Security disclosures by AISLE
Hall of Fame
CVEs discovered by AISLE and published through coordinated disclosure with open-source maintainers.
432 published CVEs 440 discovered CVEs
6
Sep 25
3
Oct 25
9
Nov 25
12
Dec 25
34
Jan 26
63
Feb 26
52
Mar 26
22
Apr 26
29
May 26
20
Jun 26
43
Jul 26
71
Aug 26
66
Sep 26
2
Oct 26
October 2026 · 2
-
Apache HTTP Server
1 8.8- high CVE-2026-93546 8.8 Apache HTTP Server: mod_dav_fs namespace overflow
-
OpenSSL
1 3.7- low CVE-2026-54875 3.7 Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
September 2026 · 66
-
Linux
1 8.8- high CVE-2026-13087 8.8 Heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path...
-
rpm
3 7.8- high CVE-2026-95519 7.8 Code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows)
- high CVE-2026-84838 7.8 Command injection in rpmuncompress via unescaped filenames passed to popen()
- high CVE-2026-84837 7.8 Command injection in rpmbuild via unescaped tarball path
-
flatpak-builder
1 7.8- high CVE-2026-86320 7.8 Host code execution via `git am` hook execution in patch source extraction (`use-git-am`)
-
glibc
132 7.7- high CVE-2026-19499 7.7 Buffer overflow in strfmon and strfmon_l right-justification padding
- medium CVE-2026-80489 5.9 EUC_JISX0213 decoding may hang on crafted input
- medium CVE-2026-77117 5.9 SHIFT_JISX0213 decoding may hang on crafted input
- medium CVE-2026-19542 5.6 Stack-based out-of-bounds write in tdelete during tree rebalancing
- low CVE-2026-97399 3.7 One-byte overread in strncasecmp on Power8
- low CVE-2026-95818 3.6 AT_SECURE program buffer overflow via $ORIGIN processing
-
cockpit
171 7.5- high CVE-2026-91149 7.5 Denial of service via unbounded connection thread spawning
- medium CVE-2026-91202 6.1 Arbitrary file ownership change via symlink following in privileged paste
- medium CVE-2026-91205 6.0 Local attacker can hijack file ownership via symlink race
- medium CVE-2026-91203 6.0 Arbitrary file ownership and permission modification via symlink race condition
- medium CVE-2026-91147 5.9 Dnial of service in `cockpit-ws` due to url-root handling without a trailing slash
- medium CVE-2026-92768 5.5 Sensitive data exposure via command-line arguments
- medium CVE-2026-92747 5.0 Sensitive data exposure of guest credentials via json argument in process list
- medium CVE-2026-92745 5.0 Information disclosure of rhsm offline token via process arguments
- low CVE-2026-91142 3.6 Integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 builds
-
Broker-J
11 7.5- high CVE-2026-92550 7.5 Excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder
- medium CVE-2026-92573 6.5 Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering
-
OpenSSL
1 7.5- high CVE-2026-72897 7.5 Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
-
rpcbind
1 7.5- high CVE-2026-94640 7.5 Unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service
-
tftp-hpa
1 7.5- high CVE-2026-85234 7.5 Denial of service due to out-of-bounds read/write in remap engine
-
libXi
16 7.4- high CVE-2026-93543 7.4 Out-of-bounds read in libXi's XI2 class parser
- medium CVE-2026-94281 6.5 Out-of-bounds read in libXi's XListInputDevices() class parsing
- medium CVE-2026-93545 6.5 Out-of-bounds read in libXi's XListInputDevices()
- medium CVE-2026-93544 6.5 Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing
- medium CVE-2026-93542 6.5 Out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes()
- medium CVE-2026-93541 6.5 Out-of-bounds read in libXi's XQueryDeviceState()
- medium CVE-2026-94282 5.6 Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion
-
curl
123 7.4- high CVE-2026-80230 7.4 OpenSSL pinning bypass
- medium CVE-2026-82208 4.8 wolfSSL CA-cache hit overrides callback
- medium CVE-2026-80231 4.8 native CA store conn reuse
- low CVE-2026-82209 3.7 domain-scoped PSL domain cookie
- low CVE-2026-80255 3.7 secure cookie attribute bypass with tab
- low CVE-2026-80229 3.1 OpenSSL provider use-after-free
-
undici
11 7.4- high CVE-2026-84961 7.4 undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
- low CVE-2026-85008 3.7 undici vulnerable to caching and replay of unsafe HTTP method responses
-
environment-modules
1 7.3- high CVE-2026-85013 7.3 Command injection in environment-modules bash completion via malicious module names containing shell metacharacters
-
snipe-it
31 7.1- high CVE-2026-86759 7.1 Missing Authorization via asset-history CSV importer
- high CVE-2026-86758 7.1 License Key Exposure via CSV Export
- high CVE-2026-86757 7.1 Information Disclosure via Custom Fields
- medium CVE-2026-86763 5.1 Authorization Bypass via Importer
-
libXtst
1 7.1- high CVE-2026-94286 7.1 Out-of-bounds read in libXtst's RECORD reply parser
-
gcc
1 7.0- high CVE-2026-102010 7.0 Denial of service via use-after-free in binary heap erase_if
-
winfsp
1 6.8- medium CVE-2026-93689 6.8 NULL Pointer Dereference via Fast I/O
-
libX11
3 6.5- medium CVE-2026-94283 6.5 Out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser
- medium CVE-2026-94284 5.5 Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parser
- medium CVE-2026-94285 5.1 Out-of-bounds read in libX11's byte-oriented codeset parser
-
phpMyFAQ
2 6.3- medium CVE-2026-85592 6.3 phpMyFAQ before 4.1.8 Authorization Bypass via question/create
- medium CVE-2026-85593 5.4 phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode
-
device-mapper-multipath:
1 6.2- medium CVE-2026-89329 6.2 Local denial of service via blocking ipc send operations
-
sssd
5 5.5- medium CVE-2026-90995 5.5 Denial of service due to null pointer dereference in pam responder
- medium CVE-2026-90462 5.4 Fail-open in ldap ppolicy access check allows continued authorization
- medium CVE-2026-90996 4.0 Denial of service in nss responder via crafted zero-length requests
- medium CVE-2026-90994 4.0 Denial of service via malformed pam v1 requests
- medium CVE-2026-90463 4.0 OOB read in nss service request parsers
-
Wireshark
2 5.5- medium CVE-2026-95386 5.5 Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
- medium CVE-2026-96420 4.7 Buffer Over-read in Wireshark
-
libstoragemgmt
1 5.5- medium CVE-2026-93433 5.5 Denial of service via stack buffer overflow in scsi vpd page parsing
-
libXpm
1 5.5- medium CVE-2026-94287 5.5 Denial of service via unsigned underflow in libXpm's write path
-
glibc2
1 5.3- medium CVE-2026-86469 5.3 toctou symlink race in `g_file_create_replace_destination` fallback path
-
flatpak
2 3.9- low CVE-2026-97026 3.9 World-writable temporary child repositories in system-helper cache path
- low CVE-2026-97025 3.2 World-readable oci authentication token in system-helper cache path
August 2026 · 71
-
FFmpeg
151 9.8- critical CVE-2026-75143 9.8 FFmpeg Heap Buffer Overflow via RIST Protocol Reader
- high CVE-2026-75144 8.5 FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer
- high CVE-2026-75142 8.5 FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c
- high CVE-2026-75141 8.5 FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing
- high CVE-2026-75146 8.1 FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c
- high CVE-2026-75147 7.1 FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c
- medium CVE-2026-75145 5.8 FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer
-
FreeBSD
4 9.8- critical CVE-2026-58097 9.8 ppp(8): missing length validation in mp_SetEnddisc()
- critical CVE-2026-58096 9.8 ppp(8): missing length validation in LcpDecodeConfig()
- critical CVE-2026-58095 9.8 ppp(8): incorrect length calculation in mp_Enddisc()
- critical CVE-2026-49420 9.8 Buffer overflow in libalias RTSP handler
-
rodauth
14 9.4- critical CVE-2026-82466 9.4 Rodauth before 2.46.0 Authentication Bypass via webauthn_login
- medium CVE-2026-82470 5.4 Rodauth before 2.47.0 TOTP Code Reuse via Drift Window
- medium CVE-2026-82469 5.4 Rodauth before 2.47.0 Authentication Bypass via jwt_refresh
- medium CVE-2026-82468 4.9 Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type
- medium CVE-2026-82467 4.9 Rodauth before 2.47.0 Open Redirect via Return-to Path
-
phpMyFAQ
2 8.8- high CVE-2026-76208 8.8 Authentication Bypass via LDAP
- high CVE-2026-76207 8.6 2FA Bypass via Remember-Me Cookie
-
Roundcube
11 8.8- high CVE-2026-74997 8.8 Remote code execution via crafted mail headers
- medium CVE-2026-75006 5.8 SSRF in modcss
-
jsoup
1 8.7- high CVE-2026-75140 8.7 Uncontrolled Resource Consumption in XmlTreeBuilder
-
pac4j
23 8.6- high CVE-2026-82463 8.6 pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check
- high CVE-2026-82461 8.6 pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token
- medium CVE-2026-82465 6.9 pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest
- medium CVE-2026-82462 6.9 pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution
- medium CVE-2026-82464 6.1 pac4j-core before 6.5.6 Open Redirect via Backslash Logout
-
Wireshark
4101 8.1- high CVE-2026-76886 8.1 Heap-based Buffer Overflow in Wireshark
- high CVE-2026-76928 7.5 NULL Pointer Dereference in Wireshark
- high CVE-2026-76880 7.5 Out-of-bounds Write in Wireshark
- high CVE-2026-76879 7.5 Stack-based Buffer Overflow in Wireshark
- medium CVE-2026-19696 6.6 Out-of-bounds write in BLF file parsing
- medium CVE-2026-76924 5.5 Out-of-bounds Read in Wireshark
- medium CVE-2026-76923 5.5 Out-of-bounds Read in Wireshark
- medium CVE-2026-76922 5.5 NULL Pointer Dereference in Wireshark
- medium CVE-2026-76921 5.5 Use After Free in Wireshark
- medium CVE-2026-76919 5.3 Use of Uninitialized Variable in Wireshark
- medium CVE-2026-76929 4.7 Out-of-bounds Read in Wireshark
- medium CVE-2026-76927 4.7 NULL Pointer Dereference in Wireshark
- medium CVE-2026-76920 4.7 Out-of-bounds Write in Wireshark
- medium CVE-2026-76881 4.7 NULL Pointer Dereference in Wireshark
- low CVE-2026-76926 3.1 Reachable Assertion in Wireshark
-
openvt
1 7.8- high CVE-2026-72693 7.8 Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login
-
freeipa
22 7.5- high CVE-2026-73198 7.5 Unauthenticated DoS in via unbounded request body read
- high CVE-2026-73197 7.5 Unauthenticated DoS in `/ipa/migration/migration.py` via unbounded request body read
- medium CVE-2026-73199 6.5 Null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value
- medium CVE-2026-73196 4.3 Authenticated DoS in `otptoken-add` via unbounded otp key decoding/re-encoding
-
Iperf3
11 7.5- high CVE-2026-71217 7.5 Unbounded peer-controlled json parameters enables remote denial of service via resource exhaustion
- medium CVE-2026-71218 5.3 Unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated remote memory exhaustion
-
libkcapi
12 7.3- high CVE-2026-71226 7.3 Memory corruption from uncanceled AIO requests in the one-shot AIO error path
- medium CVE-2026-71225 6.5 IV reuse across chunks in one-shot symmetric cipher operations on large inputs
- medium CVE-2026-71227 5.1 Infinite wait loop in _kcapi_aio_read_all() when reusing an AIO handle after an error
-
RabbitMQ
122 7.1- high CVE-2026-67419 7.1 RabbitMQ: Consecutive topic wildcards cause combinatorial routing work
- medium CVE-2026-67416 5.3 Descriptor prefix collision in the AMQP 1.0 parser lets stored messages crash consumers
- medium CVE-2026-67421 4.5 RabbitMQ: Stored HTML Injection in RabbitMQ Management OAuth Error Handling
- low CVE-2026-67420 2.3 OAuth credential refresh retains revoked runtime tags
- low CVE-2026-67418 2.3 Inapplicable PUBLISH property disconnects matching subscribers
-
mrtg
1 7.1- high CVE-2026-72694 7.1 Symlink-following chown allows local privilege escalation via pid file path manipulation
