medium 5.5 FIX slesdebian debian rhel 7mo ago In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs On the following path, flush_tlb_range() can be used for zapping …
CVE-2023-53386 medium 5.5 FIX rocky slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix potential use-after-free when clear keys Similar to commit c5d2b6fa26b5 ("Bluetooth: Fix use-after-free in hci_rem…
CVE-2023-53331 medium 5.5 FIX rhel sles rocky 7mo ago In the Linux kernel, the following vulnerability has been resolved: pstore/ram: Check start of empty przs during init After commit 30696378f68a ("pstore/ram: Do not treat empty buffers as valid"), …
CVE-2022-50386 medium 5.5 FIX rocky slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix user-after-free This uses l2cap_chan_hold_unless_zero() after calling __l2cap_get_chan_blah() to prevent th…
CVE-2025-12194 unknown debian debian sles 8mo ago Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
CVE-2025-40022 unknown FIX slesdebian debian 8mo ago In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix incorrect boolean values in af_alg_ctx Commit 1b34cbbf4f01 ("crypto: af_alg - Disallow concurrent writes in …
CVE-2025-53057 medium 5.9 5.9 FIX rhel slesdebian debian oracle 8mo ago Moderate: java-1.8.0-openjdk security update
CVE-2022-4981 medium 5.5 5.5 FIX debian debian offis 8mo ago A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeerList of the file /dcmqrcnf.cc of the component dcmqrscp. The manipulation resul…
CVE-2020-36855 medium 5.5 5.5 FIX debian debian offis 8mo ago A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the component dcmqrscp. The manipulation of the argument StorageQuota leads to stac…
CVE-2025-40005 medium 5.5 5.5 FIX slesdebian debian linux-kernel 8mo ago In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Implement refcount to handle unbind during busy driver support indirect read and indirect write operation w…
CVE-2025-38571 medium 5.5 FIX rhel slesdebian debian 8mo ago Moderate: kernel security update
CVE-2025-38566 medium 5.5 FIX rhel slesdebian debian 8mo ago Moderate: kernel security update
CVE-2025-22026 medium 5.5 FIX rhel rocky sles 8mo ago Moderate: kernel security update
CVE-2025-11840 medium 5.5 5.5 FIX debian debian sles gnu 8mo ago A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be …
CVE-2025-41254 unknown debian debian 8mo ago Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
CVE-2025-11839 medium 5.5 5.5 FIX debian debian sles gnu 8mo ago A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be…
CVE-2025-5318 medium 5.5 FIX rocky rheldebian debian 8mo ago RHSA-2025:18286: libssh security update (Moderate)
CVE-2025-59419 unknown FIX slesdebian debian 8mo ago Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
CVE-2025-39997 unknown FIX slesdebian debian 8mo ago In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free The previous commit 0718a78f6a9f ("ALSA: usb-audio: Kill timer pro…
CVE-2025-39977 unknown FIX slesdebian debian 8mo ago In the Linux kernel, the following vulnerability has been resolved: futex: Prevent use-after-free during requeue-PI syzbot managed to trigger the following race: T1 …
CVE-2025-43368 medium 4.3 4.3 FIX rhel rocky sles apple 8mo ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing maliciously crafted web content may lead to an…
CVE-2025-53906 medium 5.5 FIX rhel rocky sles 8mo ago Moderate: vim security update
CVE-2025-53905 medium 5.5 FIX rhel rocky sles 8mo ago Moderate: vim security update
CVE-2025-38614 medium 5.5 5.5 FIX rhel sles rocky 8mo ago Moderate: kernel security update
CVE-2025-38556 medium 5.5 FIX rhel rocky sles 8mo ago Moderate: kernel security update
CVE-2023-53373 medium 5.5 FIX rhel rocky sles 8mo ago Moderate: kernel security update
CVE-2023-53305 medium 5.5 FIX rocky slesdebian debian 8mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free Fix potential use-after-free in l2cap_le_command_rej.
CVE-2025-62706 unknown FIX slesdebian debian 8mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF path performs unbounded DEFLATE decompression. A very small ciphertext can exp…
CVE-2025-61920 unknown FIX slesdebian debian 8mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote atta…