Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

616 CVEs · published 2026-08-13 to 2026-08-13

CVEs (616, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 301–325 of 616 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-19487 MEDIUM Patched 5.3 2026-08-13 Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. …
CVE-2026-73558 MEDIUM Patched 5.3 2026-08-13 vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul…
CVE-2026-73557 NONE Patched — 2026-08-13 vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses torch.sparse.c…
CVE-2026-73556 MEDIUM Patched 5.3 2026-08-13 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_en…
CVE-2026-73555 MEDIUM Patched 5.3 2026-08-13 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts Fas…
CVE-2026-73509 HIGH Patched 7.6 2026-08-13 OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the…
CVE-2026-73508 MEDIUM Patched 5.3 2026-08-13 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handle…
CVE-2026-73507 HIGH Patched 7.5 2026-08-13 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to…
CVE-2026-73506 MEDIUM Patched 6.1 2026-08-13 Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-control…
CVE-2026-73505 HIGH Patched 7.8 2026-08-13 Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, …
CVE-2026-70464 HIGH Patched 7.5 2026-08-13 rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the h…
CVE-2026-70463 HIGH Patched 8.1 2026-08-13 rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, …
CVE-2026-70462 MEDIUM Patched 6.5 2026-08-13 rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts…
CVE-2026-70461 HIGH Patched 8.2 2026-08-13 rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end o…
CVE-2026-70460 HIGH Patched 8.1 2026-08-13 rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree…
CVE-2026-70459 MEDIUM Patched 5.3 2026-08-13 rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file li…
CVE-2026-70458 HIGH Patched 8.2 2026-08-13 rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the …
CVE-2026-70457 MEDIUM Patched 6.5 2026-08-13 rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a .bss-segment array wit…
CVE-2026-70456 HIGH Patched 8.2 2026-08-13 rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending…
CVE-2026-70455 HIGH Patched 7.5 2026-08-13 rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compres…
CVE-2026-70454 HIGH 8.0 2026-08-13 rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to inte…
CVE-2026-70453 HIGH Patched 7.5 2026-08-13 rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a…
CVE-2026-70452 HIGH Patched 7.4 2026-08-13 rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures dur…
CVE-2026-6387 HIGH 7.0 2026-08-13 A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.
CVE-2026-68454 HIGH 8.8 2026-08-13 In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a …