-
pdfio
1 7.1- high CVE-2026-77220 7.1 PDFio < 1.6.5 Dangling Pointer via Dictionary String-Formatting
-
sblim-sfcb
2 6.6- medium CVE-2026-73583 6.6 Unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr
- medium CVE-2026-73584 6.3 Privileged file corruption and denial of service via insecure temporary file handling
-
open-iscsi
3 6.5- medium CVE-2026-18728 6.5 Integer underflow in iscsiuio ipv4 dhcp parsing
- medium CVE-2026-18727 6.5 Integer underflow in iscsiuio dhcpv6 parsing
- medium CVE-2026-18726 6.5 Denial of service in iscsiuio router advertisement parsing
-
stunnel
2 6.5- medium CVE-2026-70368 6.5 Stack out-of-bounds read in s_vlog() when handling oversized log messages
- medium CVE-2026-70367 5.4 SOCKS proxy localhost restriction bypass via IPv4-mapped IPv6 and unspecified addresses
-
sblim-cmpi-base
1 6.3- medium CVE-2026-73585 6.3 Insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack
-
p11-kit
1 6.2- medium CVE-2026-18938 6.2 Integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems
-
dolibarr
1 5.3- medium CVE-2026-77923 5.3 Authorization Bypass via clonetasks Mass Action
-
OpenSSH
21 5.0- medium CVE-2026-55655 5.0 Local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions
- medium CVE-2026-55653 4.3 Double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
- low CVE-2026-55654 3.7 Heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination
July 2026 · 43
-
curl
33 9.8- critical CVE-2026-10536 9.8 Use-after-free in HTTP/2 stream-dependency handling after curl_easy_reset()
- critical CVE-2026-8925 9.8 Double free of the GSASL context during SASL authentication cleanup
- critical CVE-2026-8926 9.1 Password for another .netrc user sent when the URL specifies only a username
- high CVE-2026-8932 7.5 Connection reuse ignores changed client certificate and private key TLS options
- high CVE-2026-9547 7.4 Known-host key type mismatch silently accepted via the CURLOPT_SSH_KEYFUNCTION callback
- high CVE-2026-9080 7.3 Use-after-free when curl_easy_pause() is called from the socket callback
-
Ninja Forms
221 9.3- critical CVE-2026-65049 9.3 Site-scoped capability check in nf_delete_all_data enables network-wide data deletion
- critical CVE-2026-65048 9.3 Unauthenticated stored XSS via crafted Repeatable Fieldset submission indexes
- high CVE-2026-65052 8.7 Payment total tampering via fail-open get_calc_value() in ListSelect and ListRadio fields
- high CVE-2026-65050 7.1 Missing authorization in the submissions-table block exposes form submissions to visitors
- medium CVE-2026-65051 6.9 Validation bypass via client-controlled field metadata in the AJAX submission handler
-
FFmpeg
6 8.8- high CVE-2026-64835 8.8 Out-of-bounds read and write in the ADX audio decoder via a mid-stream channel layout change
- high CVE-2026-64832 8.8 Double free in the NVDEC hardware decoder when no decoder surfaces remain
- high CVE-2026-64831 8.8 Stack buffer overflow in the Vulkan HEVC decoder via oversized vps_num_hrd_parameters
- high CVE-2026-64830 8.8 Heap buffer overflow in the VobSub subtitle demuxer via excessive distinct stream IDs
- high CVE-2026-64834 8.7 Infinite loop in rtp_asf_fix_header() via an undersized ASF chunksize
- high CVE-2026-64833 7.1 Out-of-bounds read in the S/PDIF muxer via an oversized DTS core_size value
-
Foreman
13 8.8- high CVE-2026-5136 8.8 Privilege escalation to administrator via unvalidated usergroup role assignments
- medium CVE-2026-5142 6.5 Cross-tenant private SSH key disclosure via taxonomy scoping bypass
- medium CVE-2026-5135 6.5 Authorization bypass lets host editors retarget lookup value overrides to other hosts
- medium CVE-2026-5138 4.3 Cross-tenant infrastructure metadata disclosure via unvalidated IDs in taxonomy_scope
-
libssh
111 8.8- high CVE-2026-59851 8.8 Missing Kerberos principal check in the gssapi-keyex path allows login as arbitrary users
- medium CVE-2026-59848 5.3 Unbounded memory growth in SFTP clients from responses with unknown request IDs
- low CVE-2026-59849 3.1 Infinite loop in automatic certificate authentication leading to denial of service
-
cJSON
21 8.7- high CVE-2026-67215 8.7 Stack exhaustion via uncontrolled recursion when applying crafted JSON Patch documents
- high CVE-2026-67216 8.2 Exponential runtime in cJSON_Compare() on deeply nested JSON, leading to denial of service
- medium CVE-2026-67217 6.9 Non-atomic JSON Patch application destroys target document members on failed operations
-
Gitea
1 8.1- high CVE-2026-26247 8.1 OAuth2 PKCE bypass via unpersisted S256 code_challenge_method during authorization
-
yggdrasil-worker-package-manager
1 7.8- high CVE-2026-18157 7.8 Argument injection in the APT backend via crafted package names leading to root code execution
-
gnome-remote-desktop
1 7.5- high CVE-2026-18358 7.5 Missing connection throttling in the system-mode RDP listener allows unauthenticated DoS
-
libsolv
1 7.5- high CVE-2026-48863 7.5 Stack buffer overflow verifying EdDSA PGP signatures with mismatched MPI lengths
-
rpcbind
2 6.5- medium CVE-2026-16461 6.5 Stack buffer overflow in rpcinfo's rpcbdump() when formatting remote version lists
- medium CVE-2026-16277 6.5 Stack buffer overflow in rpcinfo's rpcbaddrlist() via a malicious rpcbind server
-
dhcpcd
1 6.5- medium CVE-2026-14258 6.5 Infinite loop and out-of-bounds read via a zero-length option in IPv6 Router Advertisements
-
libgit2
1 6.5- medium CVE-2026-53583 6.5 Inverted IP SubjectAltName comparison in the OpenSSL backend skips authenticity checks
-
saleor/saleor
1 6.5- medium CVE-2026-48744 6.5 Permission check bypass in channelUpdate via all([]) lets anonymous users modify channels
-
squid
