Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

899
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 241 - 260 of 27,228 CVEs
CVE-2026-45252 HIGH - 7.5

When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a given file. The FUSE protocol requires the daemon to return a packed list of NUL-terminated strings. The fusefs kernel mo...

Vendor: FreeBSD
Product: FreeBSD
Published: May 21, 2026
Source: NVD
CVE-2026-45251 HIGH - 7.8

A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. Because the blocked thread does not hold a reference to the underlying object, this closure may result in the object being freed while the thread remains blocked. In this situation...

Vendor: FreeBSD
Product: FreeBSD
Published: May 21, 2026
Source: NVD
CVE-2026-42396 MEDIUM - 4.9

Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

Vendor: PowerDNS
Product: Authoritative
Published: May 21, 2026
Source: NVD
CVE-2026-42002 MEDIUM - 5.9

Concurrency and locking defects in GSS-TSIG

Vendor: PowerDNS
Product: Authoritative
Published: May 21, 2026
Source: NVD
CVE-2026-42001 HIGH - 7.5

Insufficient Validation of Autoprimary SOA Queries

Vendor: PowerDNS
Product: Authoritative
Published: May 21, 2026
Source: NVD
CVE-2026-42000 MEDIUM - 6.8

Insufficient Validation of Names During AXFR

Vendor: PowerDNS
Product: Authoritative
Published: May 21, 2026
Source: NVD
CVE-2026-41999 MEDIUM - 4.8

Incorrect Behaviour of Views with TCP PROXY Requests

Vendor: PowerDNS
Product: Authoritative
Published: May 21, 2026
Source: NVD
CVE-2026-39461 MEDIUM - 5.1

libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for data to become available. However, it does not verify that its socket descriptor fits within select(2)'s descriptor set size limit of FD_SETSIZE (1024). An attacker able to ...

Vendor: FreeBSD
Product: FreeBSD
Published: May 21, 2026
Source: NVD
CVE-2026-28764 HIGH - 7.8

MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability

Vendor: MediaArea
Product: MediaInfoLib
Published: May 21, 2026
Source: NVD
CVE-2026-9157 HIGH - 8.4

Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This issue affects Web Fax: from 3.0 before 3.1.

Published: May 21, 2026
Source: NVD
CVE-2026-7837 LOW - 3.7

A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited data modification under specific race conditions.

Published: May 21, 2026
Source: NVD
CVE-2026-5434 MEDIUM - 5.9

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data.

Published: May 21, 2026
Source: NVD
CVE-2026-5433 CRITICAL - 9.1

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE).

Published: May 21, 2026
Source: NVD
CVE-2026-4858 HIGH - 8.0

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermost auth token using via path traversal in integra...

Vendor: mattermost
Product: mattermost_server
Published: May 21, 2026
Source: NVD
CVE-2026-45250 HIGH - 7.8

The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is checked, the user-supplied list of supplementary groups is copied into a fixed-size kernel stack buffer without first validating its length. If the supplied list exceeds the capac...

Vendor: FreeBSD
Product: FreeBSD
Published: May 21, 2026
Source: NVD

A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session option handling that may allow a remote attacker to cause a minor service disruption via crafted DSI se...

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD

Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker to cause a minor service disruption via conditions that trigger incorrect error-handling paths.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD

Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of service via memory errors that would otherwise be caught and safely terminated by runtime protection.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD

A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authenticated attacker to obtain limited information via crafted Spotlight RPC requests.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD
CVE-2026-27393 MEDIUM - 5.3

Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 WOW Styler: from n/a through 1.7.6.

Vendor: Tobias
Product: CF7 WOW Styler
Published: May 21, 2026
Source: NVD