Total CVEs

149,824

Critical Severity

4,834

High Severity

17,268

Last 7 Days

2,947
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 21 - 40 of 46,229 CVEs

Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for the given operation without any checking being done. As a result, certain operations might access stack rubble as structures are possibly uninitialized.

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in dereferencing a NULL pointer.

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that can be set to zero to cause a #DE fault.

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs to cache the guest chosen index, and one of the usages of the index didn't take the necessary locking to avoid concurrent changes. As a result, a guest could change the index after it being check...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cleaning up of that configuration information is not synchronized with its retrieval by a device model controlling the guest.

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a mapping or another copy). For all copy operations the referenced guest frame is looked up. When another operation is already active for the grant (the grant is "pinned")...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parall...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parall...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating t...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating t...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating t...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD
CVE-2026-49332 HIGH - 8.5

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowin...

Vendor: Red Hat
Product: Red Hat OpenShift Container Platform 4
Published: Jul 28, 2026
Source: NVD

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating t...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating t...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternatives (HVM/PVH: HAP, PV: shim) are commonly available, the decision was to deprecate the functionality, while still retainin...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. The management of the bitmap underlying that operation is tied into the binding of the VIRQ_DOM_EXC virtual...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low and de...

Vendor: OpenSolution
Product: Quick.Cart
Published: Jul 28, 2026
Source: NVD
CVE-2026-18047 MEDIUM - 6.5

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy sti...

Vendor: Red Hat
Product: Red Hat Certificate System 10, Red Hat Certificate System 11, Red Hat Certificate System 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 28, 2026
Source: NVD
CVE-2026-18038 MEDIUM - 4.3

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of the component jq Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotel...

Vendor: nextlevelbuilder
Product: GoClaw
Published: Jul 28, 2026
Source: NVD
CVE-2026-15393 MEDIUM - 6.4

The Cozy Blocks โ€“ Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sani...

Vendor: cozythemes
Product: Cozy Blocks โ€“ Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates
Published: Jul 28, 2026
Source: NVD