Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,961
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,101 - 6,120 of 34,990 CVEs
CVE-2026-33464 MEDIUM - 6.5

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding a low-privileged role can submit a specially crafted, oversized payload to an internal Kibana API, causing the Kibana process to exhaust available...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-33463 MEDIUM - 5.3

Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-bounded access token to remain usable beyond its intended validity window, enabling an unauthenticated...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-33462 MEDIUM - 4.6

A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could create a dashboard with a specially crafted identifier. When an administrator subsequently attempts to delete this dashboard through the Kibana inte...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-32847 HIGH - 7.5

DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying percent-encoded path segments to the GET /{full_path:path} endpoint. Attackers can bypass Starlette&...

Vendor: HKUDS
Product: DeepCode
Published: May 28, 2026
Source: NVD
CVE-2026-47144 MEDIUM - 5.5

Shamefile has an arbitrary file read via shamefile.yaml in shame next

Vendor: pip
Product: shamefile
Published: May 28, 2026
Source: GitHub
CVE-2026-47128 MEDIUM - 6.1

nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`

Vendor: rust
Product: nono-cli
Published: May 28, 2026
Source: GitHub

symfony/polyfill-intl-idn: xn-- labels with ASCII-only Punycode payloads are treated as equivalent to their decoded form

Vendor: composer
Product: symfony/polyfill
Published: May 28, 2026
Source: GitHub
CVE-2026-4944 HIGH - 8.8

vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files (`vllm/model_executor/models/nemotron_vl.py` and `vllm/model_executor/models/kimi_k25.py`). This bypasses the user's explicit `--trust-remote-cod...

Published: May 28, 2026
Source: NVD

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD

Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and could result in incorrect fine-grained mediation of network sockets.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47335 MEDIUM - 5.5

Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel panic.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47334 MEDIUM - 5.5

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47333 HIGH - 7.8

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data bei...

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47332 MEDIUM - 5.5

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent sl...

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47331 HIGH - 7.8

Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD

Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47328 MEDIUM - 6.1

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and...

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47326 MEDIUM - 5.5

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD