Search

Found 49,540 results in 2249ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-4892 high 8.4 8.4 FIX rheldebian debian sles 19d ago RHSA-2026:20589: dnsmasq security update (Important)
CVE-2026-4890 high 7.5 7.5 FIX rheldebian debian sles 19d ago RHSA-2026:20589: dnsmasq security update (Important)
CVE-2026-4519 high 8.0 FIX rocky rheldebian debian 19d ago Important: python3.12 security update
CVE-2026-4224 high 7.5 7.5 FIX rhel slesdebian debian python 19d ago Important: python3.12 security update
CVE-2026-41035 high 7.8 7.8 FIX rhel slesdebian debian samba 19d ago Important: rsync security update
CVE-2026-3644 high 7.5 7.5 FIX rhel slesdebian debian python 19d ago Important: python3.12 security update
CVE-2026-33984 high 8.0 FIX rheldebian debian sles 19d ago Important: freerdp security update
CVE-2026-33983 high 8.0 FIX rheldebian debian sles 19d ago Important: freerdp security update
CVE-2026-33810 high 8.0 FIX rheldebian debian sles 19d ago When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affe…
CVE-2026-32281 high 8.0 FIX rheldebian debian sles google 19d ago Inefficient policy validation in crypto/x509
CVE-2026-31790 high 7.5 7.5 FIX rhel slesdebian debian opensslgoogle 19d ago Moderate: openssl security update
CVE-2026-3085 high 8.0 FIX rheldebian debian rocky 19d ago GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Int…
CVE-2026-3083 high 8.0 FIX rheldebian debian rocky 19d ago GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interactio…
CVE-2026-3082 high 8.0 FIX rheldebian debian rocky 19d ago RHSA-2026:6750: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good security update (Important)
CVE-2026-2923 high 8.0 FIX rheldebian debian rocky 19d ago RHSA-2026:6750: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good security update (Important)
CVE-2026-2922 high 8.0 FIX rheldebian debian rocky 19d ago Important: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update
CVE-2026-2921 high 8.0 FIX rheldebian debian rocky 19d ago RHSA-2026:6750: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good security update (Important)
CVE-2026-2920 high 8.0 FIX rheldebian debian rocky 19d ago RHSA-2026:6750: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good security update (Important)
CVE-2026-28871 high 8.0 FIX rhel slesdebian debian 19d ago A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website …
CVE-2026-28859 high 8.0 FIX rhel slesdebian debian 19d ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A malicious website may …
CVE-2026-28857 high 8.0 FIX rhel slesdebian debian 19d ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may le…
CVE-2026-27137 high 8.0 FIX rheldebian debian sles 19d ago Incorrect enforcement of email constraints in crypto/x509
CVE-2026-24842 high 8.0 FIX rhel slesdebian debian 19d ago Important: linux-sgx security update
CVE-2026-23950 high 8.0 FIX rheldebian debian 19d ago Important: linux-sgx security update
CVE-2026-23745 high 8.0 FIX rhel slesdebian debian 19d ago Important: linux-sgx security update
CVE-2026-23243 high 7.8 7.8 FIX rhel slesdebian debian 19d ago In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_write ib_umad_write computes data_len from user-controlled count and the MAD heade…
CVE-2026-23060 high 8.0 FIX rhel slesdebian debian 19d ago Important: kernel security update
CVE-2026-2297 high 8.0 FIX rhel slesdebian debian 19d ago Important: python3.12 security update
CVE-2026-2291 high 7.3 7.3 FIX rheldebian debian sles 19d ago RHSA-2026:20589: dnsmasq security update (Important)
CVE-2026-20691 high 8.0 FIX rhel slesdebian debian 19d ago An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted…
CVE-2026-20676 high 8.0 FIX rhel slesdebian debian 19d ago This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through…
CVE-2026-20665 high 8.0 FIX rhel slesdebian debian 19d ago This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, wat…
CVE-2026-20664 high 8.0 FIX rhel slesdebian debian 19d ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may le…
CVE-2026-20652 high 8.0 FIX rhel slesdebian debian 19d ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker m…
CVE-2026-20644 high 8.0 FIX rhel slesdebian debian 19d ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciou…
CVE-2026-20643 high 8.0 FIX rhel slesdebian debian 19d ago A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 an…
CVE-2026-20636 high 8.0 FIX rhel slesdebian debian 19d ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may le…
CVE-2026-20635 high 8.0 FIX rhel slesdebian debian 19d ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS …
CVE-2026-20608 high 8.0 FIX rhel slesdebian debian 19d ago This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing mal…
CVE-2026-1502 high 8.0 FIX rhel slesdebian debian 19d ago Important: python3.12 security update
CVE-2026-0966 high 8.2 8.2 FIX rheldebian debian sles libsshredhat 19d ago Moderate: libssh security update
CVE-2026-0672 high 8.0 FIX rhel slesdebian debian 19d ago Important: python3.12 security update
CVE-2025-61726 high 8.0 FIX rocky rheldebian debian google 19d ago Memory exhaustion in query parameter parsing in net/url
CVE-2025-55668 high 8.0 FIX rhel slesdebian debian 19d ago Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Old…
CVE-2025-46701 high 8.0 FIX arch arch rhel sles 19d ago Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to th…
CVE-2025-46299 high 8.0 FIX rhel slesdebian debian 19d ago A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Proc…
CVE-2025-43511 high 8.0 FIX rhel slesdebian debian 19d ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watc…
CVE-2025-43457 high 8.0 FIX rhel slesdebian debian 19d ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing malicious…
CVE-2025-43214 high 8.0 FIX rhel slesdebian debian 19d ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously …
CVE-2025-43213 high 8.0 FIX rhel slesdebian debian 19d ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously …
CVE-2025-39866 high 7.8 7.8 FIX rhel slesdebian debian 19d ago In the Linux kernel, the following vulnerability has been resolved: fs: writeback: fix use-after-free in __mark_inode_dirty() An use-after-free issue occurred when __mark_inode_dirty() get the bdi_…
CVE-2025-15284 high 8.0 FIX rheldebian debian 19d ago Important: linux-sgx security update
CVE-2025-15282 high 8.0 FIX rhel slesdebian debian 19d ago Important: python3.12 security update
CVE-2025-13837 high 8.0 FIX rhel slesdebian debian 19d ago Important: python3.12 security update
CVE-2025-11234 high 7.5 7.5 FIX rocky rhel sles 19d ago A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use…
CVE-2026-30950 high 7.1 7.1 19d ago AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijac…
CVE-2026-8851 high 8.1 8.1 FIX debian debian 19d ago SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database b…
CVE-2026-4137 high 7.8 7.8 lfprojects 19d ago MLFlow Creates a Temporary File With Insecure Permissions
CVE-2026-22810 high 7.3 7.3 joplinappmsiemens 19d ago Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows o…
CVE-2026-46522 high 9.0 EXPFIX debian debian 19d ago ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
CVE-2026-46520 high 8.0 FIX debian debian 19d ago ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions
CVE-2026-45367 high 8.0 19d ago HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CVE-2026-45553 high 7.5 7.5 19d ago NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI …
CVE-2026-45686 high 7.5 7.5 sles opentelemetry 19d ago OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcac…
CVE-2026-45685 high 7.5 7.5 sles opentelemetry 19d ago OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught …
CVE-2026-47092 high 7.8 7.8 jarrodwatts 19d ago Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment vari…
CVE-2026-45245 high 7.4 7.4 steipete 19d ago Summarize's hover summary feature allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links
CVE-2026-45680 high 7.5 7.5 sles opentelemetry 19d ago OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations by looping once pe…
CVE-2026-45242 high 7.1 7.1 steipete 19d ago Summarize contains a path traversal vulnerability
CVE-2026-45495 high 8.8 8.8 windows windows microsoft 19d ago Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-29963 high 7.5 7.5 hsclabs 19d ago HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without …
CVE-2026-29962 high 7.5 7.5 hsclabs 19d ago HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controll…
CVE-2026-45678 high 7.5 7.5 sles opentelemetry 19d ago OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a vali…
CVE-2026-42306 high 8.0 19d ago Docker: Race condition in docker cp allows bind mount redirection to host path
CVE-2026-45727 high 8.0 19d ago CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the user-supplied fingerprint query parameter directly as a filesystem path componen…
CVE-2026-41567 high 7.2 7.2 sles 19d ago Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/arc…
CVE-2026-45707 high 8.1 8.1 n8n-mcp 19d ago n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that th…
CVE-2026-45327 high 8.2 8.2 19d ago TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection. Version 2.5.0 fixes the …
CVE-2026-45829 unknown 19d ago ChromaDB Python project has a pre-authentication code injection vulnerability
CVE-2026-41085 high 8.8 8.8 19d ago Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited access privileges to gain unauthorized administrato…
CVE-2026-45325 high 8.0 19d ago @tmlmobilidade/utils has prototype pollution in its setValueAtPath
CVE-2026-45302 high 8.2 8.2 19d ago parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData field names into nes…
CVE-2026-45300 high 7.4 7.4 debian debian 19d ago The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch pri…
CVE-2026-46385 high 8.0 19d ago iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state ins…
CVE-2026-45270 high 8.0 19d ago CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
CVE-2026-46384 high 8.0 19d ago iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed them to platform-sized int before …
CVE-2026-45149 high 7.5 7.5 debian debian juliangruber 19d ago The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large num…
CVE-2025-57282 high 8.8 8.8 19d ago ngrok is Vulnerable to Command Injection
CVE-2025-56352 high 7.5 7.5 19d ago In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet parsing. When receiving a CONNECT packet with a zero-length C…
CVE-2026-41949 high 7.5 7.5 dify 19d ago Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document acros…
CVE-2026-39079 high 7.5 7.5 19d ago An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upsshipping/logs/, and /modules/upsshipping/lib/UPSBas…
CVE-2026-26462 high 7.3 7.3 19d ago Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation…
CVE-2026-46724 unknown 19d ago TYPO3-EXT-SA-2026-011: Path Traversal in extension "Faceted Search" (ke_search)
CVE-2026-46722 unknown 19d ago TYPO3-EXT-SA-2026-011: XML External Entity Injection in extension "Faceted Search" (ke_search)
CVE-2026-45627 high 8.2 8.2 19d ago Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query param…
CVE-2026-45135 high 8.0 19d ago Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
CVE-2026-46510 high 8.2 8.2 19d ago form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, …
CVE-2026-42009 high 7.5 7.5 FIX debian debian sleswindows windows 19d ago RHSA-2026:20612: gnutls security update (Important)
CVE-2026-7498 high 8.8 8.8 19d ago Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored…
CVE-2026-6347 high 7.6 7.6 mattermost 19d ago Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin