archivers/arc arc-5.21q_1 ! CVE-2015-9275 5.3 ARC 5.21q allows directory traversal via a full pathname in an archive file. archivers/bzip2 bzip2-1.0.8_1 ! CVE-2026-42250 4.8 Off-by-One Leading to Out-of-Bounds Write in bzip2 archivers/dpkg dpkg-1.19.8_1 ! CVE-2025-6297 8.2 dpkg-deb: Fix cleanup for control member with restricted directories archivers/gcpio gcpio-2.15_1 ! CVE-2026-66484 4.6 Path Traversal in GNU cpio ! CVE-2026-66485 4.6 Uncontrolled Memory Allocation in GNU cpio ! CVE-2026-66486 4.6 Improper Output Encoding in GNU cpio archivers/gtar gtar-1.35_1 ! CVE-2026-18477 4.4 Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape ! CVE-2026-18508 4.4 Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling ar ! CVE-2025-45582 4.1 tar: Tar path traversal archivers/gzip gzip-1.14 ! CVE-2026-41992 6.9 Global Buffer Overflow in GNU gzip ! CVE-2026-41991 2.0 Predictable Temporary File in GNU gzip archivers/linux-c7-lz4 linux-c7-lz4-1.8.3 ! CVE-2021-3520 9.8 lz4: memory corruption due to an integer overflow bug caused by memmove argument ! CVE-2019-17543 8.1 lz4: heap-based buffer overflow in LZ4_write32 archivers/linux-rl9-lz4 linux-rl9-lz4-1.9.3_1 ! CVE-2021-3520 9.8 lz4: memory corruption due to an integer overflow bug caused by memmove argument archivers/rubygem-rubyzip-gitlab rubygem-rubyzip-gitlab-2.4.1 ! CVE-2026-85396 8.7 rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix archivers/rubygem-rubyzip13 rubygem-rubyzip13-1.3.0 ! CVE-2026-85396 8.7 rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix archivers/rubygem-rubyzip2 rubygem-rubyzip2-2.4.1 ! CVE-2026-85396 8.7 rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix archivers/rzip rzip-2.1_2 ! CVE-2017-8364 7.8 The read_buf function in stream.c in rzip 2.1 allows remote attackers to cause a denial of archivers/sharutils sharutils-4.15.2_4 ! CVE-2018-1000097 7.8 sharutils: heap-buffer-overflow in find_archive in unshar.c archivers/unace unace-1.2b_3 ! CVE-2015-2063 4.3 Integer overflow in unace 1.2b allows remote attackers to cause a denial of service (crash archivers/unarj unarj-2.65_2 ! CVE-2004-1027 5.0 security flaw archivers/unzip unzip-6.0_8 ! CVE-2014-8139 7.8 unzip: CRC32 verification heap-based buffer overread (oCERT-2014-011) ! CVE-2014-8140 7.8 unzip: out-of-bounds write issue in test_compr_eb() (oCERT-2014-011) ! CVE-2014-8141 7.8 unzip: getZip64Data() out-of-bounds read issues (oCERT-2014-011) ! CVE-2018-1000035 7.8 unzip: Heap-based buffer overflow in fileio.c:UzpPassword function allows code execution ! CVE-2015-7696 6.8 unzip: Heap overflow and DoS in 6.0 ! CVE-2018-18384 5.5 unzip: Buffer overflow in list.c resulting in a denial of service ! CVE-2022-0529 5.5 unzip: Heap out-of-bound writes and reads during conversion of wide string to local string ! CVE-2022-0530 5.5 unzip: SIGSEGV during the conversion of an utf-8 string to a local string ! CVE-2014-9636 5.0 unzip: out-of-bounds read/write in test_compr_eb() in extract.c ! CVE-2015-7697 4.3 unzip: Heap overflow and DoS in 6.0 ! CVE-2014-9913 4.0 unzip: methbuf[] buffer overflow in unzip's list_files() ! CVE-2016-9844 4.0 unzip: methbuf[] buffer overflow in zipinfo's zi_short() ! CVE-2019-13232 3.3 unzip: overlapping of files in ZIP container leads to denial of service ! CVE-2021-4217 3.3 unzip: Null pointer dereference in Unicode strings code archivers/unzoo unzoo-4.4_2 ! CVE-2007-1673 7.8 unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote at astro/gpsd gpsd-3.25_3 ! CVE-2025-67268 9.8 gpsd: gpsd: Arbitrary code execution via heap-based out-of-bounds write in NMEA2000 packet ! CVE-2026-60122 8.5 gpsd gpsprof Code Injection via SKY.satellites used Field ! CVE-2026-58459 8.4 gpsd gpsprof Command Injection via gnuplot plot title subtype field ! CVE-2025-67269 7.5 gpsd: gpsd: Denial of Service due to malformed NAVCOM packet parsing astro/traccar traccar-6.15.3 ! CVE-2026-25648 8.7 Traccar Vulnerable to Stored Cross-Site Scripting (XSS) via Malicious SVG File Upload audio/ampache ampache-php84-5.6.0_1 ! CVE-2024-28852 6.1 Ampache has multiple reflective XSS vulnerabilities ! CVE-2024-47184 6.1 Ampache vulnerable to Stored XSS via Democratic Playlist Name ! CVE-2024-41665 5.5 Ampache Stored Cross-site Scripting Vulnerability ! CVE-2024-51486 5.5 Stored Cross-Site Scripting in Ampache ! CVE-2024-51490 5.5 Stored Cross-Site Scripting in Ampache ! CVE-2024-47828 5.3 Cross-Site Request Forgery in ampache ! CVE-2024-51484 5.3 Insufficient Validation in Controllers (Activation/Deactivation) in Ampache ! CVE-2024-51485 5.3 Insufficient Validation in Plugins (Activation/Deactivation) in Ampache ! CVE-2024-51487 5.3 Insufficient Validation in Catalog (Activation/Deactivation) in Ampache ! CVE-2024-51488 5.3 Insufficient Validation in Delete Message in Ampache ! CVE-2024-51489 5.3 Insufficient Message Token Validation in Ampache ! CVE-2024-28853 3.9 Ampache Stored XSS audio/cadence cadence-0.9.2_5 ! CVE-2023-43783 7.5 Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File ! CVE-2023-43782 5.5 Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary F audio/festalon festalon-0.5.5_15 ! CVE-2006-4024 7.5 The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assist audio/gstreamer1-plugins-a52dec gstreamer1-plugins-a52dec-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-alsa gstreamer1-plugins-alsa-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-amrnb gstreamer1-plugins-amrnb-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-amrwbdec gstreamer1-plugins-amrwbdec-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-bs2b gstreamer1-plugins-bs2b-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-cdparanoia gstreamer1-plugins-cdparanoia-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-chromaprint gstreamer1-plugins-chromaprint-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-faac gstreamer1-plugins-faac-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-faad gstreamer1-plugins-faad-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-fdkaac gstreamer1-plugins-fdkaac-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-flac gstreamer1-plugins-flac-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-flite gstreamer1-plugins-flite-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-gme gstreamer1-plugins-gme-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-gsm gstreamer1-plugins-gsm-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-jack gstreamer1-plugins-jack-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-ladspa gstreamer1-plugins-ladspa-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-lame gstreamer1-plugins-lame-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-lv2 gstreamer1-plugins-lv2-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-modplug gstreamer1-plugins-modplug-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-mpg123 gstreamer1-plugins-mpg123-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-ogg gstreamer1-plugins-ogg-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-openmpt gstreamer1-plugins-openmpt-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-opus gstreamer1-plugins-opus-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-pulse gstreamer1-plugins-pulse-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-shout2 gstreamer1-plugins-shout2-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-sidplay