Search

Found 367 results in 178ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-4408 critical 9.0 9.0 FIX slesdebian debian rhel 7d ago Important: samba security update
CVE-2026-8959 critical 9.6 9.6 FIX rheldebian debian sles mozilla 8d ago Important: thunderbird security update
CVE-2026-8956 critical 9.8 9.8 FIX rheldebian debian sles mozilla 8d ago Important: thunderbird security update
CVE-2026-8953 critical 9.6 9.6 FIX rheldebian debian sles mozilla 8d ago Important: thunderbird security update
CVE-2026-8950 critical 9.3 9.3 FIX rheldebian debian sles mozilla 8d ago Important: thunderbird security update
CVE-2026-8401 critical 9.8 9.8 FIX rheldebian debian sles mozilla 8d ago Important: thunderbird security update
CVE-2026-4480 critical 9.0 9.0 FIX slesdebian debian rhel redhatsamba 8d ago Important: samba security update
CVE-2026-8094 critical 9.8 9.8 FIX rheldebian debian sles mozilla 9d ago RHSA-2026:20566: firefox security update (Important)
CVE-2026-2332 critical 9.1 9.1 FIX rheldebian debian sles eclipse 9d ago Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
CVE-2026-31607 critical 9.8 9.8 FIX rhel slesdebian debian 15d ago In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_…
CVE-2026-7321 critical 9.6 9.6 FIX rheldebian debianalmalinux almalinux mozilla 16d ago RHSA-2026:20586: thunderbird security update (Important)
CVE-2025-68121 critical 10.0 10.0 FIX rocky rheldebian debian golanggoogle 16d ago RHSA-2026:22714: osbuild-composer security update (Important)
CVE-2025-55754 critical 9.6 9.6 FIX rhel slesdebian debian apache 16d ago Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Win…
CVE-2026-28780 critical 9.8 9.8 FIX debian debian rhel sles apache 29d ago Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy…
CVE-2026-31402 critical 9.8 9.8 FIX rhel sles rocky 1mo ago In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_…
CVE-2026-4800 critical 9.8 9.8 FIX rheldebian debian rocky lodash 1mo ago Important: pcs security update
CVE-2026-31685 critical 9.4 9.4 FIX sles rheldebian debian 1mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` derives a modified EUI-64 from the Ethernet source…
CVE-2026-4631 critical 10.0 EXPFIX rheldebian debian sles 2mo ago Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit…
CVE-2026-23455 critical 9.1 9.1 FIX sles rheldebian debian 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit leng…
CVE-2026-4698 critical 9.8 9.8 FIX rocky rheldebian debian mozilla 2mo ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-2786 critical 9.8 9.8 FIX rocky rheldebian debian mozilla 3mo ago Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-1709 critical 9.5 FIX rhel sles rocky 4mo ago Critical: keylime security update
CVE-2025-47151 critical 9.5 FIX rocky rheldebian debian 7mo ago RHSA-2025:21628: lasso security update (Critical)
CVE-2025-22871 critical 9.1 9.1 FIX rhel rockydebian debian 10mo ago Moderate: git-lfs security update
CVE-2025-49796 critical 9.1 9.1 FIX arch arch rhel rocky 11mo ago A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input f…
CVE-2025-49794 critical 9.1 9.1 FIX arch arch rhel rocky 11mo ago A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. …
CVE-2024-47685 critical 9.1 9.1 FIX rhel slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put() syzbot reported that nf_reject_ip6_tcphdr_put() was possibly sending ga…
CVE-2024-5535 critical 9.1 9.1 FIX rhel rocky sles 2y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-38612 critical 9.8 9.8 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defin…
CVE-2024-45492 critical 9.8 9.8 FIX rhel rockydebian debian libexpat_project 2y ago RHSA-2024:6989: expat security update (Moderate)
CVE-2024-45491 critical 9.8 9.8 FIX rhel rockydebian debian libexpat_project 2y ago RHSA-2024:8859: xmlrpc-c security update (Moderate)
CVE-2024-37371 critical 9.1 9.1 FIX rhelarch arch rocky mit 2y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-35845 critical 9.1 9.1 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure NUL termination The iwl_fw_ini_debug_info_tlv is used as a string, so we must ensure the string is…
CVE-2024-3596 critical 9.0 9.0 FIX rhel rockydebian debian freeradiusbroadcom 2y ago RHSA-2024:8860: krb5 security update (Important)
CVE-2024-35960 critical 9.1 9.1 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Properly link new fs rules into the tree Previously, add_rule_fg would only add newly created rules from the handle int…
CVE-2024-29944 critical 9.5 FIX rhel rockydebian debian 2y ago An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, …
CVE-2024-2616 critical 9.5 FIX rhel rockydebian debian 2y ago RHSA-2024:1484: firefox security update (Critical)
CVE-2023-46848 critical 9.5 FIX rhel sles rocky 3y ago Critical: squid security update
CVE-2023-46847 critical 9.5 FIX rhel rocky sles 3y ago RHSA-2023:7213: squid:4 security update (Critical)
CVE-2023-46846 critical 9.5 FIX rhel rocky sles 3y ago RHSA-2023:7213: squid:4 security update (Critical)
CVE-2023-38545 critical 9.8 9.8 FIX rhelarch archdebian debian haxxnetapp 3y ago This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it…
CVE-2023-29405 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-29404 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-29403 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-29402 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2022-42722 critical 9.5 FIX arch arch rhel sles 3y ago In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the b…
CVE-2022-42721 critical 9.5 FIX arch arch rhel sles 3y ago A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked lis…
CVE-2022-42720 critical 9.5 FIX arch arch rhel sles 3y ago Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger…
CVE-2022-41674 critical 9.5 FIX arch arch rhel sles 3y ago An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.
CVE-2022-1802 critical 9.5 FIX arch arch rhel sles 4y ago If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged cont…
CVE-2022-1529 critical 9.5 FIX arch arch rhel sles 4y ago An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled Ja…
CVE-2020-1147 critical 10.0 KEVEXP rhel 4y ago Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploi…
CVE-2020-0603 critical 9.5 rhel 4y ago RHSA-2020:0130: .NET Core on Red Hat Enterprise Linux security and bug fix update (Critical)
CVE-2020-0602 critical 9.5 rhel 4y ago RHSA-2020:0130: .NET Core on Red Hat Enterprise Linux security and bug fix update (Critical)
CVE-2019-11707 critical 10.0 KEVEXPFIX arch arch slesdebian debian 4y ago Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
CVE-2012-3503 critical 9.8 9.8 rhel theforeman 4y ago Katello uses hard coded credential
CVE-2017-1000116 critical 9.8 9.8 FIX arch arch slesdebian debian mercurial 4y ago Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
CVE-2017-7550 critical 9.8 9.8 FIX debian debian sles rhel redhat 4y ago A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive infor…
CVE-2019-11043 critical 10.0 KEVEXPFIX arch arch sles rocky 4y ago In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
CVE-2021-44142 critical 9.5 FIX arch arch sles rocky 4y ago RHSA-2022:0332: samba security and bug fix update (Critical)
CVE-2022-23305 critical 9.8 9.8 FIX debian debian sles rocky apachenetappbroadcom 4y ago RHSA-2022:0290: parfait:0.5 security update (Important)
CVE-2020-25717 critical 9.5 FIX arch arch sles rocky 5y ago RHSA-2022:0332: samba security and bug fix update (Critical)
CVE-2021-43527 critical 9.5 FIX arch arch sles rocky 5y ago NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatu…
CVE-2020-6820 critical 10.0 KEVFIX arch arch slesdebian debian 5y ago Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unsp…
CVE-2020-6819 critical 10.0 KEVFIX arch arch slesdebian debian 5y ago Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, caus…
CVE-2019-17026 critical 10.0 KEVEXPFIX arch archdebian debian rhel 5y ago Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.
