Search
616 CVEs · published 2026-08-13 to 2026-08-13
CVEs (616, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 616 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-68453 | HIGH | 7.1 | 2026-08-13 | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer s… | |
| CVE-2026-68452 | HIGH | 7.8 | 2026-08-13 | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key requests cca_cipher2protkey() derives the copy len… | |
| CVE-2026-68451 | HIGH | 7.8 | 2026-08-13 | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA ECC private key requests cca_ecc2protkey() derives the copy lengt… | |
| CVE-2026-66256 | HIGH | 7.2 | 2026-08-13 | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to t… | |
| CVE-2026-65936 | NONE | — | 2026-08-13 | A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below. | |
| CVE-2026-65935 | NONE | — | 2026-08-13 | Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value. See vulnerability B-E3 in the related paper below. | |
| CVE-2026-65934 | NONE | — | 2026-08-13 | An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module. See vulnerability B-E10 in the related paper below. | |
| CVE-2026-65933 | NONE | — | 2026-08-13 | A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below. | |
| CVE-2026-65932 | NONE | — | 2026-08-13 | The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related … | |
| CVE-2026-63426 | HIGH | 7.1 | 2026-08-13 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary… | |
| CVE-2026-63425 | HIGH | 7.8 | 2026-08-13 | During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to … | |
| CVE-2026-63424 | HIGH | 7.3 | 2026-08-13 | During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges. | |
| CVE-2026-63423 | HIGH | 7.8 | 2026-08-13 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a loc… | |
| CVE-2026-53803 | HIGH | Patched | 7.8 | 2026-08-13 | rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path suc… |
| CVE-2026-53802 | HIGH | Patched | 7.1 | 2026-08-13 | rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following … |
| CVE-2026-53801 | MEDIUM | Patched | 5.9 | 2026-08-13 | rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender to enumerate and trans… |
| CVE-2026-53800 | MEDIUM | Patched | 4.7 | 2026-08-13 | rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows attackers with symlink creation access to cause arbitrar… |
| CVE-2026-53799 | MEDIUM | Patched | 6.3 | 2026-08-13 | rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended f… |
| CVE-2026-53798 | MEDIUM | Patched | 5.3 | 2026-08-13 | rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to b… |
| CVE-2026-53797 | MEDIUM | Patched | 4.7 | 2026-08-13 | rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an attacker who can manipulate a parent directory of th… |
| CVE-2026-53796 | MEDIUM | Patched | 6.3 | 2026-08-13 | rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory handling that allows an … |
| CVE-2026-53795 | HIGH | Patched | 8.1 | 2026-08-13 | rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path … |
| CVE-2026-53794 | MEDIUM | Patched | 5.3 | 2026-08-13 | rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely r… |
| CVE-2026-53793 | HIGH | Patched | 7.4 | 2026-08-13 | rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths th… |
| CVE-2026-53792 | MEDIUM | Patched | 6.5 | 2026-08-13 | rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the… |