| CVE-2025-68121 |
Unexpected session resumption in crypto/tls |
10.0 |
critical |
|
| CVE-2026-27211 |
Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse |
10.0 |
critical |
|
| CVE-2025-62878 |
Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern |
9.9 |
critical |
|
| CVE-2025-61144 |
libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function. |
9.8 |
critical |
|
| CVE-2026-24300 |
Azure Front Door Elevation of Privilege Vulnerability |
9.8 |
critical |
|
| CVE-2026-26119 |
Windows Admin Center Elevation of Privilege Vulnerability |
8.8 |
critical |
|
| CVE-2026-24302 |
Azure Arc Elevation of Privilege Vulnerability |
8.6 |
critical |
|
| CVE-2026-21532 |
Azure Function Information Disclosure Vulnerability |
8.2 |
critical |
|
| CVE-2026-21535 |
Microsoft Teams Information Disclosure Vulnerability |
8.2 |
critical |
|
| CVE-2026-21522 |
Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability |
6.7 |
critical |
|
| CVE-2026-23655 |
Microsoft ACI Confidential Containers Information Disclosure Vulnerability |
6.5 |
critical |
|
| CVE-2026-27969 |
Vitess users with backup storage access can write to arbitrary file paths on restore |
— |
critical |
|
| CVE-2026-21531 |
Azure SDK for Python Remote Code Execution Vulnerability |
9.8 |
high |
|
| CVE-2026-24834 |
Kata Container to Guest micro VM privilege escalation |
9.3 |
high |
|
| CVE-2026-21255 |
Windows Hyper-V Security Feature Bypass Vulnerability |
8.8 |
high |
|
| CVE-2026-21256 |
GitHub Copilot and Visual Studio Remote Code Execution Vulnerability |
8.8 |
high |
|
| CVE-2026-21510 |
Windows Shell Security Feature Bypass Vulnerability |
8.8 |
high |
Yes |
| CVE-2026-21513 |
MSHTML Framework Security Feature Bypass Vulnerability |
8.8 |
high |
Yes |
| CVE-2026-21516 |
GitHub Copilot for Jetbrains Remote Code Execution Vulnerability |
8.8 |
high |
|
| CVE-2026-21518 |
GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability |
8.8 |
high |
|
| CVE-2026-21537 |
Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability |
8.8 |
high |
|
| CVE-2025-61732 |
Potential code smuggling via doc comments in cmd/cgo |
8.6 |
high |
|
| CVE-2025-67733 |
Valkey Affected by RESP Protocol Injection via Lua error_reply |
8.5 |
high |
|
| CVE-2025-71228 |
LoongArch: Set correct protection_map[] for VM_NONE/VM_SHARED |
8.4 |
high |
|
| CVE-2025-71229 |
wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon() |
8.4 |
high |
|
| CVE-2025-71231 |
crypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode |
8.4 |
high |
|
| CVE-2025-71233 |
PCI: endpoint: Avoid creating sub-groups asynchronously |
8.4 |
high |
|
| CVE-2026-23213 |
drm/amd/pm: Disable MMIO access during SMU Mode 1 reset |
8.4 |
high |
|
| CVE-2026-23214 |
btrfs: reject new transactions if the fs is fully read-only |
8.4 |
high |
|
| CVE-2026-23215 |
x86/vmware: Fix hypercall clobbers |
8.4 |
high |
|
| CVE-2026-23216 |
scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() |
8.4 |
high |
|
| CVE-2026-23230 |
smb: client: split cached_fid bitfields to avoid shared-byte RMW races |
8.4 |
high |
|
| CVE-2025-69299 |
WordPress Oxygen theme <= 6.0.8 - Server Side Request Forgery (SSRF) vulnerability |
8.3 |
high |
|
| CVE-2026-21228 |
Azure Local Remote Code Execution Vulnerability |
8.1 |
high |
|
| CVE-2026-21229 |
Power BI Remote Code Execution Vulnerability |
8.0 |
high |
|
| CVE-2026-21257 |
GitHub Copilot and Visual Studio Elevation of Privilege Vulnerability |
8.0 |
high |
|
| CVE-2026-21523 |
GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability |
8.0 |
high |
|
| CVE-2026-28364 |
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data. |
7.9 |
high |
|
| CVE-2025-71234 |
wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add |
7.8 |
high |
|
| CVE-2026-23068 |
spi: spi-sprd-adi: Fix double free in probe error path |
7.8 |
high |
|
| CVE-2026-23208 |
ALSA: usb-audio: Prevent excessive number of frames |
7.8 |
high |
|
| CVE-2026-20841 |
Windows Notepad App Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2026-21231 |
Windows Kernel Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2026-21232 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2026-21236 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2026-21238 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2026-21239 |
Windows Kernel Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2026-21240 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2026-21245 |
Windows Kernel Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2026-21246 |
Windows Graphics Component Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2026-21250 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2026-21251 |
Cluster Client Failover (CCF) Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2026-21259 |
Microsoft Excel Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2026-21514 |
Microsoft Word Security Feature Bypass Vulnerability |
7.8 |
high |
Yes |
| CVE-2026-21519 |
Desktop Window Manager Elevation of Privilege Vulnerability |
7.8 |
high |
Yes |
| CVE-2026-21533 |
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
7.8 |
high |
Yes |
| CVE-2026-21863 |
Malformed Valkey Cluster bus message can lead to Remote DoS |
7.5 |
high |
|
| CVE-2026-23226 |
ksmbd: add chann_lock to protect ksmbd_chann_list xarray |
7.5 |
high |
|
| CVE-2026-27141 |
Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net |
7.5 |
high |
|
| CVE-2026-27623 |
Valkey has Pre-Authentication DOS from malformed RESP request |
7.5 |
high |
|
| CVE-2026-20846 |
GDI+ Denial of Service Vulnerability |
7.5 |
high |
|
| CVE-2026-21218 |
.NET Spoofing Vulnerability |
7.5 |
high |
|
| CVE-2026-21243 |
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
7.5 |
high |
|
| CVE-2026-21260 |
Microsoft Outlook Spoofing Vulnerability |
7.5 |
high |
|
| CVE-2026-21511 |
Microsoft Outlook Spoofing Vulnerability |
7.5 |
high |
|
| CVE-2026-23066 |
rxrpc: Fix recvmsg() unconditional requeue |
7.4 |
high |
|
| CVE-2026-21235 |
Windows Graphics Component Elevation of Privilege Vulnerability |
7.3 |
high |
|
| CVE-2026-21244 |
Windows Hyper-V Remote Code Execution Vulnerability |
7.3 |
high |
|
| CVE-2026-21247 |
Windows Hyper-V Remote Code Execution Vulnerability |
7.3 |
high |
|
| CVE-2026-21248 |
Windows Hyper-V Remote Code Execution Vulnerability |
7.3 |
high |
|
| CVE-2025-71226 |
wifi: iwlwifi: Implement settime64 as stub for MVM/MLD PTP |
7.1 |
high |
|
| CVE-2026-23204 |
net/sched: cls_u32: use skb_header_pointer_careful() |
7.1 |
high |
|
| CVE-2026-26960 |
node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction |
7.1 |
high |
|
| CVE-2025-71221 |
dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() |
7.0 |
high |
|
| CVE-2026-23191 |
ALSA: aloop: Fix racy access at PCM trigger |
7.0 |
high |
|
| CVE-2026-23221 |
bus: fsl-mc: fix use-after-free in driver_override_show() |
7.0 |
high |
|
| CVE-2026-23227 |
drm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free |
7.0 |
high |
|
| CVE-2026-2492 |
TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability |
7.0 |
high |
|
| CVE-2026-21234 |
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2026-21237 |
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2026-21241 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2026-21242 |
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2026-21253 |
Mailslot File System Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2026-21508 |
Windows Storage Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2023-2804 |
Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo |
6.5 |
high |
|
| CVE-2026-21512 |
Azure DevOps Server Cross-Site Scripting Vulnerability |
6.5 |
high |
|
| CVE-2026-21527 |
Microsoft Exchange Server Spoofing Vulnerability |
6.5 |
high |
|
| CVE-2026-21528 |
Azure IoT Explorer Information Disclosure Vulnerability |
6.5 |
high |
|
| CVE-2026-21529 |
Azure HDInsight Spoofing Vulnerability |
5.7 |
high |
|
| CVE-2026-21222 |
Windows Kernel Information Disclosure Vulnerability |
5.5 |
high |
|
| CVE-2026-21258 |
Microsoft Excel Information Disclosure Vulnerability |
5.5 |
high |
|
| CVE-2026-21261 |
Microsoft Excel Information Disclosure Vulnerability |
5.5 |
high |
|
| CVE-2026-21517 |
Windows App for Mac Installer Elevation of Privilege Vulnerability |
4.7 |
high |
|
| CVE-2026-21249 |
Windows NTLM Spoofing Vulnerability |
3.3 |
high |
|
| CVE-2026-27965 |
Vitess users with backup storage access can gain unauthorized access to production deployment environments |
— |
high |
|
| CVE-2026-25541 |
Bytes is vulnerable to integer overflow in BytesMut::reserve |
7.5 |
medium |
|
| CVE-2026-24051 |
OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking |
7.0 |
medium |
|
| CVE-2026-23171 |
bonding: fix use-after-free due to enslave fail after slave array update |
6.7 |
medium |
|
| CVE-2026-0665 |
Qemu-kvm: heap off-by-one in kvm xen physdevop_map_pirq |
6.5 |
medium |
|
| CVE-2026-25727 |
time affected by a stack exhaustion denial of service attack |
6.5 |
medium |
|
| CVE-2026-0391 |
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability |
6.5 |
medium |
|
| CVE-2026-21525 |
Windows Remote Access Connection Manager Denial of Service Vulnerability |
6.2 |
medium |
Yes |
| CVE-2026-27571 |
nats-server websockets are vulnerable to pre-auth memory DoS |
5.9 |
medium |
|
| CVE-2025-61143 |
libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c. |
5.5 |
medium |
|
| CVE-2025-71202 |
iommu/sva: invalidate stale IOTLB entries for kernel address space |
5.5 |
medium |
|
| CVE-2025-71227 |
wifi: mac80211: don't WARN for connections on invalid channels |
5.5 |
medium |
|
| CVE-2025-71235 |
scsi: qla2xxx: Delay module unload while fabric scan in progress |
5.5 |
medium |
|
| CVE-2025-71236 |
scsi: qla2xxx: Validate sp before freeing associated memory |
5.5 |
medium |
|
| CVE-2025-71237 |
nilfs2: Fix potential block overflow that cause system hang |
5.5 |
medium |
|
| CVE-2026-23069 |
vsock/virtio: fix potential underflow in virtio_transport_get_credit() |
5.5 |
medium |
|
| CVE-2026-23086 |
vsock/virtio: cap TX credit to local buffer size |
5.5 |
medium |
|
| CVE-2026-23088 |
tracing: Fix crash on synthetic stacktrace field usage |
5.5 |
medium |
|
| CVE-2026-23100 |
mm/hugetlb: fix hugetlb_pmd_shared() |
5.5 |
medium |
|
| CVE-2026-23113 |
io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop |
5.5 |
medium |
|
| CVE-2026-23137 |
of: unittest: Fix memory leak in unittest_data_add() |
5.5 |
medium |
|
| CVE-2026-23138 |
tracing: Add recursion protection in kernel stack trace recording |
5.5 |
medium |
|
| CVE-2026-23141 |
btrfs: send: check for inline extents in range_is_hole_in_parent() |
5.5 |
medium |
|
| CVE-2026-23154 |
net: fix segmentation of forwarding fraglist GRO |
5.5 |
medium |
|
| CVE-2026-23157 |
btrfs: do not strictly require dirty metadata threshold for metadata writepages |
5.5 |
medium |
|
| CVE-2026-23212 |
bonding: annotate data-races around slave->last_rx |
5.5 |
medium |
|
| CVE-2026-23217 |
riscv: trace: fix snapshot deadlock with sbi ecall |
5.5 |
medium |
|
| CVE-2026-23220 |
ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths |
5.5 |
medium |
|
| CVE-2026-23222 |
crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly |
5.5 |
medium |
|
| CVE-2026-23223 |
xfs: fix UAF in xchk_btree_check_block_owner |
5.5 |
medium |
|
| CVE-2026-23224 |
erofs: fix UAF issue for file-backed mounts w/ directio option |
5.5 |
medium |
|
| CVE-2026-23228 |
smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection() |
5.5 |
medium |
|
| CVE-2026-23229 |
crypto: virtio - Add spinlock protection with virtqueue notification |
5.5 |
medium |
|
| CVE-2025-71225 |
md: suspend array while updating raid_disks via sysfs |
5.3 |
medium |
|
| CVE-2026-1979 |
mruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free |
5.3 |
medium |
|
| CVE-2026-23225 |
sched/mmcid: Don't assume CID is CPU owned on mode switch |
5.3 |
medium |
|
| CVE-2026-2443 |
Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure |
5.3 |
medium |
|
| CVE-2026-28419 |
Vim has Heap-based Buffer Underflow in Emacs tags parsing |
5.3 |
medium |
|
| CVE-2026-28421 |
Vim has a heap-buffer-overflow and a segmentation fault |
5.3 |
medium |
|
| CVE-2026-2243 |
Qemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsing |
5.1 |
medium |
|
| CVE-2025-71232 |
scsi: qla2xxx: Free sp in error path to fix system crash |
4.7 |
medium |
|
| CVE-2026-23110 |
scsi: core: Wake up the error handler when final completions race against each other |
4.7 |
medium |
|
| CVE-2026-23118 |
rxrpc: Fix data-race warning and potential load/store tearing |
4.7 |
medium |
|
| CVE-2026-23126 |
netdevsim: fix a race issue related to the operation on bpf_bound_progs list |
4.7 |
medium |
|
| CVE-2026-23169 |
mptcp: fix race in mptcp_pm_nl_flush_addrs_doit() |
4.7 |
medium |
|
| CVE-2026-23207 |
spi: tegra210-quad: Protect curr_xfer check in IRQ handler |
4.7 |
medium |
|
| CVE-2026-28417 |
Vim has OS Command Injection in netrw |
4.4 |
medium |
|
| CVE-2026-28418 |
Vim has Heap-based Buffer Overflow in Emacs tags parsing |
4.4 |
medium |
|
| CVE-2026-28420 |
Vim has Heap-based Buffer Overflow and OOB Read in :terminal |
4.4 |
medium |
|
| CVE-2025-71230 |
hfs: ensure sb->s_fs_info is always cleaned up |
4.2 |
medium |
|
| CVE-2026-27199 |
Werkzeug safe_join() allows Windows special device names |
— |
medium |
|
| CVE-2026-2739 |
This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely. |
— |
medium |
|
| CVE-2025-61145 |
libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c. |
5.5 |
medium |
|
| CVE-2025-11563 |
wcurl path traversal with percent-encoded slashes |
4.6 |
medium |
|
| CVE-2026-0102 |
Microsoft Edge (Chromium-based) Defense in Depth Vulnerability |
3.1 |
low |
|
| CVE-2025-69873 |
ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., "^(a|a)*$") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation. |
2.9 |
low |
|