CVE-2020-27221 critical 9.5 sles rhel 5y ago RHSA-2021:0736: java-1.8.0-ibm security update (Critical)
CVE-2020-16044 critical 9.5 FIX arch arch slesdebian debian 6y ago Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.
CVE-2020-26968 critical 9.5 FIX arch arch slesdebian debian 6y ago Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
CVE-2020-26965 critical 9.5 FIX arch arch slesdebian debian 6y ago Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remember…
CVE-2020-26961 critical 9.5 FIX arch arch slesdebian debian 6y ago When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped…
CVE-2020-26960 critical 9.5 FIX arch arch slesdebian debian 6y ago If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerabili…
CVE-2020-26959 critical 9.5 FIX arch arch slesdebian debian 6y ago During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerabil…
CVE-2020-26958 critical 9.5 FIX arch arch slesdebian debian 6y ago Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerabili…
CVE-2020-26956 critical 9.5 FIX arch arch slesdebian debian 6y ago In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbir…
CVE-2020-26953 critical 9.5 FIX arch arch slesdebian debian 6y ago It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerabilit…
CVE-2020-26951 critical 9.5 FIX arch arch slesdebian debian 6y ago A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privilege…
CVE-2020-16012 critical 9.5 FIX arch archdebian debian sles 6y ago Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2020-26950 critical 10.0 EXPFIX arch arch slesdebian debian 6y ago In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox …
CVE-2020-15999 critical 10.0 KEVFIX arch arch slesdebian debian 6y ago Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded int…
CVE-2020-15969 critical 9.5 FIX arch archdebian debian sles 6y ago Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-15683 critical 9.5 FIX arch arch slesdebian debian 6y ago Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
CVE-2020-14803 critical 9.5 FIX slesdebian debian rhel 6y ago RHSA-2021:0736: java-1.8.0-ibm security update (Critical)
CVE-2020-14782 critical 9.5 FIX slesdebian debian rhel 6y ago RHSA-2021:0736: java-1.8.0-ibm security update (Critical)
CVE-2020-14781 critical 9.5 FIX slesdebian debian rhel 6y ago RHSA-2021:0736: java-1.8.0-ibm security update (Critical)
CVE-2020-12390 critical 9.5 FIX arch archdebian debian rhel 6y ago Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.
CVE-2019-17023 critical 9.5 FIX arch archdebian debian rocky 6y ago After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state,…
CVE-2019-11756 critical 9.5 FIX arch archdebian debian rocky 6y ago Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability affects Firefox < 71.
CVE-2020-12397 critical 9.5 FIX arch archdebian debian rhel 6y ago multiple issues in thunderbird
CVE-2020-6831 critical 9.5 FIX arch archdebian debian sles 6y ago A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR <…
CVE-2020-12395 critical 9.5 FIX arch archdebian debian rhel 6y ago Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
CVE-2020-12392 critical 9.5 FIX arch archdebian debian rhel 6y ago The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and past…
CVE-2020-12387 critical 9.5 FIX arch arch slesdebian debian 6y ago A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Fire…
CVE-2020-2773 critical 9.5 FIX slesdebian debian rhel 6y ago RHSA-2021:0736: java-1.8.0-ibm security update (Critical)
CVE-2020-6825 critical 9.5 FIX arch arch slesdebian debian 6y ago Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corrupti…
CVE-2020-6821 critical 9.5 FIX arch arch slesdebian debian 6y ago When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returned values be zero. Previously, this memor…
CVE-2020-11100 critical 9.5 FIX arch arch slesdebian debian 6y ago arbitrary code execution in haproxy
CVE-2020-6814 critical 9.5 FIX arch arch slesdebian debian 6y ago Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these co…
CVE-2020-6812 critical 9.5 FIX arch arch slesdebian debian 6y ago The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate de…
CVE-2020-6811 critical 9.5 FIX arch arch slesdebian debian 6y ago The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted …