Total CVEs

125,843

Critical Severity

2,274

High Severity

7,870

Last 7 Days

1,169
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 321 - 340 of 1,284 CVEs
CVE-2026-5329 HIGH - 8.5

Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Velociraptor server (primarily Linux) that allows an authenticated remote attacker to write to arbitrary internal server queues via a crafted monitoring me...

Published: Apr 09, 2026
Source: NVD
CVE-2026-35207 MEDIUM - 5.4

dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the deepinid cloud service. Prior to 6.1.80, plugin-deepinid is configured to skip TLS certificate verification when fetching the user's avatar from ...

Vendor: linuxdeepin
Product: dde-control-center, deepin-deepinid-plugin
Published: Apr 09, 2026
Source: NVD
CVE-2026-39860 CRITICAL - 9.0

Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-outp...

Vendor: NixOS
Product: nix
Published: Apr 08, 2026
Source: NVD
CVE-2025-30650 MEDIUM - 6.7

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to line cards running Junos OS Evolved as root. This issue affects systems running Junos OS using Linux-based line cards. Affected line...

Vendor: Juniper Networks
Product: Junos OS
Published: Apr 08, 2026
Source: NVD
CVE-2026-4837 MEDIUM - 6.6

An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is u...

Published: Apr 08, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer available at [1]. The ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the vcc pointer from msg->vcc and uses it directly without any ...

Vendor: Linux
Product: Linux
Published: Apr 08, 2026
Source: NVD
CVE-2026-32282 MEDIUM - 6.4

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to av...

Vendor: Go standard library
Product: internal/syscall/unix
Published: Apr 08, 2026
Source: NVD
CVE-2026-34079 HIGH - 7.5

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the...

Vendor: flatpak
Product: flatpak
Published: Apr 07, 2026
Source: NVD

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to ...

Vendor: flatpak
Product: flatpak
Published: Apr 07, 2026
Source: NVD
CVE-2026-39316 MEDIUM - 4.0

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a use-after-free vulnerability exists in the CUPS scheduler (cupsd) when temporary printers are automatically deleted. cupsdDeleteTemporaryPrinters() in scheduler/printe...

Vendor: OpenPrinting
Product: cups
Published: Apr 07, 2026
Source: NVD
CVE-2026-39314 MEDIUM - 4.0

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, an integer underflow vulnerability in _ppdCreateFromIPP() (cups/ppd-cache.c) allows any unprivileged local user to crash the cupsd root process by supplying a negative j...

Vendor: OpenPrinting
Product: cups
Published: Apr 07, 2026
Source: NVD
CVE-2025-14821 HIGH - 7.8

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insec...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images 1, Red Hat OpenShift Container Platform 4
Published: Apr 07, 2026
Source: NVD
CVE-2026-33727 MEDIUM - 6.4

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privilege-escalation vulnerability allows code execution as root from the low-privilege pihole account. Important context: the pihole account uses nologin, so this is not a direct intera...

Vendor: pi-hole
Product: pi-hole
Published: Apr 06, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use volume UUID in FS_OBJECT_ID_INFORMATION Use sb->s_uuid for a proper volume identifier as the primary choice. For filesystems that do not provide a UUID, fall back to stfs.f_fsid obtained from vfs_statfs().

Vendor: Linux
Product: Linux
Published: Apr 06, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->binding on failed binding request When a multichannel SMB2_SESSION_SETUP request with SMB2_SESSION_REQ_FLAG_BINDING fails ksmbd sets conn->binding = true but never clears it on the error path. This leaves ...

Vendor: Linux
Product: Linux
Published: Apr 06, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold sco_recv_frame() reads conn->sk under sco_conn_lock() but immediately releases the lock without holding a reference to the socket. A concurrent clo...

Vendor: Linux
Product: Linux
Published: Apr 06, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: add missing netlink policy validations Hyunwoo Kim reports out-of-bounds access in sctp and ctnetlink. These attributes are used by the kernel without any validation. Extend the netlink policies accordingly....

Vendor: Linux
Product: Linux
Published: Apr 06, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() After cancel_delayed_work_sync() is called from xfrm_nat_keepalive_net_fini(), xfrm_state_fini() flushes remaining states via __xfrm_state_delete(), which ca...

Vendor: Linux
Product: Linux
Published: Apr 06, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension header tables The ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables in handle_one_ule_extension() are declared with 255 elements (valid indices 0-254), but the inde...

Vendor: Linux
Product: Linux
Published: Apr 06, 2026
Source: NVD
CVE-2026-34990 HIGH - 7.8

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token...

Vendor: OpenPrinting
Product: cups
Published: Apr 03, 2026
Source: NVD