gstreamer1-plugins-sidplay-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-sndfile gstreamer1-plugins-sndfile-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-soundtouch gstreamer1-plugins-soundtouch-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-speex gstreamer1-plugins-speex-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-taglib gstreamer1-plugins-taglib-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-twolame gstreamer1-plugins-twolame-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-vorbis gstreamer1-plugins-vorbis-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-wavpack gstreamer1-plugins-wavpack-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/gstreamer1-plugins-webrtcdsp gstreamer1-plugins-webrtcdsp-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p audio/libao libao-1.2.0_7 ! CVE-2017-11548 5.5 libao: Invalid memory allocation in _tokenize_matrix function in audio_out.c audio/libaudiofile libaudiofile-0.3.6_6 ! CVE-2018-17095 8.8 audiofile: Heap-based buffer overflow in Expand3To4Module::run() when running sfconvert ! CVE-2017-6827 7.8 audiofile: Heap-based buffer overflow in MSADPCM::initializeCoefficients ! CVE-2017-6828 7.8 audiofile: Heap-based buffer overflow in readValue ! CVE-2018-13440 6.5 audiofile: NULL pointer dereference in ModuleState::setup() in modules/ModuleState.cpp all ! CVE-2019-13147 6.5 audiofile: a NULL pointer dereference in ulaw2linear_buf in G711.cpp in libmodules.a leadi ! CVE-2022-24599 6.5 audiofile: memory leak in printinfo.c ! CVE-2017-6829 5.5 audiofile: Global buffer overflow in decodeSample ! CVE-2017-6830 5.5 audiofile: Heap-based buffer overflow in alaw2linear_buf ! CVE-2017-6831 5.5 audiofile: Heap-based buffer overflow in IMA::decodeBlockWAVE ! CVE-2017-6832 5.5 audiofile: Heap-based buffer overflow in MSADPCM::decodeBlock ! CVE-2017-6833 5.5 audiofile: Divide-by-zero in BlockCodec::runPull ! CVE-2017-6834 5.5 audiofile: Heap-based buffer overflow in ulaw2linear_buf ! CVE-2017-6835 5.5 audiofile: Divide-by-zero in BlockCodec::reset1 ! CVE-2017-6836 5.5 audiofile: Heap-based buffer overflow in Expand3To4Module::run ! CVE-2017-6837 5.5 audiofile: Index out of bounds for type int16_t ! CVE-2017-6838 5.5 audiofile: Signed integer overflow in sfconvert.c ! CVE-2017-6839 5.5 audiofile: Signed integer overflow in MSADPCM.cpp ! CVE-2020-18781 5.5 audiofile: a Denial of Service via crafted file audio/libgig libgig-4.6.0 ! CVE-2021-32294 8.8 An issue was discovered in libgig through 20200507. A heap-buffer-overflow exists in the f audio/libmp3splt libmp3splt-0.9.2_5 ! CVE-2017-5665 5.5 The splt_cue_export_to_file function in cue.c in libmp3splt 0.9.2 allows remote attackers ! CVE-2017-15185 5.0 plugins/ogg.c in Libmp3splt 0.9.2 calls the libvorbis vorbis_block_clear function with uni audio/linux-c7-audiofile linux-c7-audiofile-0.3.6_2 ! CVE-2018-17095 8.8 audiofile: Heap-based buffer overflow in Expand3To4Module::run() when running sfconvert ! CVE-2017-6827 7.8 audiofile: Heap-based buffer overflow in MSADPCM::initializeCoefficients ! CVE-2017-6828 7.8 audiofile: Heap-based buffer overflow in readValue ! CVE-2018-13440 6.5 audiofile: NULL pointer dereference in ModuleState::setup() in modules/ModuleState.cpp all ! CVE-2019-13147 6.5 audiofile: a NULL pointer dereference in ulaw2linear_buf in G711.cpp in libmodules.a leadi ! CVE-2022-24599 6.5 audiofile: memory leak in printinfo.c ! CVE-2017-6829 5.5 audiofile: Global buffer overflow in decodeSample ! CVE-2017-6830 5.5 audiofile: Heap-based buffer overflow in alaw2linear_buf ! CVE-2017-6831 5.5 audiofile: Heap-based buffer overflow in