Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-48615 nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling MEDIUM 5.9 N/A cvelistv5 2026-08-10
cve-2026-48588 django: Django: Information disclosure due to improper caching of Set-Cookie responses LOW 3.1 N/A cvelistv5 2026-07-10
cve-2026-48112 7-Zip: heap-based buffer over-read in the Ar handler BSD SYMDEF parser MEDIUM 5.5 N/A cvelistv5 2026-06-28
cve-2026-48111 7-Zip: off-by-one out-of-bounds read in the UEFI firmware image parser MEDIUM 6.1 N/A cvelistv5 2026-06-28
cve-2026-48104 7-Zip: uninitialized heap read in the SquashFS archive handler MEDIUM 5.5 N/A cvelistv5 2026-06-28
cve-2026-48103 7-Zip: off-by-one heap-based buffer over-read in the WIM archive handler MEDIUM 6.1 N/A cvelistv5 2026-06-28
cve-2026-48102 7-Zip: 7-Zip: Information disclosure and denial of service via crafted UDF image MEDIUM 5.9 N/A cvelistv5 2026-06-28
cve-2026-48101 7-Zip: 7-Zip: Information Disclosure via uninitialized memory in UEFI capsule parser MEDIUM 6.5 N/A cvelistv5 2026-06-28
cve-2026-48095 SUSE CVE CVE-2026-48095 HIGH 7.8 N/A cvelistv5 2026-07-15
cve-2026-48092 7-Zip: 7-Zip: Information disclosure in 32-bit builds due to heap memory disclosure MEDIUM 6.5 N/A cvelistv5 2026-06-28
cve-2026-4802 cockpit: Cockpit: Arbitrary command execution via crafted links in system logs UI HIGH 8.0 N/A cvelistv5 2026-06-30
cve-2026-4775 libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing HIGH 7.8 N/A cvelistv5 2026-06-30
cve-2026-47240 net-imap: Net::IMAP: Command injection via non-synchronizing literals MEDIUM 6.1 N/A cvelistv5 2026-08-26
cve-2026-47167 SUSE CVE CVE-2026-47167 HIGH 7.8 N/A cvelistv5 2026-08-31
cve-2026-47162 SUSE CVE CVE-2026-47162 HIGH 7.8 N/A cvelistv5 2026-09-18
cve-2026-46595 SUSE CVE CVE-2026-46595 HIGH 8.1 N/A cvelistv5 2026-09-02
cve-2026-46572 SUSE CVE CVE-2026-46572 HIGH 7.1 N/A cvelistv5 2026-09-11
cve-2026-46571 SUSE CVE CVE-2026-46571 MEDIUM 5.5 N/A cvelistv5 2026-09-11
cve-2026-46570 SUSE CVE CVE-2026-46570 HIGH 7.1 N/A cvelistv5 2026-09-11
cve-2026-46569 SUSE CVE CVE-2026-46569 HIGH 7.1 N/A cvelistv5 2026-09-11
cve-2026-46529 SUSE CVE CVE-2026-46529 HIGH 7.0 N/A cvelistv5 2026-07-23
cve-2026-46483 vim: command injection when decompressing .tgz archives HIGH 7.0 N/A cvelistv5 2026-09-03
cve-2026-46333 kernel: Read root-owned files as an unprivileged user HIGH 7.8 N/A cvelistv5 2026-09-01
cve-2026-46331 kernel: net/sched: act_pedit: extend the writable skb range per key MEDIUM 6.7 N/A cvelistv5 2026-09-01
cve-2026-46323 kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs HIGH 7.8 N/A cvelistv5 2026-09-02
cve-2026-46316 kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry HIGH 7.0 N/A cvelistv5 2026-08-31
cve-2026-46300 In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during ... HIGH 7.8 N/A cvelistv5 2026-09-08
cve-2026-46259 SUSE CVE CVE-2026-46259 MEDIUM 5.5 N/A cvelistv5 2026-08-31
cve-2026-46244 SUSE CVE CVE-2026-46244 MEDIUM 5.5 N/A cvelistv5 2026-08-31
cve-2026-46243 kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions HIGH 7.8 N/A cvelistv5 2026-09-01