Search

Found 26,281 results in 3372ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-49942 high 7.3 7.3 FIX debian debian 1d ago Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could contain Unicode digits such as the Arabic-Indic One (U+0661), or non-digits, wh…
CVE-2026-49941 high 7.5 7.5 FIX debian debian 1d ago Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network range…
CVE-2026-49940 medium 6.5 6.5 FIX debian debian 1d ago Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Arabic-Indic One (U+0661) were accepted but not properly parsed as numbers. This…
CVE-2026-46739 medium 5.3 5.3 debian debian 1d ago Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional st…
CVE-2026-44393 high 7.4 7.4 debian debian 2d ago An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl…
CVE-2026-40930 medium 5.4 5.4 FIX debian debian 2d ago LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG pa…
CVE-2026-8916 medium 6.1 6.1 debian debian 2d ago Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd760aec00ada6a148635.
CVE-2026-49510 medium 6.1 6.1 debian debian 2d ago Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.
CVE-2026-47320 medium 6.1 6.1 debian debian 2d ago Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: befo…
CVE-2026-47319 medium 6.1 6.1 debian debian 2d ago Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.
CVE-2026-47318 medium 6.1 6.1 debian debian 2d ago Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035.
CVE-2026-47306 medium 6.1 6.1 debian debian 2d ago Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.
CVE-2026-50219 medium 5.9 5.9 debian debian sles libexpat_project 2d ago libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation.…
CVE-2026-48681 high 8.1 8.1 debian debian openstack 2d ago OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
CVE-2026-44917 medium 4.9 4.9 debian debian openstack 2d ago OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
CVE-2026-41283 critical 9.9 9.9 debian debian 2d ago OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
CVE-2026-8829 high 7.5 7.5 FIX slesdebian debian 2d ago HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV retu…
CVE-2026-35240 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-35239 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-35238 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-35237 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-35236 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-34308 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-34304 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-34303 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-34293 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-34278 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-34276 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-34271 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-34270 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-34267 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-22017 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-22015 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-22009 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-22005 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-22004 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-22002 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-22001 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-21998 medium 5.5 FIX debian debian rhelalmalinux almalinux 2d ago Moderate: mysql security update
CVE-2026-46447 high 7.7 7.7 debian debian openstack 2d ago OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
CVE-2026-40898 high 7.5 7.5 debian debian quic-go_project 2d ago quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a …
CVE-2026-26825 medium 5.3 5.3 debian debian libxls_project 2d ago A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory origi…
CVE-2026-26824 medium 6.5 6.5 slesdebian debian libxls_project 2d ago libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not ful…
CVE-2026-45702 medium 5.5 5.5 debian debian 2d ago OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.3.0 and prior t…
CVE-2026-45614 medium 4.7 4.7 debian debian 2d ago OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Prior to version 4.11.0, on many of t…
CVE-2026-40290 high 7.8 7.8 debian debian 3d ago OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.16.0 and prior …
CVE-2026-46273 high 8.6 8.6 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power systems do not support segmentation offload when …
CVE-2026-6657 medium 6.1 6.1 debian debian 3d ago A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use o…
CVE-2026-37462 high 7.5 7.5 FIX debian debian 3d ago An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
CVE-2026-46271 high 7.8 7.8 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link In case of multi-link connection, WCN7850 firmware crashes due to WoW offloads…
CVE-2026-46270 high 8.4 8.4 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_supply_changed() Using the `devm_` variant for requesting IRQ _before_ the `de…
CVE-2026-46266 critical 9.1 9.1 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reported that simply having one RAW socket on protocol IP…
CVE-2026-46265 high 7.5 7.5 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix WQ_MEM_RECLAIM warning When sunrpc is used, if a reset triggered, our wq may lead the following trace: workqueue: …
CVE-2026-46264 high 8.8 8.8 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of devm_add_action_or_reset() failure the provided cleanup action will be run immedia…
CVE-2026-46263 high 7.8 7.8 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds stream encoder index v3 eng_id can be negative and that stream_enc_regs[] can be indexed out o…
CVE-2026-46260 high 7.8 7.8 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bound access in fib6_add_rt2node(). syzbot reported out-of-bound read in fib6_add_rt2node(). [0] When IPv6 rout…