1 6.5- medium CVE-2026-47729 6.5 Out-of-bounds read parsing FTP directory listings leaks memory from other transactions
-
ansible-collection-redhat-leapp
2 6.2- medium CVE-2026-68562 6.2 Controller-side file disclosure via tampered Leapp report content during remediation
- medium CVE-2026-68563 5.5 Insecure permissions on the PostgreSQL data backup archive expose data to local users
-
Joomla! CMS
1 5.9- medium CVE-2026-48953 5.9 XSS via missing escaping in the generic image output layout
-
Wireshark
1 5.5- medium CVE-2026-15171 5.5 NULL pointer dereference in the SSH protocol dissector
-
vim
1 4.8- medium CVE-2026-43961 4.8 Code injection via the mf command
-
libheif
1 4.3- medium CVE-2026-62377 4.3 Reachable assertion in HeifContext::get_track() when opening an empty HEIF sequence file
June 2026 · 20
-
Apache HTTP Server
11 9.8- critical CVE-2026-29167 9.8 Use-after-free in mod_ldap with per-directory configuration
- medium CVE-2026-29170 6.1 XSS in mod_proxy_ftp's FTP directory listing generation
-
MariaDB
11 9.8- critical CVE-2026-44170 9.8 Argument injection in the CONNECT engine's curl command line via the table HTTP attribute
- high CVE-2026-44169 8.1 Authorization bypass exposes stored routine definitions to role-granted EXECUTE users
-
Pacemaker
1 8.6- high CVE-2026-10649 8.6 Integer overflow in remote message decompression crashes the CIB remote listener
-
Poppler
1 7.8- high CVE-2026-10118 7.8 Integer overflow in SplashOutputDev::tilingPatternFill leading to heap buffer overflow
-
rrdtool
1 7.8- high CVE-2026-43958 7.8 Stack buffer overflow in rrdcached via an oversized CREATE request
-
openemr
1 7.7- high CVE-2026-46518 7.7 Stored XSS in the prescription multi-print view via patient demographic fields
-
ImageMagick
2 7.5- high CVE-2026-53460 7.5 Unbounded memory request in AcquireAlignedMemory leading to out-of-memory condition
- high CVE-2026-49218 7.5 Missing check in the DCM decoder allows images with invalid dimensions, causing crashes
-
OpenSSL
11 7.5- high CVE-2026-42765 7.5 NULL pointer dereference during OCSP chain checking with partial-chain verification
- medium CVE-2026-35188 5.0 Double free in the TLS client when checking a crafted OCSP stapled response
-
dracut
1 7.5- high CVE-2026-6893 7.5 Command injection via crafted DHCP options allows root code execution in the initramfs
-
FOG
1 7.5- high CVE-2026-54554 7.5 Unauthenticated disclosure of the Active Directory default join password via adInfo()
-
phpBB
1 7.1- high CVE-2026-48613 7.1 SQL injection during profile field migration via user-supplied profile field data
-
alsa-lib
1 7.0- high CVE-2026-56109 7.0 Double free in parse_def() when parsing nested compound configuration blocks
-
Capstone
2 6.5- medium CVE-2026-55894 6.5 Out-of-bounds read in sh_disassemble when disassembling crafted SH2A bytecode
- medium CVE-2026-55893 6.5 Heap buffer overflow in set_reg_n when disassembling crafted SH2A FPU bytecode
-
n8n
1 6.3- medium CVE-2026-56350 6.3 SSO enforcement bypass via the API lets SSO users create local password credentials
-
GnuTLS
1 4.0- medium CVE-2026-42014 4.0 Use-after-free in gnutls_pkcs11_token_set_pin() with a NULL old PIN
May 2026 · 29
-
GnuTLS
14 9.8- critical CVE-2026-42010 9.8 Authentication bypass via NUL character in RSA-PSK usernames
- high CVE-2026-42013 8.2 Certificate validation falls back to Common Name checks on an oversized SAN
- high CVE-2026-5260 8.2 Heap overread in RSA key exchange with a PKCS#11-backed key via a short premaster secret
- high CVE-2026-42009 7.5 Denial of service via duplicate sequence numbers in DTLS packet reordering
- high CVE-2026-29169 7.5 NULL pointer dereference in mod_dav_lock via a malicious request
-
FreeBSD
12 8.8- high CVE-2026-39461 8.8 Stack buffer overflow in libcasper via file descriptors exceeding FD_SETSIZE in select()
- medium CVE-2026-45254 6.5 Privilege widening in cap_net when keys omitted from a new limit default to allow-any
- medium CVE-2026-45252 5.5 Heap overflow in FUSE_LISTXATTR handling via a non-NUL-terminated attribute list
-
PostgreSQL
2 8.8- high CVE-2026-6638 8.8 SQL injection in logical replication via crafted table names at REFRESH PUBLICATION
- high CVE-2026-6473 8.8 Integer wraparound undersizes allocations, letting unprivileged users write out of bounds
-
FOG
31 8.2- high CVE-2026-47688 8.2 Unauthenticated deletion of host AES keys and power schedules via clearAES and clearPMTasks
- high CVE-2026-47687 7.3 Stored XSS in the Inventory Report via unescaped option labels in selectForm()
- high CVE-2026-47685 7.3 Stored XSS in the Host Management page via the unauthenticated inventory endpoint
- medium CVE-2026-47689 4.6 Stored XSS via unescaped inventory data in buildRow() on the Group Inventory tab
-
libsolv
12 7.8- high CVE-2026-48864 7.8 Heap buffer overflow when decompressing page data from crafted .solv files
- medium CVE-2026-9150 6.5 Stack buffer overflow in the Debian metadata parser via SHA384/SHA512 checksum tags
- medium CVE-2026-9149 6.5 Heap buffer overflow in repo_add_solv() via negative size values in a crafted .solv file
-
Apache HTTP Server
11 7.3- high CVE-2026-29168 7.3 Unbounded resource allocation in mod_md when processing OCSP response data
- medium CVE-2026-33007 5.3 NULL pointer dereference in mod_authn_socache in caching forward proxy configurations
-
mautic/core
11 7.1- high CVE-2026-9808 7.1 Owner-scope role restrictions not enforced on API v2 endpoints, exposing other users' data
- medium CVE-2026-9811 5.4 Stored XSS in the project selector via unsanitized project names
-
rpm
1 7.0- high CVE-2026-44604 7.0 Command injection in rpmuncompress via an archive's top-level directory name
-
Samba
1 6.5- medium CVE-2026-2340 6.5 WORM protection bypass in vfs_worm via rename over a protected file
-
Drupal core
1 6.1- medium CVE-2026-6367 6.1 Cross-site scripting via improper neutralization of input during web page generation
-
Joomla! CMS
1 6.1- medium CVE-2026-25901 6.1 XSS in the multilingual associations component due to missing output escaping
-
vim
1 4.4- medium CVE-2026-42307 4.4 Command injection in the netrw plugin via crafted sftp:// and file:// URLs
-
glib-networking
1 4.3- medium CVE-2026-10028 4.3 Infinite loop in the GnuTLS backend on circular certificate chains leading to denial of service
-
Safari
1 4.3- medium CVE-2026-28901 4.3 Memory corruption when processing crafted web content leading to a process crash
-
rsync
1 3.7- low CVE-2026-45232 3.7 Off-by-one stack write in establish_proxy_connection() via a malformed HTTP proxy response
April 2026 · 22
-
hackage-server
2 9.9- critical CVE-2026-40472 9.9 Stored XSS via package metadata rendered unescaped in href attributes
- critical CVE-2026-40471 9.6 Missing CSRF protection allows cross-site package uploads and admin actions
-
OTP
111 9.8- critical CVE-2026-28808 9.8 Authentication bypass for ScriptAlias CGI scripts via a mod_auth/mod_cgi path mismatch
- high CVE-2026-32144 7.4 OCSP designated-responder authorization bypass via missing signature verification
- low CVE-2026-28810 3.7 Predictable DNS transaction IDs in the inet_res resolver enable cache poisoning
-
GnuTLS
111 9.1- critical CVE-2026-33845 9.1 Out-of-bounds read via integer underflow when reassembling zero-length DTLS fragments
- high CVE-2026-3833 7.4 Name constraints bypass via case-sensitive dNSName and rfc822Name comparison
- low CVE-2026-3832 3.7 Revoked server certificates accepted via crafted multi-record OCSP response
-
BC-JAVA
1 8.7- high CVE-2026-3505 8.7 Unbounded PGP AEAD chunk size allows pre-authentication resource exhaustion
-
OpenSSL
5 8.1- high CVE-2026-28387 8.1 Use-after-free in client-side DANE TLSA certificate checking
- high CVE-2026-28390 7.5 NULL pointer dereference when processing CMS KeyTransportRecipientInfo
- high CVE-2026-28389 7.5 NULL pointer dereference when processing CMS KeyAgreeRecipientInfo
- high CVE-2026-28388 7.5 NULL pointer dereference when processing a delta CRL missing the CRL Number extension
- high CVE-2026-28386 7.5 Out-of-bounds read when processing partial AES-CFB128 blocks on AVX-512 systems
-
FreeBSD
3 8.1- high CVE-2026-42512 8.1 Heap buffer overflow in dhclient's environment array resizing via a crafted packet
- high CVE-2026-42511 8.1 dhclient.conf directive injection via the BOOTP file field, leading to root code execution
- high CVE-2026-39457 7.8 Stack buffer overflow in libnv via file descriptors exceeding FD_SETSIZE in select()
-
MySQL Server
3 6.5- medium CVE-2026-34276 6.5 Resource exhaustion in the Group Replication plugin leading to denial of service
- medium CVE-2026-34271 6.5 Hang or repeatable crash in the Group Replication plugin
- medium CVE-2026-34270 6.5 Hang or repeatable crash in the Group Replication plugin
-
MariaDB
1 6.5- medium CVE-2026-35549 6.5 Stack overflow via alloca in the caching_sha2_password authentication plugin
-
wolfSSH
1 4.3- medium CVE-2026-0930 4.3 Out-of-bounds stack read in wolfSSHd on Windows when handling terminal resize requests
March 2026 · 52
-
openemr
2914 10.0- critical CVE-2026-24898 10.0 Unauthenticated MedEx API token disclosure via the callback endpoint
- critical CVE-2026-32118 9.0 Stored XSS in the Graphical Pain Map (clickmap) encounter form
- high CVE-2026-33918 8.8 Missing authorization on get_claim_file.php lets any user download and delete claim files
- high CVE-2026-33346 8.7 Stored XSS in the patient portal payment flow executing in staff browsers
- high CVE-2026-34055 8.1 IDOR in the patient notes web UI allows modifying and deleting arbitrary notes
- high CVE-2026-34053 8.1 Missing authorization lets any user delete procedure orders via handle_deletions.php
- high CVE-2026-33302 8.1 Module ACL check in zhAclCheck() ignores explicit deny entries
- high CVE-2026-32126 8.1 Inverted ACL check in the CDR ControllerRouter lets any user modify clinical rules
- high CVE-2026-32123 7.7 Broken sensitivity check lets restricted users view sensitive group encounters
- high CVE-2026-32121 7.7 Stored DOM XSS in the portal signer modal via unsanitized patient names
- high CVE-2026-33932 7.6 Stored XSS in the CCDA document preview via unsanitized linkHtml attributes
- medium CVE-2026-33931 6.5 IDOR in the portal payment page exposes other patients' payment records via recid
- medium CVE-2026-33304 6.5 Authorization bypass in the dated reminders log exposes other users' reminder messages
- medium CVE-2026-32120 6.5 IDOR in fee sheet product save allows modifying other patients' drug sales records
- medium CVE-2026-25928 6.5 Path traversal when zipping DICOM folders leads to arbitrary file write
- medium CVE-2026-25745 6.5 IDOR in the message update endpoint allows modifying any patient's messages
- medium CVE-2026-25744 6.5 IDOR in the encounter vitals API allows overwriting any patient's vitals
- medium CVE-2026-33933 6.1 Reflected XSS in the custom template editor via the contextName parameter
- medium CVE-2026-33305 5.4 Authorization bypass in the FaxSMS AppDispatch constructor exposes patient data
- medium CVE-2026-33303 5.4 Stored XSS via unescaped portal_login_username in the portal credential print view
- medium CVE-2026-32125 5.4 Stored XSS in Track Anything graphs via unescaped Dygraph titles and labels
- medium CVE-2026-32124 5.4 Stored XSS in the dynamic code picker via unescaped code descriptions
- medium CVE-2026-32119 4.4 Stored DOM XSS in the SearchHighlight plugin on the Custom Report page
