Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

11,548 CVEs · High severity

CVEs (11,548, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 11,548 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-71220 HIGH 7.0 2026-09-03 A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds ch…
CVE-2026-71221 HIGH 7.0 2026-09-03 A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking…
CVE-2026-78409 HIGH 7.0 2026-09-02 The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag d…
CVE-2026-73725 HIGH Patched 7.0 2026-09-01 A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker…
CVE-2026-84233 HIGH 7.0 2026-09-01 A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncomp…
CVE-2026-13732 HIGH 7.0 2026-08-31 A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates d…
CVE-2026-16821 HIGH Patched 7.0 2026-08-28 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.
CVE-2026-81726 HIGH Patched 7.0 2026-08-27 NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. …
CVE-2026-81714 HIGH Patched 7.0 2026-08-27 openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operato&hellip;
CVE-2026-58093 HIGH 7.0 2026-08-26 The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the t&hellip;
CVE-2026-54467 HIGH Patched 7.0 2026-08-26 On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.
CVE-2026-65082 HIGH Patched 7.0 2026-08-25 NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability m&hellip;
CVE-2026-66153 HIGH 7.0 2026-08-25 The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.
CVE-2026-75037 HIGH 7.0 2026-08-25 Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit d0478&hellip;
CVE-2026-78465 HIGH Patched 7.0 2026-08-24 A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the &hellip;
CVE-2026-78367 HIGH 7.0 2026-08-24 A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-&hellip;
CVE-2026-77584 HIGH Patched 7.0 2026-08-20 Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN bef&hellip;
CVE-2026-63387 HIGH Patched 7.0 2026-08-20 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a nam&hellip;
CVE-2026-18268 HIGH 7.0 2026-08-20 Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected inst&hellip;
CVE-2026-16922 HIGH Patched 7.0 2026-08-20 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) race condition.
CVE-2026-16923 HIGH Patched 7.0 2026-08-20 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
CVE-2026-62727 HIGH 7.0 2026-08-19 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges&hellip;
CVE-2026-16838 HIGH Patched 7.0 2026-08-19 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-us&hellip;
CVE-2026-48711 HIGH Patched 7.0 2026-08-19 SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed mount source such as [-oProxyCommand=CMD]:/path &hellip;
CVE-2026-71098 HIGH 7.0 2026-08-18 Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is&hellip;