Search

Found 10,197 results in 2367ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-5987 medium 5.5 FIX rheldebian debian sles 6mo ago Moderate: libssh security update
CVE-2025-43541 high 8.0 FIX rocky rhel sles 6mo ago A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Process…
CVE-2025-43536 high 8.0 FIX rocky rhel sles 6mo ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciou…
CVE-2025-43535 high 8.0 FIX rocky rhel sles 6mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciou…
CVE-2025-43531 high 8.0 FIX rocky rhel sles 6mo ago A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, wa…
CVE-2025-43529 high 9.5 KEVFIX rocky rhel sles 6mo ago Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could…
CVE-2025-43501 high 8.0 FIX rocky rhel sles 6mo ago A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Proce…
CVE-2025-1735 medium 5.5 FIX rockyalmalinux almalinux rhel 6mo ago RHSA-2026:2470: php:7.4 security update (Moderate)
CVE-2025-14174 high 9.5 KEVFIX rheldebian debian sles 6mo ago Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability co…
CVE-2025-1220 medium 5.5 FIX rocky rhelalmalinux almalinux 6mo ago RHSA-2026:2470: php:7.4 security update (Moderate)
CVE-2025-11083 high 7.8 7.8 FIX rocky rheldebian debian gnu 6mo ago RHSA-2026:2627: gcc-toolset-14-binutils security update (Moderate)
CVE-2024-5642 high 8.0 FIX rocky rhel sles 6mo ago CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-re…
CVE-2025-61985 medium 5.5 FIX rocky rhel sles 6mo ago ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
CVE-2025-61984 medium 5.5 FIX rocky rhel sles 6mo ago ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrus…
CVE-2025-4516 high 8.0 FIX rocky slesdebian debian 6mo ago There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To…
CVE-2025-40176 high 8.0 FIX rhel sles rocky 6mo ago Important: kernel security update
CVE-2025-39966 high 8.0 FIX rhel sles rocky 6mo ago Important: kernel security update
CVE-2025-38499 medium 5.5 5.5 FIX rhel sles rocky 6mo ago Important: kernel security update
CVE-2025-13609 high 8.0 FIX rhel sles rocky 6mo ago Keylime allows users to register new agents by recycling existing UUIDs when using different TPM devices
CVE-2025-14512 medium 6.5 6.5 FIX rheldebian debian sles gnomeredhat 6mo ago A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when pro…
CVE-2025-53069 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53062 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53054 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53053 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53045 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53044 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53042 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53040 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-13499 high 8.0 FIX rhel sles rocky 6mo ago Important: wireshark security update
CVE-2025-14087 medium 5.6 5.6 FIX rheldebian debian sles gnome 6mo ago A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GV…
CVE-2025-55752 high 7.5 7.5 FIX rocky rhel sles apache 6mo ago Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the po…
CVE-2025-31651 high 8.0 FIX rocky rhel sles 6mo ago Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to…
CVE-2025-14333 high 8.0 FIX rocky rheldebian debian 6mo ago Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
CVE-2025-14331 high 8.0 FIX rocky rheldebian debian 6mo ago Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14330 high 8.0 FIX rocky rheldebian debian 6mo ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14329 high 8.0 FIX rocky rheldebian debian 6mo ago Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14328 high 8.0 FIX rocky rheldebian debian 6mo ago Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14325 high 8.0 FIX rocky rheldebian debian 6mo ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14324 high 8.0 FIX rocky rheldebian debian 6mo ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14323 high 8.0 FIX rocky rheldebian debian 6mo ago Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-14322 high 8.0 FIX rocky rheldebian debian 6mo ago Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Th…
CVE-2025-14321 high 8.0 FIX rocky rheldebian debian 6mo ago Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVE-2025-39979 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-39925 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-66287 high 8.0 FIX rocky rhel sles 6mo ago A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.
CVE-2025-43458 high 8.0 FIX rocky rhel sles 6mo ago This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, wat…
CVE-2025-43443 high 8.0 FIX rocky rhel sles 6mo ago This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Pr…
CVE-2025-43441 high 8.0 FIX rhel slesdebian debian 6mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processi…
CVE-2025-43440 high 8.0 FIX rocky rhel sles 6mo ago This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted w…
CVE-2025-43438 high 8.0 FIX rhel slesdebian debian 6mo ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watc…
CVE-2025-43434 high 8.0 FIX rocky rhel sles 6mo ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watc…
CVE-2025-43433 high 8.0 FIX rhel slesdebian debian 6mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS …
CVE-2025-43432 high 8.0 FIX rocky rhel sles 6mo ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processin…
CVE-2025-43431 high 8.0 FIX rocky rhel sles 6mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS …
CVE-2025-43430 high 8.0 FIX rocky rhel sles 6mo ago This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciou…
CVE-2025-43429 high 8.0 FIX rocky rhel sles 6mo ago A buffer overflow was addressed with improved bounds checking. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, …
CVE-2025-43427 high 8.0 FIX rocky rhel sles 6mo ago This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted we…
CVE-2025-43425 high 8.0 FIX rocky rhel sles 6mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously c…
CVE-2025-43421 high 8.0 FIX rocky rhel sles 6mo ago Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Processing maliciously crafted web…
CVE-2025-43392 high 8.0 FIX rocky rhel sles 6mo ago The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watch…
CVE-2025-13947 high 8.0 FIX rocky rhel sles 6mo ago A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechani…
CVE-2025-13502 high 8.0 FIX rocky rhel sles 6mo ago A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspec…
CVE-2025-66471 high 8.0 FIX rocky rhel sles 6mo ago Important: fence-agents security update
CVE-2025-65637 high 8.0 FIX rockydebian debian rhel 6mo ago RHSA-2026:3428: container-tools:rhel8 security update (Important)
CVE-2025-12744 high 9.0 EXP rhel 6mo ago RHSA-2025:22760: abrt security update (Important)
CVE-2025-4598 medium 4.7 4.7 FIX arch arch rhel sles systemd_projectredhat 6mo ago Moderate: systemd security update
CVE-2025-9714 medium 5.5 5.5 FIX rheldebian debian sles xmlsoft 6mo ago Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPat…
CVE-2025-40186 medium 5.5 FIX slesdebian debian rhel 6mo ago In the Linux kernel, the following vulnerability has been resolved: tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). syzbot reported the splat below in tcp_conn_request(). [0] If a l…
CVE-2025-40185 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-40058 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-39981 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-39955 medium 5.5 FIX rocky rhel sles 6mo ago Moderate: kernel security update
CVE-2025-39918 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-39898 medium 5.5 FIX rocky rhel sles 6mo ago Moderate: kernel security update
CVE-2025-39864 high 7.8 7.8 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-38724 high 7.8 7.8 FIX rocky rhel sles 6mo ago Moderate: kernel security update
CVE-2025-59375 high 7.5 7.5 FIX rocky rheldebian debian libexpat_project 6mo ago Important: python3.12 security update
CVE-2025-39843 medium 5.5 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-10934 high 8.0 FIX rocky rheldebian debian 6mo ago RHSA-2025:22417: gimp:2.8 security update (Important)
CVE-2025-10925 high 8.0 FIX rocky rheldebian debian 6mo ago RHSA-2025:22417: gimp:2.8 security update (Important)
CVE-2025-10924 high 8.0 FIX rocky rheldebian debian 6mo ago RHSA-2025:22417: gimp:2.8 security update (Important)
CVE-2025-10923 high 8.0 FIX rocky rheldebian debian 6mo ago RHSA-2025:22417: gimp:2.8 security update (Important)
CVE-2025-10922 high 8.0 FIX rocky rheldebian debian 6mo ago RHSA-2025:22417: gimp:2.8 security update (Important)
CVE-2025-10921 high 8.0 FIX rocky rheldebian debian 6mo ago RHSA-2025:22417: gimp:2.8 security update (Important)
CVE-2025-10920 high 8.0 FIX rocky rheldebian debian 6mo ago RHSA-2025:22417: gimp:2.8 security update (Important)
CVE-2025-58183 medium 5.5 FIX rocky rheldebian debian 7mo ago Moderate: image-builder security update
CVE-2025-11230 high 8.0 FIX rheldebian debian sles 7mo ago Important: haproxy security update
CVE-2025-40047 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: always prune wait queue entry in io_waitid_wait() For a successful return, always remove our entry from the wait…
CVE-2025-39983 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix UAF in hci_conn_tx_dequeue This fixes the following UAF caused by not properly locking hdev when proces…
CVE-2025-39982 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync This fixes the following UFA in hci_acl_create_conn_sync where a connec…
CVE-2025-39973 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: i40e: add validation for ring_len param The `ring_len` parameter provided by the virtual function (VF) is assigned directly to th…
CVE-2025-39971 medium 5.5 FIX rocky rhel sles 7mo ago In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in config queues msg Ensure idx is within range of active/initialized TCs when iterating over vf->ch[idx…
CVE-2025-39881 medium 5.5 FIX rhel slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: kernfs: Fix UAF in polling when open file is released A use-after-free (UAF) vulnerability was identified in the PSI (Pressure St…
CVE-2025-39697 medium 4.7 4.7 FIX rocky rhel sles 7mo ago In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a race when updating an existing write After nfs_lock_and_join_requests() tests for whether the request is still attache…
CVE-2025-9230 high 7.5 7.5 FIX rocky rhel sles 7mo ago Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigge…
CVE-2025-13020 high 8.0 FIX rocky rheldebian debian 7mo ago Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
CVE-2025-13019 high 8.0 FIX rocky rheldebian debian 7mo ago Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
CVE-2025-13018 high 8.0 FIX rocky rheldebian debian 7mo ago Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
CVE-2025-13017 high 8.0 FIX rocky rheldebian debian 7mo ago Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
CVE-2025-13016 high 8.0 FIX rocky rheldebian debian 7mo ago Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.