Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-9545 In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second tra... HIGH 7.5 0.41% cvelistv5 2026-09-15
cve-2026-9539 SUSE CVE CVE-2026-9539 MEDIUM 6.5 0.22% cvelistv5 2026-07-28
cve-2026-9256 SUSE CVE CVE-2026-9256 HIGH 8.1 2.70% cvelistv5 2026-08-26
cve-2026-9080 libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback HIGH 7.3 0.49% cvelistv5 2026-09-01
cve-2026-9079 libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials HIGH 7.5 0.58% cvelistv5 2026-08-31
cve-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) HIGH 7.5 1.08% cvelistv5 2026-08-21
cve-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fa... CRITICAL 9.1 0.50% cvelistv5 2026-09-15
cve-2026-8924 A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public ... CRITICAL 9.1 0.66% cvelistv5 2026-09-15
cve-2026-8631 SUSE CVE CVE-2026-8631 CRITICAL 9.8 1.14% cvelistv5 2026-07-31
cve-2026-8458 libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even wh... MEDIUM 6.5 0.37% cvelistv5 2026-09-15
cve-2026-8357 libreoffice: LibreOffice Calc: Arbitrary code execution via heap buffer overflow in formula compilation HIGH 7.8 0.23% cvelistv5 2026-07-28
cve-2026-8286 curl: curl: Insecure connection establishment due to TLS configuration mismatch HIGH 8.1 0.52% cvelistv5 2026-09-02
cve-2026-8177 XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing tr... HIGH 7.5 0.88% cvelistv5 2026-09-18
cve-2026-7568 php: signed integer overflow in metaphone() HIGH 7.5 0.84% cvelistv5 2026-07-01
cve-2026-7511 PKCS7_verify signer confusion allows forged signatures to be accepted MEDIUM 5.9 0.26% cvelistv5 2026-06-26
cve-2026-7263 SUSE CVE CVE-2026-7263 HIGH 7.5 0.63% cvelistv5 2026-07-15
cve-2026-7262 SUSE CVE CVE-2026-7262 MEDIUM 5.3 1.05% cvelistv5 2026-07-15
cve-2026-7258 PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions MEDIUM 5.9 0.40% cvelistv5 2026-07-01
cve-2026-6735 SUSE CVE CVE-2026-6735 MEDIUM 6.3 0.31% cvelistv5 2026-07-07
cve-2026-6734 SUSE CVE CVE-2026-6734 HIGH 8.8 0.39% cvelistv5 2026-08-30
cve-2026-6733 undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. LOW 3.7 0.27% cvelistv5 2026-08-19
cve-2026-6731 X.509 name constraint bypass via Subject CN treated as a DNS name MEDIUM 6.0 0.20% cvelistv5 2026-06-26
cve-2026-6681 PKCS#7 decode ignores caller output buffer size, writing past buffer bounds LOW 1.0 0.38% cvelistv5 2026-06-26
cve-2026-6678 Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info LOW 1.0 0.33% cvelistv5 2026-07-01
cve-2026-6478 SUSE CVE CVE-2026-6478 MEDIUM 6.5 0.56% cvelistv5 2026-09-11
cve-2026-6477 postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory HIGH 8.4 0.45% cvelistv5 2026-08-25
cve-2026-6475 SUSE CVE CVE-2026-6475 HIGH 8.8 0.32% cvelistv5 2026-09-11
cve-2026-6473 SUSE CVE CVE-2026-6473 HIGH 8.8 1.01% cvelistv5 2026-09-11
cve-2026-6450 CRL critical extension bypass in ParseCRL_Extensions LOW 1.0 0.33% cvelistv5 2026-06-26
cve-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinal LOW 2.1 0.19% cvelistv5 2026-06-26