Search
23,123 CVEs
EOL hidden · Show all products
CVEs (23,123, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 23,123 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-11721 | HIGH | 7.5 | 2026-07-22 | It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `na… | |
| CVE-2026-11622 | HIGH | 7.5 | 2026-07-22 | A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to sen… | |
| CVE-2026-11605 | HIGH | 7.5 | 2026-07-22 | The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly need… | |
| CVE-2026-11331 | HIGH | 7.5 | 2026-07-22 | An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during R… | |
| CVE-2026-10822 | MEDIUM | 6.5 | 2026-07-22 | If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store… | |
| CVE-2026-10723 | MEDIUM | 6.8 | 2026-07-22 | BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.1… | |
| CVE-2026-62145 | HIGH | 7.5 | 2026-07-22 | A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges. | |
| CVE-2026-62144 | CRITICAL | 9.1 | 2026-07-22 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administ… | |
| CVE-2026-56444 | MEDIUM | 5.9 | 2026-07-22 | In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (cont… | |
| CVE-2026-56416 | MEDIUM | 4.8 | 2026-07-22 | In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the add… | |
| CVE-2026-55991 | MEDIUM | 5.9 | 2026-07-22 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate th… | |
| CVE-2026-55990 | MEDIUM | 5.9 | 2026-07-22 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:… | |
| CVE-2026-55973 | HIGH | 7.5 | 2026-07-22 | In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is… | |
| CVE-2026-55717 | MEDIUM | 5.9 | 2026-07-22 | In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <tar… | |
| CVE-2026-55708 | LOW | 3.1 | 2026-07-22 | In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an alr… | |
| CVE-2026-54478 | LOW | 3.7 | 2026-07-22 | In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie Sip… | |
| CVE-2026-53910 | NONE | Patched | — | 2026-07-22 | diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in m… |
| CVE-2026-52863 | MEDIUM | 5.9 | 2026-07-22 | In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect … | |
| CVE-2026-50252 | NONE | — | 2026-07-22 | In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transaction… | |
| CVE-2026-50251 | MEDIUM | 5.3 | 2026-07-22 | In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can s… | |
| CVE-2026-50248 | MEDIUM | 6.5 | 2026-07-22 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a p… | |
| CVE-2026-50243 | NONE | — | 2026-07-22 | In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect… | |
| CVE-2026-50046 | MEDIUM | 5.9 | 2026-07-22 | In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime… | |
| CVE-2026-50045 | MEDIUM | 5.3 | 2026-07-22 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream… | |
| CVE-2026-46582 | LOW | 3.7 | 2026-07-22 | In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the R… |