Search

Found 25,799 results in 3006ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-50292 high 7.4 7.4 FIX debian debian 10h ago In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
CVE-2026-50266 low 2.2 2.2 FIX debian debian 11h ago In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("n…
CVE-2026-49942 high 7.3 7.3 FIX debian debian 11h ago Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could contain Unicode digits such as the Arabic-Indic One (U+0661), or non-digits, wh…
CVE-2026-49941 high 7.5 7.5 FIX debian debian 11h ago Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network range…
CVE-2026-49940 medium 6.5 6.5 FIX debian debian 11h ago Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Arabic-Indic One (U+0661) were accepted but not properly parsed as numbers. This…
CVE-2026-46739 medium 5.3 5.3 debian debian 11h ago Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional st…
CVE-2026-44393 high 7.4 7.4 debian debian 12h ago An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl…
CVE-2026-40930 medium 5.4 5.4 FIX debian debian 12h ago LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG pa…
CVE-2026-8916 medium 6.1 6.1 debian debian 18h ago Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd760aec00ada6a148635.
CVE-2026-49510 medium 6.1 6.1 debian debian 18h ago Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.
CVE-2026-47320 medium 6.1 6.1 debian debian 18h ago Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: befo…
CVE-2026-47319 medium 6.1 6.1 debian debian 18h ago Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.
CVE-2026-47318 medium 6.1 6.1 debian debian 18h ago Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035.
CVE-2026-47306 medium 6.1 6.1 debian debian 18h ago Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.
CVE-2026-50219 medium 5.9 5.9 debian debian sles libexpat_project 1d ago libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation.…
CVE-2026-48681 high 8.1 8.1 debian debian openstack 1d ago OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
CVE-2026-44917 medium 4.9 4.9 debian debian openstack 1d ago OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
CVE-2026-41283 critical 9.9 9.9 debian debian 1d ago OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
CVE-2026-8829 high 7.5 7.5 FIX slesdebian debian 1d ago HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV retu…
CVE-2026-35240 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-35239 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-35238 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-35237 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-35236 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34308 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34304 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34303 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34293 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34278 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34276 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34271 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34270 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34267 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-22017 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-22015 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-22009 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-22005 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-22004 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-22002 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-22001 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-21998 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-46447 high 7.7 7.7 debian debian openstack 1d ago OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
CVE-2026-45702 medium 4.4 4.4 debian debian 1d ago OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.3.0 and prior t…
CVE-2026-45614 medium 4.7 4.7 debian debian 1d ago OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Prior to version 4.11.0, on many of t…
CVE-2026-40290 high 7.8 7.8 debian debian 2d ago OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.16.0 and prior …
CVE-2026-6657 medium 6.1 6.1 debian debian 2d ago A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use o…
CVE-2026-8404 low 3.1 3.1 FIX debian debian sles 2d ago An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitive…
CVE-2026-7666 low 3.1 3.1 FIX debian debian sles 2d ago An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a …
CVE-2026-6873 low 3.1 3.1 FIX debian debian sles 2d ago An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and…
CVE-2026-48587 low 3.1 3.1 FIX debian debian sles 2d ago An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header va…
CVE-2026-44546 low 3.7 3.7 debian debian 2d ago daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twisted does not treat \x0b, \x0c, \x1c, \x1d, \x1e, or …
CVE-2026-44545 medium 5.3 5.3 debian debian 2d ago daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote a…
CVE-2026-35193 low 3.1 3.1 FIX debian debian sles 2d ago An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requ…
CVE-2026-50031 high 7.5 7.5 debian debian sleswindows windows 2d ago ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform m…
CVE-2026-9516 high 7.5 7.5 FIX debian debian sles 2d ago Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances t…
CVE-2026-9334 high 7.3 7.3 FIX debian debian sles 2d ago Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference…
CVE-2026-35177 medium 5.5 FIX slesdebian debian rhel 2d ago Moderate: vim security update
CVE-2026-10650 medium 5.3 5.3 debian debian 2d ago A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Hand…
CVE-2026-42507 medium 5.3 5.3 FIX debian debian sles 2d ago When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or log…
CVE-2026-42504 high 7.5 7.5 FIX debian debian sles 2d ago Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
CVE-2026-27145 medium 6.5 6.5 FIX debian debian sles 2d ago (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the sa…
CVE-2026-48682 medium 5.9 5.9 debian debian 2d ago FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4…
CVE-2026-34993 medium 6.4 6.4 FIX debian debian sles 2d ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most appli…
CVE-2026-10702 medium 4.3 4.3 FIX debian debian mozilla 2d ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
CVE-2026-10701 high 7.5 7.5 FIX debian debian mozilla 2d ago Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3.
CVE-2026-49943 medium 6.3 6.3 debian debian 2d ago CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. The as_path_match() function uses a fixed-s…
CVE-2026-5422 high 8.1 8.1 debian debian jupyter 3d ago A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.…
CVE-2026-10528 low 3.3 3.3 debian debian 3d ago A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the function DcmItem::read of the file OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp of the c…
CVE-2026-10298 low 3.3 3.3 debian debian 3d ago A security flaw has been discovered in ggml-org whisper.cpp up to 1.8.2. This vulnerability affects the function whisper_model_load of the file ggml/src/ggml.c. The manipulation results in null point…
CVE-2026-10294 medium 4.3 4.3 slesdebian debian 3d ago A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket…
CVE-2026-5419 low 3.7 3.7 FIX debian debian sles rhel 3d ago A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive informat…
CVE-2026-45729 medium 4.3 4.3 FIX debian debian 3d ago Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes untrusted SVG data to …
CVE-2026-43958 high 7.8 7.8 slesdebian debian 3d ago A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulner…
CVE-2026-8643 medium 5.5 5.5 FIX debian debian sleswindows windows pypa 3d ago pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed out…
CVE-2026-46243 high 7.8 7.8 FIX debian debian slesalmalinux almalinux 3d ago RHSA-2026:23259: kernel-rt security update (Important)
CVE-2026-10275 medium 5.0 5.0 slesdebian debian 3d ago A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation …
CVE-2026-10118 high 7.8 7.8 FIX debian debian 3d ago A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatte…
CVE-2025-60495 medium 5.5 5.5 debian debian 4d ago A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a …
CVE-2025-60486 medium 5.5 5.5 debian debian 4d ago A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file.
CVE-2025-60485 medium 5.5 5.5 debian debian 4d ago A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a cr…
CVE-2025-60483 medium 5.5 5.5 debian debian 4d ago A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) …
CVE-2025-60481 medium 5.5 5.5 debian debian 4d ago A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted…
CVE-2025-55664 medium 5.5 5.5 debian debian 4d ago A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
CVE-2026-49270 medium 5.9 5.9 debian debian apache 4d ago Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurabl…
CVE-2026-49157 high 8.8 8.8 debian debian apache 4d ago Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-ad…
CVE-2026-48827 high 7.1 7.1 debian debian sles apache 4d ago Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to …
CVE-2026-46605 medium 4.3 4.3 debian debian apache 4d ago Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apa…
CVE-2026-45505 high 8.8 8.8 debian debian apache 4d ago Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrapp…
CVE-2026-44825 high 8.1 8.1 FIX debian debian apache 4d ago Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access…
CVE-2026-42588 high 8.1 8.1 debian debian apache 4d ago Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes th…
CVE-2026-42253 medium 6.1 6.1 debian debian apache 4d ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API copies …
CVE-2026-35563 high 8.5 8.5 debian debian apache 4d ago It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname. While the underlying code validates the certifica…
CVE-2026-10233 low 3.3 3.3 slesdebian debian 4d ago A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::read_sequence_infos of the file HL1MDLLoader.cpp of the component Half-Life 1 MD…
CVE-2026-10232 medium 5.3 5.3 slesdebian debian 4d ago A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation c…
CVE-2026-10231 medium 5.3 5.3 slesdebian debian 4d ago A security flaw has been discovered in Assimp up to 6.0.4. Affected is the function HL1MDLLoader::extract_anim_value of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Performing a…
CVE-2026-10230 medium 5.3 5.3 slesdebian debian 4d ago A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Load…
CVE-2026-10229 medium 5.3 5.3 slesdebian debian 4d ago A vulnerability was determined in Assimp up to 6.0.4. This affects the function HL1MDLLoader::read_meshes of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. This manipulation cause…
CVE-2026-10201 low 3.3 3.3 slesdebian debian 4d ago A vulnerability was determined in Assimp up to 6.0.4. This vulnerability affects the function FBXExporter::WriteObjects of the file FBXExporter.cpp of the component UV Channel Handler. Executing a ma…
CVE-2025-53020 medium 5.5 FIX debian debian sles rhel 4d ago Moderate: mod_http2 security update
CVE-2026-10200 medium 5.3 5.3 slesdebian debian 4d ago A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in h…