Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,261 - 6,280 of 35,133 CVEs
CVE-2026-47328 MEDIUM - 6.1

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and...

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47326 MEDIUM - 5.5

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns parsed license metadata without requiring authentication. The endpoint is registered on the console listener and returns JSON containing license informa...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener's ConditionalCorsLayer reflects any request Origin value back as Access-Control-Allow-Origin and also sets Access-Control-Allow-Credentials: true...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD
CVE-2026-46526 MEDIUM - 5.0

Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. The current project uses validate_url to validate the input URL. The m...

Vendor: LearningCircuit
Product: local-deep-research
Published: May 28, 2026
Source: NVD

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication layer, allowing any unauthenticated HTTP client to invoke profiling handlers without credentials. On supported builds (e...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the UploadPartCopy operation allows copying objects across buckets without enforcing destination bucket restrictions on allowed copy sources. The implementation validates GetObject permissio...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a 2048-bit RSA private key as a string constant named TEST_PRIVATE_KEY and uses it in production via parse_license() to "verify" license tokens. Because the key is embedded...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensitive credentials including SessionToken (JWT), SecretAccessKey, and full JWT claims are printed in pla...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD
CVE-2026-45039 CRITICAL - 9.8

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a shared secret. The function that produces this secret, get_shared_secret() in crates/ecstore/src/rpc/http_auth.rs, falls back ...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD
CVE-2026-44394 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapp...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-43000 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token car...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-42999 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set fr...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-42998 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credent...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-30761 HIGH - 7.3

An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.

Published: May 28, 2026
Source: NVD
CVE-2026-30760 HIGH - 7.3

An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call.

Published: May 28, 2026
Source: NVD
CVE-2026-46439 HIGH - 7.8

compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub
CVE-2026-46405 MEDIUM - 5.3

OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub
CVE-2026-46380 MEDIUM - 6.7

compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub