Recent Vulnerabilities

Sources: amazon_linux archlinux azure_linux bitnami_vulndb capec capec_enrichment_dashboard certeu certfr circl_kev cisa_known_exploited cna_scorecard cnvd csaf_abb csaf_adstecindustrialitgmbh csaf_amd csaf_aumariestergmbhcokg csaf_baadem2mproductsgmbh csaf_beckhoffautomationgmbhcokg csaf_bendergmbhcokg csaf_bosch csaf_bsi csaf_bsi_aggregator csaf_bsi_cvd_white csaf_bsi_white csaf_bsi_wid_white csaf_carlogavazziautomation csaf_certbund csaf_certvde csaf_cisa csaf_cisa_it csaf_cisa_ot csaf_cisco csaf_claaskgaa csaf_codesysgmbh csaf_dell csaf_duraggmbh csaf_endresshauserag csaf_ericsson csaf_euchnergmbhcokg csaf_festosecokg csaf_frauschersensortechnikgmbh csaf_hancom csaf_harmaninternational csaf_helmholzgmbhcokg csaf_himapaulhildebrandtgmbh csaf_hitachi csaf_hpe csaf_huawei csaf_hydacinternationalgmbh csaf_ibm csaf_ifmelectronicgmbh csaf_janitzaelectronicsgmbh csaf_jumogmbhcokg csaf_juniper csaf_kebautomationkg csaf_kukaag csaf_lenovo csaf_lenzese csaf_mbconnectlinegmbh csaf_mettlertoledogmbh csaf_metzconnectgmbh csaf_microsoft csaf_mieleciekg csaf_moxa csaf_murrelektronikgmbh csaf_ncscnl csaf_ndaal csaf_netapp csaf_nozomi csaf_nozominetworks csaf_nvidia csaf_opcfoundation csaf_openeuler csaf_opensuse csaf_oracle csaf_ox csaf_paloalto csaf_panasonic csaf_pentagrid csaf_pepperlfuchsse csaf_phoenix csaf_pilzgmbhcokg csaf_qnap csaf_redhat csaf_samsung csaf_sauterag csaf_schneider csaf_sick csaf_siemens csaf_smasolartechnologyag csaf_suse csaf_swarcotrafficsystemsgmbh csaf_synology csaf_tibco csaf_trend csaf_trumpfsecokg csaf_trustsource csaf_tuxcare csaf_ubiquiti csaf_vartastoragegmbh csaf_vegagrieshaberkg csaf_vmware csaf_wagogmbhcokg csaf_weidmuellerinterfacegmbhcokg csaf_welotecgmbh csaf_wiesemanntheisgmbh csaf_yaskawaeuropegmbh csaf_yokogawa csaf_zyxel cve_forecast cve_icu cve_vs_github_dashboard cvelistv5 cwe_dashboard cwe_enrichment cwec debian_security_tracker drupal emb3d emb3d_dashboard epss_dashboard epss_history epss_kev_enrichment euvd_kev fedora fkie_nvd freebsd gcve gcve_enriched gcve_enrichment gcve_enrichment_dashboard gentoo github gsd jvn kev_ransomware mitre_attack moksha ndaal_kev netbsd nuclei_dashboard nuclei_enrichment nvd nvd_cpe_dictionary openbsd opencve oracle_linux ossf_malicious_packages osv_almalinux osv_alpine osv_bellsoft osv_chainguard osv_cran osv_github_actions osv_golang osv_haskell osv_hex osv_maven osv_npm osv_nuget osv_ocaml osv_ossfuzz osv_packagist osv_pub osv_rocky osv_rubygems osv_rustsec osv_swift osv_ubuntu osv_wolfi publish_stats pysec sadp_pilot ssvc ssvc_dashboard tailscale tsunami_enrichment variot vulnrichment Clear
ID Title Severity CVSS Source Updated
70797 Red Hat Security Advisory: kernel security update HIGH 7.5 csaf_redhat 2026-09-23
70803 Red Hat Security Advisory: gstreamer1-plugins-good security update HIGH 7.5 csaf_redhat 2026-09-23
70584 Red Hat Security Advisory: gstreamer1-plugins-good security update HIGH 7.5 csaf_redhat 2026-09-23
70264 Red Hat Security Advisory: gstreamer1-plugins-good security update HIGH 7.5 csaf_redhat 2026-09-23
cve-2026-96611 ffmpeg: FFmpeg: Data corruption and information disclosure via signed integer overflow in HEIF processing MEDIUM 6.5 cvelistv5 2026-09-23
cve-2026-96276 flatpak: flatpak: Arbitrary write in host context via flatpak build-init UNKNOWN cvelistv5 2026-09-23
cve-2026-93751 uri-js: uri-js: Improper UTF-8 decoding allows path traversal and CRLF injection MEDIUM 6.5 cvelistv5 2026-09-23
cve-2026-96577 oc-mirror__release-4.21: Embedded local cache registry listens on all interfaces without authentication, with delete enabled HIGH 7.1 cvelistv5 2026-09-23
cve-2026-96275 flatpak: flatpak: Arbitrary write access as root via extra-data extraction HIGH 8.8 cvelistv5 2026-09-23
cve-2026-93690 uri-js: uri-js: Denial of Service via malformed path segments HIGH 7.5 cvelistv5 2026-09-23
cve-2026-93600 rustls-webpki: rustls-webpki: URI Name Constraint Bypass via X.509 Certificate Misissue LOW 2.2 cvelistv5 2026-09-23
cve-2026-91182 open-cluster-management: Open-Cluster-Management: Privilege escalation and unauthorized resource modification in gRPC broker LOW 3.3 cvelistv5 2026-09-23
cve-2026-77301 adm-zip: adm-zip: Denial of Service via uncontrolled memory allocation MEDIUM 6.5 cvelistv5 2026-09-22
cve-2026-92595 SUSE CVE CVE-2026-92595 UNKNOWN cvelistv5 2026-09-19
cve-2026-93841 vllm: vLLM: Memory corruption via unvalidated prompt token IDs LOW 3.7 cvelistv5 2026-09-22
cve-2026-94624 vllm: vLLM: Denial of Service via unbounded P2P KV offloading sessions HIGH 7.5 cvelistv5 2026-09-22
cve-2026-93386 SUSE CVE CVE-2026-93386 UNKNOWN cvelistv5 2026-09-19
70267 Red Hat Security Advisory: Red Hat Quay 3.14.9 UNKNOWN csaf_redhat 2026-09-22
cve-2026-86049 jupyter-server: Jupyter Server: Information disclosure via 5xx request logging MEDIUM 4.8 cvelistv5 2026-09-22
cve-2026-63458 github.com/perses/perses: Perses: Information disclosure via query parameter authorization bypass MEDIUM 5.3 cvelistv5 2026-09-22
69462 Red Hat Security Advisory: firefox security update HIGH 7.5 csaf_redhat 2026-09-22
69461 Red Hat Security Advisory: firefox security update HIGH 7.5 csaf_redhat 2026-09-22
cve-2026-93750 http-cache-semantics: http-cache-semantics: Information disclosure via improper Vary header wildcard validation MEDIUM 5.9 cvelistv5 2026-09-22
cve-2026-92597 nodemailer: Nodemailer: Email domain validation bypass via RFC 5322 comment mis-parsing MEDIUM 6.5 cvelistv5 2026-09-22
cve-2026-49811 Dell Command | Monitor: Dell Command | Monitor: Elevation of Privileges via Incorrect Permission Assignment HIGH 8.4 cvelistv5 2026-09-22
cve-2026-75939 openshift/oc-mirror: Release signature verification: OpenPGP SignatureError checked before signed body is consumed HIGH 7.4 cvelistv5 2026-09-22
cve-2026-94640 rpcbind: Unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service HIGH 7.5 cvelistv5 2026-09-22
cve-2026-94625 vllm: vLLM: Resource exhaustion via rejected prefill requests HIGH 7.5 cvelistv5 2026-09-22
cve-2026-93990 expat: Expat: XML Injection via Malformed UTF-16 Input HIGH 7.5 cvelistv5 2026-09-22
cve-2026-93752 CSSOM: CSSOM: Denial of Service due to improper property name validation HIGH 7.5 cvelistv5 2026-09-22