IMA::decodeBlockWAVE ! CVE-2017-6832 5.5 audiofile: Heap-based buffer overflow in MSADPCM::decodeBlock ! CVE-2017-6833 5.5 audiofile: Divide-by-zero in BlockCodec::runPull ! CVE-2017-6834 5.5 audiofile: Heap-based buffer overflow in ulaw2linear_buf ! CVE-2017-6835 5.5 audiofile: Divide-by-zero in BlockCodec::reset1 ! CVE-2017-6836 5.5 audiofile: Heap-based buffer overflow in Expand3To4Module::run ! CVE-2017-6837 5.5 audiofile: Index out of bounds for type int16_t ! CVE-2017-6838 5.5 audiofile: Signed integer overflow in sfconvert.c ! CVE-2017-6839 5.5 audiofile: Signed integer overflow in MSADPCM.cpp ! CVE-2020-18781 5.5 audiofile: a Denial of Service via crafted file audio/linux-c7-flac linux-c7-flac-libs-1.3.0_2 ! CVE-2020-22219 7.8 flac: Remote Code Execution (RCE) via the bitwriter_grow_ function, by supplying crafted i ! CVE-2017-6888 5.5 flac: Memory leak in src/libFLAC/stream_decoder.c:read_metadata_vorbiscomment_() audio/linux-c7-libsndfile linux-c7-libsndfile-1.0.25_7 ! CVE-2025-52194 7.5 libsndfile: buffer overflow when processing crafted IRCAM audio files ! CVE-2017-16942 6.5 libsndfile: divide-by-zero error in wav_w64_read_fmt_chunk() ! CVE-2024-50613 6.5 libsndfile: Reachable assertion in mpeg_l3_encoder_close ! CVE-2017-7585 5.5 libsndfile: Stack-based buffer overflow in flac_buffer_copy() ! CVE-2017-7586 5.5 libsndfile: Error in header_read() causing stack-based buffer overflow ! CVE-2017-7741 5.5 libsndfile: Invalid memory write in flac_buffer_copy function ! CVE-2017-7742 5.5 libsndfile: Invalid memory read in flac_buffer_copy function ! CVE-2024-50612 5.3 libsndfile: Segmentation fault error in ogg_vorbis.c:417 vorbis_analysis_wrote() ! CVE-2014-9756 5.0 libsndfile: division by zero leading to denial of service in psf_fwrite() ! CVE-2014-9496 2.1 libsndfile: 2 buffer overruns in sd2_parse_rsrc_fork() audio/linux-c7-libvorbis linux-c7-libvorbis-1.3.3_2 ! CVE-2020-20412 6.5 lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, audio/linux-rl9-flac linux-rl9-flac-libs-1.3.3_2 ! CVE-2020-22219 7.8 flac: Remote Code Execution (RCE) via the bitwriter_grow_ function, by supplying crafted i audio/linux-rl9-libsndfile linux-rl9-libsndfile-1.0.31_5 ! CVE-2025-52194 7.5 libsndfile: buffer overflow when processing crafted IRCAM audio files ! CVE-2024-50613 6.5 libsndfile: Reachable assertion in mpeg_l3_encoder_close ! CVE-2024-50612 5.3 libsndfile: Segmentation fault error in ogg_vorbis.c:417 vorbis_analysis_wrote() audio/miniaudio miniaudio-0.11.24,1 ! CVE-2026-32837 5.1 mackron / miniaudio Out-of-Bounds Read in BEXT Coding History Parsing audio/mp3gain mp3gain-1.6.2 ! CVE-2023-49356 7.5 A stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a deni ! CVE-2019-18359 5.5 A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulne audio/mp3splt mp3splt-2.6.2_1 ! CVE-2017-5666 5.5 The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to ! CVE-2017-5851 5.5 The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to audio/mumble mumble-1.5.915 ! CVE-2025-71264 3.7 Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denia audio/mumble-server mumble-server-1.5.915 ! CVE-2025-71264 3.7 Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denia audio/opusfile opusfile-0.12_1 ! CVE-2022-47021 7.8 A null pointer dereference issue was discovered in functions op_get_data and op_open1 in o cad/admesh admesh-0.98.5_1 ! CVE-2026-2653 4.8 admesh normals.c stl_check_normal_vector heap-based overflow cad/libopencad libopencad-0.2.0_5 ! CVE-2018-18480 6.5 A heap-based buffer over-read exists in libopencad 0.2.0 in the ReadMCHAR function in lib/ ! CVE-2018-18481 6.5 A heap-based buffer over-read exists in libopencad 0.2.0 in the ReadCHAR function in lib/d cad/libredwg libredwg-0.12.4 ! CVE-2022-35164 9.8 LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via ! CVE-2023-36271 8.8 LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the functio ! CVE-2023-36272 8.8 LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the functio ! CVE-2023-36274 8.8 LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the functio ! CVE-2023-26157 5.5 Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (D cad/openfpgaloader openfpgaloader-1.1.1 ! CVE-2026-35170 7.1 openFPGALoader has a heap buffer overflow in BitParser::parseHeader() via crafted .bit fil ! CVE-2026-35176 7.1 openFPGALoader has a heap buffer overflow in POFParser::parseSection() via crafted .pof fi chinese/wordpress-zh_CN zh-wordpress-zh_CN-7.1 ! CVE-2026-64638 8.9 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. chinese/wordpress-zh_TW zh-wordpress-zh_TW-7.1 ! CVE-2026-64638 8.9 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. comms/gstreamer1-plugins-spandsp gstreamer1-plugins-spandsp-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p comms/libmodbus libmodbus-3.2.0 ! CVE-2024-34244 7.5 libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. Thi ! CVE-2024-36845 4.3 An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers t comms/lrzsz lrzsz-0.12.20_7 ! CVE-2018-10195 7.1 lrzsz: Integer overflow in src/zm.c:zsdata() causes crash in sz and can leak information t comms/mgetty+sendfax mgetty-1.1.37_3 ! CVE-2018-16741 7.8 mgetty: command injection in faxrunq ! CVE-2018-16742 7.8 mgetty: Stack-based buffer overflow in contrib/scrts.c triggered via command line paramete ! CVE-2018-16743 7.8 mgetty: Stack-based buffer overflow with long username in contrib/next-login/login.c ! CVE-2018-16744 7.8 mgetty: Command injection in faxrec.c ! CVE-2018-16745 7.8 mgetty: Stack-based buffer overflow in fax_notify_mail() in faxrec.c ! CVE-2019-1010190 5.6 mgetty: out-of-bounds read in function putwhitespan() in g3/pbm2g3.c causing denial of ser ! CVE-2019-1010189 5.5 mgetty: opening a specially crafted file leads to an infinite loop and DoS comms/multimon-ng multimon-ng-1.1.0_2 ! CVE-2020-36619 5.5 multimon-ng demod_flex.c add_ch format string comms/nmealib nmealib-0.5.3 ! CVE-2018-17174 9.8 A stack-based buffer overflow was discovered in the xtimor NMEA library (aka nmealib) 0.5. converters/linux-c7-fribidi linux-c7-fribidi-1.0.2_1 ! CVE-2019-18397 7.8 fribidi: buffer overflow in fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c le ! CVE-2022-25308 7.8 fribidi: Stack based buffer overflow ! CVE-2022-25309 5.5 fribidi: Heap-buffer-overflow in fribidi_cap_rtl_to_unicode ! CVE-2022-25310 5.5 fribidi: SEGV in fribidi_remove_bidi_marks converters/linux-rl9-fribidi linux-rl9-fribidi-1.0.10_1 ! CVE-2022-25308 7.8 fribidi: Stack based buffer overflow ! CVE-2022-25309 5.5 fribidi: Heap-buffer-overflow in fribidi_cap_rtl_to_unicode ! CVE-2022-25310 5.5 fribidi: SEGV in fribidi_remove_bidi_marks converters/mpack mpack-1.6_4 ! CVE-2011-4919 7.5 mpack 1.6 has information disclosure via eavesdropping on mails sent by other users converters/uudeview uudeview-0.5.20_1 ! CVE-2008-2266 4.4 uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other prod databases/db5 db5-5.3.28_10 ! CVE-2017-3604 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3605 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3606 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3607 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3608 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3609 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3610 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3611 