- medium CVE-2026-33934 4.3 Missing authorization in show-signature.php lets portal patients read staff signatures
- medium CVE-2026-32122 4.3 Missing authorization on the Claim File Tracker AJAX endpoint exposes billing claim data
-
OpenClaw
334 9.8- critical CVE-2026-28470 9.8 Exec allowlist bypass via command substitution inside double-quoted strings
- critical CVE-2026-28391 9.8 Command injection via cmd.exe metacharacters in allowlist-gated exec requests
- critical CVE-2026-28446 9.4 Inbound allowlist bypass in the voice-call extension via empty or suffix-matched caller IDs
- high CVE-2026-28472 8.1 Unvalidated auth.token skips device identity checks in the gateway WebSocket handshake
- high CVE-2026-28454 7.5 Unvalidated Telegram webhook secret allows forged updates that bypass sender allowlists
- high CVE-2026-28448 7.3 allowFrom allowlist bypass in the Twitch plugin when allowedRoles is empty
- medium CVE-2026-28450 6.8 Missing authentication on the Nostr plugin's profile HTTP endpoints
- medium CVE-2026-28467 6.5 SSRF in attachment and media URL hydration
- medium CVE-2026-28471 6.3 DM allowlist bypass in the Matrix plugin via display names and cross-homeserver localparts
- medium CVE-2026-29613 5.9 Webhook password bypass in the BlueBubbles plugin via trusted loopback remoteAddress
-
nextcloud-talk
1 9.8- critical CVE-2026-28474 9.8 Allowlist bypass via spoofed actor.name display names in the Nextcloud Talk plugin
-
OTP
12 9.4- critical CVE-2026-23941 9.4 Request smuggling via first-wins Content-Length parsing in inets httpd
- medium CVE-2026-23942 5.4 Path traversal in ssh_sftpd via a string-prefix root directory check
- medium CVE-2026-23943 5.3 Pre-authentication memory exhaustion via unbounded zlib decompression in the SSH transport
-
NGINX Open Source
1 7.8- high CVE-2026-32647 7.8 Buffer over-read and over-write in ngx_http_mp4_module when processing crafted MP4 files
-
AWS-LC
11 7.5- high CVE-2026-3336 7.5 Certificate chain verification bypass in PKCS7_verify() with multiple signers
- medium CVE-2026-3337 5.9 Timing side channel in AES-CCM authentication tag verification
-
Pagure
1 7.5- high CVE-2026-3312 7.5 Local file exposure allows any user to read internal system files
-
undici
1 7.5- high CVE-2026-2229 7.5 Unhandled exception in the WebSocket client via an out-of-range server_max_window_bits
-
Metricbeat
1 5.7- medium CVE-2026-26931 5.7 Excessive memory allocation in the Prometheus remote_write HTTP handler
-
Packetbeat
1 5.7- medium CVE-2026-26933 5.7 Out-of-bounds reads in multiple protocol parsers via malformed network packets
-
grafana/grafana
1 5.4- medium CVE-2026-21724 5.4 Authorization bypass in the provisioning contact points API for protected webhook URLs
-
Mattermost
4 4.6- medium CVE-2026-27659 4.6 CSRF in the access control policy activation endpoint
- medium CVE-2026-25783 4.3 Denial of service via a malformed User-Agent header in getBrowserVersion
- medium CVE-2026-2578 4.3 Information disclosure of unrevealed burn-on-read posts via the WebSocket deletion event
- medium CVE-2026-1629 4.3 Cached permalink previews remain viewable after channel access is revoked
-
DNSdist
1 4.3- medium CVE-2026-0396 4.3 HTML injection in the web dashboard via crafted DNS queries
February 2026 · 63
-
openemr
166 10.0- critical CVE-2026-24908 10.0 SQL injection in the Patient REST API via the _sort parameter
- high CVE-2026-23627 8.8 SQL injection in the Immunization module via the patient_id parameter
- high CVE-2026-25164 8.1 Missing ACL checks on the document and insurance REST API routes
- high CVE-2026-24890 8.1 Provider signature forgery via missing authorization in the portal signature endpoint
- high CVE-2026-25476 7.5 Session timeout bypass via the skip_timeout_reset parameter
- high CVE-2026-25927 7.1 IDOR in the DICOM viewer state API allows reading or modifying any document's state
- high CVE-2026-25147 7.1 IDOR in the portal payment page via a user-supplied pid parameter
- medium CVE-2026-27943 6.5 Insecure direct object reference in the eye exam (eye_mag) view via form_id
- medium CVE-2026-25930 6.5 IDOR in the printable LBF view allows viewing any patient's encounter forms
- medium CVE-2026-25929 6.5 IDOR in the patient_picture document context allows retrieving any patient's photo
- medium CVE-2026-25220 6.5 Missing admin check on the Message Center show_all parameter exposing all users' messages
- medium CVE-2026-24488 6.5 Arbitrary file exfiltration via unrestricted file paths in the fax sending endpoint
- medium CVE-2026-24487 6.5 FHIR patient compartment bypass in the CareTeam endpoint exposing cross-patient data
-
WeKan
3516 9.8- critical CVE-2026-25560 9.8 LDAP filter injection via unescaped usernames during authentication
- critical CVE-2026-1963 9.8 Improper access control in the attachment storage move operation
- critical CVE-2026-1962 9.8 Improper access control in the attachment migration routine
- high CVE-2026-25859 8.8 Insufficient permission checks allow non-admin users to run migration operations
- high CVE-2026-2206 8.8 Improper access control in the fixDuplicateLists admin repair method
- high CVE-2026-25564 7.5 Cross-board IDOR in checklist deletion via unverified cardId-to-board relationship
- high CVE-2026-25563 7.5 Cross-board IDOR in checklist creation via unverified cardId-to-board relationship
- high CVE-2026-25561 7.5 Missing object relationship validation in the attachment upload API
- medium CVE-2026-25565 6.5 Missing write-permission check lets read-only board members update cards
- medium CVE-2026-2208 6.5 Missing authorization in the rules publication
- medium CVE-2026-1898 6.3 Improper access control in LDAP user synchronization