CVE-2026-46259 high 7.8 7.8 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: procfs: fix missing RCU protection when reading real_parent in do_task_stat() When reading /proc/[pid]/stat, do_task_stat() acces…
CVE-2026-46253 high 7.8 7.8 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: pstore/ram: fix buffer overflow in persistent_ram_save_old() persistent_ram_save_old() can be called multiple times for the same …
CVE-2026-46251 high 8.4 8.4 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block_group_tree dirty_list corruption When the incompat flag EXTENT_TREE_V2 is set, we unconditionally add the block …
CVE-2026-46250 high 7.3 7.3 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: MIPS: Work around LLVM bug when gp is used as global register variable On MIPS, __current_thread_info is defined as global regist…
CVE-2026-46244 critical 9.1 9.1 FIX debian debian sles 3d ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() …
CVE-2026-8404 medium 5.3 5.3 FIX debian debian sles djangoproject 3d ago An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitive…
CVE-2026-7666 low 3.1 3.1 FIX debian debian sles djangoproject 3d ago An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a …
CVE-2026-6873 medium 4.3 4.3 FIX debian debian sles djangoproject 3d ago An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and…
CVE-2026-48587 medium 5.3 5.3 FIX debian debian sles djangoproject 3d ago An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header va…
CVE-2026-44546 low 3.7 3.7 debian debian 3d ago daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twisted does not treat \x0b, \x0c, \x1c, \x1d, \x1e, or …
CVE-2026-44545 medium 5.3 5.3 debian debian 3d ago daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote a…
CVE-2026-37460 high 7.5 7.5 FIX slesdebian debian 3d ago Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UP…
CVE-2026-35193 low 3.1 3.1 FIX debian debian sles djangoproject 3d ago An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requ…
CVE-2026-47065 critical 9.8 9.8 debian debian 3d ago ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the ma…
CVE-2026-50031 high 7.5 7.5 debian debian sleswindows windows 3d ago ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform m…
CVE-2026-9516 high 7.5 7.5 FIX debian debian sles rurban 3d ago Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances t…
CVE-2026-9334 high 7.3 7.3 FIX debian debian sles rurban 3d ago Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference…
CVE-2026-35177 medium 5.5 FIX slesdebian debian rhel 3d ago Moderate: vim security update
CVE-2026-10650 medium 5.3 5.3 debian debian 3d ago A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Hand…
CVE-2026-42507 medium 5.3 5.3 FIX debian debian sles 3d ago When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or log…
CVE-2026-42504 high 7.5 7.5 FIX debian debian sles 3d ago Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
CVE-2026-27145 medium 6.5 6.5 FIX debian debian sles 3d ago (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the sa…
CVE-2026-48682 medium 5.9 5.9 debian debian 3d ago FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4…
CVE-2026-47265 high 7.5 7.5 FIX debian debian sles aiohttp 3d ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin r…
CVE-2026-34993 high 7.3 7.3 FIX debian debian sles aiohttp 3d ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most appli…
CVE-2026-10702 medium 4.3 4.3 FIX debian debian mozilla 3d ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
CVE-2026-10701 high 7.5 7.5 FIX debian debian mozilla 3d ago Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3.
CVE-2026-49943 medium 6.3 6.3 debian debian 3d ago CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. The as_path_match() function uses a fixed-s…
CVE-2026-38978 medium 5.3 5.3 FIX debian debian 4d ago transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.
CVE-2026-5422 high 8.1 8.1 debian debian jupyter 4d ago A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.…
CVE-2026-10528 low 3.3 3.3 debian debian 4d ago A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the function DcmItem::read of the file OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp of the c…
CVE-2026-10298 low 3.3 3.3 debian debian 4d ago A security flaw has been discovered in ggml-org whisper.cpp up to 1.8.2. This vulnerability affects the function whisper_model_load of the file ggml/src/ggml.c. The manipulation results in null point…
CVE-2026-10294 medium 4.3 4.3 slesdebian debian 4d ago A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket…
CVE-2026-5419 low 3.7 3.7 FIX debian debian sles rhel 4d ago A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive informat…
CVE-2026-45729 medium 4.3 4.3 FIX debian debian 4d ago Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes untrusted SVG data to …
CVE-2026-43958 high 7.8 7.8 slesdebian debian 4d ago A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulner…
CVE-2026-8643 medium 5.5 5.5 FIX debian debian sleswindows windows pypa 4d ago pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed out…
CVE-2026-46243 high 7.1 7.1 FIX debian debian slesalmalinux almalinux 4d ago Important: kernel-rt security update
CVE-2026-10275 medium 5.0 5.0 slesdebian debian 4d ago A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation …
CVE-2026-10118 high 7.8 7.8 FIX debian debian 4d ago A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatte…
CVE-2025-60495 medium 5.5 5.5 debian debian 5d ago A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a …
CVE-2025-60486 medium 5.5 5.5 debian debian 5d ago A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file.
CVE-2025-60485 medium 5.5 5.5 debian debian 5d ago A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a cr…
CVE-2025-60483 medium 5.5 5.5 debian debian 5d ago A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) …