Total CVEs

140,339

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,776
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 101 - 120 of 36,744 CVEs

An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via loading a crafted shared library.

Published: Jun 26, 2026
Source: NVD

An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of Service (DoS) via parsing a crafted input.

Published: Jun 26, 2026
Source: NVD
CVE-2024-23581 MEDIUM - 6.7

The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.

Vendor: HCLSoftware
Product: Traveler for Microsoft Outlook
Published: Jun 26, 2026
Source: NVD

Flawfinder output manipulation via untrusted filenames and source text

Vendor: pip
Product: flawfinder
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48804 HIGH - 7.5

python-socketio: Binary attachment accumulation can cause denial of service

Vendor: pip
Product: python-socketio
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48802 HIGH - 7.5

python-engineio has unbound thread allocation that can cause denial of service

Vendor: pip
Product: python-engineio
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48809 HIGH - 7.5

python-engineio has possible denial of service due to maximum payload size sometimes not being enforced

Vendor: pip
Product: python-engineio
Published: Jun 26, 2026
Source: GitHub

LinkifyIt#match scan loop has quadratic algorithmic complexity

Vendor: npm
Product: linkify-it
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48790 MEDIUM - 5.5

turso-cli persists Turso platform JWT with world-readable (0o644) file permissions

Vendor: go
Product: github.com/tursodatabase/turso-cli
Published: Jun 26, 2026
Source: GitHub
CVE-2026-41262 MEDIUM - 4.3

Fleet DM Vulnerable to Cross-Team Policy Data Exposure via Global Policy Read Endpoint

Vendor: go
Product: github.com/fleetdm/fleet/v4
Published: Jun 26, 2026
Source: GitHub
CVE-2026-55838 MEDIUM - 4.3

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM user regardless of their assigned policy. Every other admin handler in the codebase calls validate_admin_request to enfo...

Vendor: rustfs
Product: rustfs
Published: Jun 26, 2026
Source: NVD
CVE-2026-55189 HIGH - 7.7

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch directly to the storage backend without ever calling the IAM authorization function that the FTP write/list handlers (and the...

Vendor: rustfs
Product: rustfs
Published: Jun 26, 2026
Source: NVD
CVE-2026-55188 HIGH - 8.2

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replication targets only checks whether request credentials exist, b...

Vendor: rustfs
Product: rustfs
Published: Jun 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: net: mana: Use pci_name() for debugfs directory naming Use pci_name(pdev) for the per-device debugfs directory instead of hardcoded "0" for PFs and pci_slot_name(pdev->slot) for VFs. The previous approach had two issu...

Vendor: Linux
Product: Linux
Published: Jun 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: net: dsa: remove redundant netdev_lock_ops() from conduit ethtool ops DSA replaces the conduit (master) device's ethtool_ops with its own wrappers that aggregate stats from both the conduit and DSA switch ports. Taking the lo...

Vendor: Linux
Product: Linux
Published: Jun 26, 2026
Source: NVD
CVE-2026-53322 HIGH - 8.8

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling function On device shutdown, make vfio_pci_core_close_device() call vfio_pci_dma_buf_cleanup() before the function is disabled via vfio_pci_core_disable(). This ensures that all access ...

Vendor: Linux
Product: Linux
Published: Jun 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: io_uring/napi: cap busy_poll_to 10 msec Currently there's no cap on the maximum amount of time that napi is allowed to poll if no events are found, which can lead to kernel complaints on a task being stuck as there's no ...

Vendor: Linux
Product: Linux
Published: Jun 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() nilfs_ioctl_mark_blocks_dirty() uses bd_oblocknr to detect dead blocks by comparing it with the current block number bd_blocknr. If they differ, the block is consi...

Vendor: Linux
Product: Linux
Published: Jun 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default() wbt_init_enable_default() uses WARN_ON_ONCE to check for failures from wbt_alloc() and wbt_init(). However, both are expected failure paths: - wbt_alloc() can return NUL...

Vendor: Linux
Product: Linux
Published: Jun 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr() Move the NULL check for 'sta' before dereferencing it to prevent a possible crash.

Vendor: Linux
Product: Linux
Published: Jun 26, 2026
Source: NVD