- medium CVE-2026-1896 6.3 Improper access control in the ComprehensiveBoardMigration operation via boardId
- medium CVE-2026-1895 6.3 Improper access control in the applyWipLimit list method
- medium CVE-2026-25566 5.4 Missing authorization checks on the destination board when moving cards
- medium CVE-2026-1894 5.4 Improper authorization in the checklist items REST API
- medium CVE-2026-2207 5.3 Information disclosure in the linked-board activities publication
- medium CVE-2026-1964 5.3 Improper access control in the board title REST endpoint
- medium CVE-2026-1892 5.0 Improper authorization in the REST API's setBoardOrgs function
- medium CVE-2026-25568 4.3 Public boards can be created despite the allowPrivateOnly setting
- medium CVE-2026-25567 4.3 Comment author spoofing via a user-supplied authorId in the card comment API
- medium CVE-2026-25562 4.3 Attachment metadata disclosure via unscoped results in the attachments publication
- medium CVE-2026-2209 4.3 Improper authorization in the setCreateTranslation custom translation handler
- medium CVE-2026-2205 4.3 Information disclosure in the cards Meteor publication
- medium CVE-2026-1897 4.3 Missing authorization in the position-history server methods
-
pearweb
72 9.8- critical CVE-2026-25241 9.8 Unauthenticated SQL injection in the /get/<package>/<version> endpoint
- critical CVE-2026-25240 9.8 SQL injection in user::maintains() via role filters interpolated into an IN() clause
- critical CVE-2026-25238 9.8 SQL injection in bug subscription deletion via a crafted email value
- critical CVE-2026-25237 9.8 PHP code execution via preg_replace /e in bug update email handling
- critical CVE-2026-25236 9.8 SQL injection in Damblan_Karma via unsafe literal substitution in an IN() list
- critical CVE-2026-25234 9.8 SQL injection in category deletion via the category id
- critical CVE-2026-25233 9.1 Roadmap authorization bypass via an operator precedence bug in the role check
- high CVE-2026-25239 7.5 SQL injection in apidoc queue insertion via an unescaped filename
- high CVE-2026-25235 7.5 Predictable verification hashes in election account requests
-
Firefox
1 9.8- critical CVE-2026-2757 9.8 Incorrect boundary conditions in the WebRTC audio/video component
-
OpenClaw
22 8.8- high CVE-2026-26323 8.8 Command injection in the update-clawtributors maintainer script via commit author emails
- high CVE-2026-26316 7.5 Webhook authentication bypass in the BlueBubbles plugin via loopback address trust
- medium CVE-2026-26327 6.5 Trust of unauthenticated discovery TXT records for client routing and TLS pinning
- medium CVE-2026-26326 4.3 Secret disclosure to operator.read clients via raw config values in skills.status
-
FreeRDP
11 8.1- high CVE-2026-25941 8.1 Out-of-bounds read in the RDPGFX channel via a crafted WIRE_TO_SURFACE_2 PDU
- medium CVE-2026-26271 5.3 Buffer overread in freerdp_image_copy_from_icon_data() via crafted TS_ICON_INFO data
-
esp-idf
1 8.0- high CVE-2026-25532 8.0 Integer underflow in WPS Enrollee fragment length handling via truncated EAP-WSC packets
-
MuPDF
1 7.5- high CVE-2026-25556 7.5 Double free in fz_fill_pixmap_from_display_list() error handling during barcode decoding
-
nats-server
1 7.5- high CVE-2026-27571 7.5 Pre-authentication memory exhaustion via a WebSocket compression bomb
-
Packetbeat
1 7.5- high CVE-2026-26932 7.5 Improper array index validation in the PostgreSQL protocol parser causing a panic
-
grafana/grafana
1 6.8- medium CVE-2025-41117 6.8 XSS via stack traces rendered as raw HTML in the Explore Traces view
-
OpenSIPS
1 6.5- medium CVE-2026-25554 6.5 SQL injection via the JWT tag claim in jwt_db_authorize() enabling authentication bypass
-
zulip
1 5.4- medium CVE-2026-24050 5.4 Stored XSS in the user profile modal via group and channel names
-
VLC for Android
1 4.9- medium CVE-2026-26228 4.9 Path traversal in the Remote Access Server's /download endpoint via the file parameter
-
curl
1 4.6- medium CVE-2025-11563 4.6 Path traversal in wcurl via percent-encoded slashes
-
OTP
1 2.3- low CVE-2026-21620 2.3 Relative path traversal in the tftp_file module
January 2026 · 34
-
OpenSSL
48 8.8- high CVE-2025-15467 8.8 Stack buffer overflow via an oversized AEAD IV in CMS (Auth)EnvelopedData parsing
- high CVE-2025-69421 7.5 NULL pointer dereference in PKCS12_item_decrypt_d2i_ex() on malformed PKCS#12 files
- high CVE-2025-69420 7.5 Type confusion in TS_RESP_verify_response() causing a NULL pointer dereference
- high CVE-2025-69419 7.4 Out-of-bounds write in PKCS12_get_friendlyname() UTF-8 conversion
- medium CVE-2025-11187 6.1 Stack buffer overflow via unvalidated PBMAC1 parameters in PKCS#12 MAC verification
- medium CVE-2025-66199 5.9 Unbounded memory allocation when processing TLS 1.3 CompressedCertificate messages
- medium CVE-2025-15468 5.9 NULL pointer dereference in SSL_CIPHER_find() on unknown cipher IDs from QUIC peers
- medium CVE-2026-22795 5.5 Type confusion in PKCS#12 parsing leading to a NULL pointer dereference
- medium CVE-2025-15469 5.5 Silent truncation of input over 16MB with one-shot signing algorithms in openssl dgst
- medium CVE-2026-22796 5.3 Type confusion in PKCS7_digest_from_attributes() leading to a NULL pointer dereference
- medium CVE-2025-68160 4.7 Heap out-of-bounds write in BIO_f_linebuffer on short writes
- medium CVE-2025-69418 4.0 Trailing bytes left unencrypted and unauthenticated in low-level CRYPTO_ocb128 calls
-
glibc
2 8.4- high CVE-2026-0861 8.4 Integer overflow in the memalign function family leading to heap corruption
- high CVE-2026-0915 7.5 Stack memory disclosure to the DNS resolver in getnetbyaddr and getnetbyaddr_r
-
wolfSSH
1 8.1- high CVE-2025-15382 8.1 Heap buffer over-read in wolfSSH_CleanPath() via SCP paths containing '/./' sequences
-
mastodon
12 7.5- high CVE-2026-22245 7.5 SSRF protection bypass via address ranges missing from the local IP denylist
- medium CVE-2026-23964 6.5 Insecure direct object reference in the web push subscription update endpoint
- medium CVE-2026-22246 6.5 Missing ownership check lets any user download other users' severed relationship lists
-
FOG
1 7.5- high CVE-2026-24138 7.5 Unauthenticated SSRF in getversion.php via the url parameter
-
Metricbeat
1 7.5- high CVE-2026-0528 7.5 Denial of service via malformed payloads in the Graphite, Zookeeper, and Prometheus metricsets
-
node
1 7.5- high CVE-2025-59464 7.5 Memory leak converting X.509 certificate fields in socket.getPeerCertificate(true)
-
traefik
1 7.5- high CVE-2026-22045 7.5 Unauthenticated resource exhaustion via stalled ACME TLS-ALPN handshakes
-
TrustTunnel
11 7.1- high CVE-2026-24902 7.1 SSRF and private network restriction bypass via numeric IP destinations
- medium CVE-2026-24904 5.3 Rule bypass via fragmented TLS ClientHello skipping client_random_prefix matching
-
libpng
1 7.1- high CVE-2026-22695 7.1 Heap buffer over-read in png_image_finish_read when reading interlaced 16-bit PNGs
-
opencryptoki
2 6.8- medium CVE-2026-23893 6.8 Symlink following in group-writable token directories leading to privilege escalation
- medium CVE-2026-22791 6.6 Heap buffer overflow in C_WrapKey with CKM_ECDH_AES_KEY_WRAP via compressed EC keys
-
Packetbeat
1 6.5- medium CVE-2026-0529 6.5 Buffer overflow in the MongoDB protocol parser via crafted network traffic
-
curl
3 6.3- medium CVE-2025-14017 6.3 TLS options set on one thread apply globally in multi-threaded LDAPS transfers
- medium CVE-2025-13034 5.9 Certificate pinning check skipped for QUIC connections with ngtcp2 and GnuTLS
- medium CVE-2025-14819 5.3 Trust chain policy bypass via a cached CA store with a stale partial-chain option
-
CryptoLib
1 4.9- medium CVE-2026-21899 4.9 Out-of-bounds read in base64urlDecode when decoding an empty string
-
GnuTLS
1 4.0- medium CVE-2025-9820 4.0 Stack buffer overflow in gnutls_pkcs11_token_init() when processing long token labels
-
OpenVPN
1 3.8- low CVE-2025-15497 3.8 Reachable assertion in epoch key slot processing leading to denial of service
December 2025 · 12
-
Firefox
11 9.8- critical CVE-2025-14321 9.8 Use-after-free in the WebRTC signaling component
- medium CVE-2025-14331 6.5 Same-origin policy bypass in the Request Handling component
-
WebKitGTK
1 8.8- high CVE-2025-66287 8.8 Memory corruption when processing crafted web content leading to a process crash
-
esp-idf
2 8.6- high CVE-2025-68473 8.6 Out-of-bounds write in bta_dm_sdp_result() when SDP discovery returns more than 32 services
- high CVE-2025-68474 7.6 Out-of-bounds write in avrc_vendor_msg() when handling AVRCP vendor commands
-
Apache HTTP Server
1 7.5- high CVE-2025-55753 7.5 Integer overflow in the mod_md ACME renewal backoff leading to delay-free retries
-
Packetbeat
3 6.5- medium CVE-2025-68382 6.5 Out-of-bounds read in the NFS dissector when handling truncated XDR-encoded RPC messages
- medium CVE-2025-68381 6.5 Buffer overflow via a crafted UDP packet with an invalid fragment sequence number
- medium CVE-2025-68388 5.3 Unbounded memory and CPU allocation when reassembling malicious IPv4 fragments
-
ImageMagick
1 6.1- medium CVE-2025-65955 6.1 Use-after-free and double free in Magick++ when Options::fontFamily clears the font family
-
traefik
1 5.9- medium CVE-2025-66491 5.9 Inverted TLS verification in the ingress-nginx provider's proxy-ssl-verify annotation
-
Linux
1 5.5- medium CVE-2025-40306 5.5 Out-of-bounds read in the orangefs xattr_key() helper due to a non-terminating loop
November 2025 · 9
-
Samba
1 10.0- critical CVE-2025-10230 10.0 Unauthenticated command injection via NetBIOS names in the WINS server hook script
-
wolfSSL
11 8.2- high CVE-2025-11931 8.2 Integer underflow leading to out-of-bounds access in wc_XChaCha20Poly1305_Decrypt()
- medium CVE-2025-11932 4.3 Timing side channel in TLS 1.3 PSK binder verification
-
Firefox
1 7.5- high CVE-2025-13016 7.5 Incorrect boundary conditions in the JavaScript WebAssembly component
-
node-glob
1 7.5- high CVE-2025-64756 7.5 Command injection via shell metacharacters in filenames with the CLI -c/--cmd option
-
WebKitGTK
1 7.5- high CVE-2025-13502 7.5 Out-of-bounds read and integer underflow in the GLib remote inspector server
-
esp-idf
1 6.9- medium CVE-2025-65092 6.9 Out-of-bounds read when parsing JPEG headers for the ESP32-P4 hardware decoder
-
Chrome
1 4.3- medium CVE-2025-12443 4.3 Out-of-bounds read in WebXR via a crafted HTML page
-
curl
1 4.3- medium CVE-2025-10966 4.3 Missing SFTP host verification with the wolfSSH backend
October 2025 · 3
-
wolfSSH
1 9.8- critical CVE-2025-11624 9.8 Stack buffer overwrite when processing oversized file handles in the SFTP server
-
OpenVPN
1 8.8- high CVE-2025-10680 8.8 Shell command injection by a malicious server via DNS variables with --dns-updown
-
openwrt
1 8.8- high CVE-2025-62525 8.8 Arbitrary kernel memory read and write via ltq-ptm driver ioctls
September 2025 · 6
-
CryptoLib
1 7.8- high CVE-2025-59534 7.8 Command injection in initialize_kerberos_keytab_file_login()
-
OpenSSL
12 7.5- high CVE-2025-9230 7.5 Out-of-bounds read and write in RFC 3211 KEK unwrap when decrypting CMS messages
- medium CVE-2025-9231 6.5 Timing side channel in SM2 signature computation on 64-bit ARM allows private key recovery
- medium CVE-2025-9232 5.9 Out-of-bounds read in HTTP client no_proxy handling
-
Linux
2 7.1- high CVE-2025-39840 7.1 Out-of-bounds read in audit_compare_dname_path() when watching the root directory
- high CVE-2025-39839 7.1 Out-of-bounds read and write in batman-adv network-coding decode