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3612 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3613 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3614 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3615 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3616 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2017-3617 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2020-2981 7.0 Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version tha ! CVE-2019-2708 3.3 libdb: Denial of service in the Data Store component databases/evolution-data-server evolution-data-server-3.56.2_4 ! CVE-2026-2604 5.6 Evolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri databases/firebird30-client firebird30-client-3.0.12 ! CVE-2026-40342 10.0 Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution ! CVE-2026-27890 8.2 Firebird has Pre-Auth DOS when Processing Out of Order CNCT_specific_data Segments ! CVE-2026-28224 8.2 Firebird Null Pointer Dereference via CryptCallback causes DOS ! CVE-2025-65104 7.9 Firebird: Information leak vulnerability in firebird3 client when used with newer server ! CVE-2026-28212 7.5 Firebird has potential server crash via null pointer dereference when processing op_slice ! CVE-2026-33337 7.5 Firebird has a buffer overflow when parsing corrupted slice packets ! CVE-2026-34232 7.5 Firebird: DoS via `op_response` packet from client ! CVE-2026-35215 7.5 Firebird: DoS via malicious slice descriptor in slice packet ! CVE-2025-24975 7.1 Firebird Non-Authorized Access to Encrypted Database Using Execute Statement on External ! CVE-2026-28214 6.0 Firebird server hangs when using specific clumplet on batch creation ! CVE-2025-54989 5.3 Firebird XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability databases/firebird30-server firebird30-server-3.0.12 ! CVE-2026-40342 10.0 Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution ! CVE-2026-27890 8.2 Firebird has Pre-Auth DOS when Processing Out of Order CNCT_specific_data Segments ! CVE-2026-28224 8.2 Firebird Null Pointer Dereference via CryptCallback causes DOS ! CVE-2025-65104 7.9 Firebird: Information leak vulnerability in firebird3 client when used with newer server ! CVE-2026-28212 7.5 Firebird has potential server crash via null pointer dereference when processing op_slice ! CVE-2026-33337 7.5 Firebird has a buffer overflow when parsing corrupted slice packets ! CVE-2026-34232 7.5 Firebird: DoS via `op_response` packet from client ! CVE-2026-35215 7.5 Firebird: DoS via malicious slice descriptor in slice packet ! CVE-2025-24975 7.1 Firebird Non-Authorized Access to Encrypted Database Using Execute Statement on External ! CVE-2026-28214 6.0 Firebird server hangs when using specific clumplet on batch creation ! CVE-2025-54989 5.3 Firebird XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability databases/firebird40-client firebird40-client-4.0.5_2 ! CVE-2026-40342 10.0 Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution ! CVE-2026-27890 8.2 Firebird has Pre-Auth DOS when Processing Out of Order CNCT_specific_data Segments ! CVE-2026-28224 8.2 Firebird Null Pointer Dereference via CryptCallback causes DOS ! CVE-2026-28212 7.5 Firebird has potential server crash via null pointer dereference when processing op_slice ! CVE-2026-33337 7.5 Firebird has a buffer overflow when parsing corrupted slice packets ! CVE-2026-34232 7.5 Firebird: DoS via `op_response` packet from client ! CVE-2026-35215 7.5 Firebird: DoS via malicious slice descriptor in slice packet ! CVE-2025-24975 7.1 Firebird Non-Authorized Access to Encrypted Database Using Execute Statement on External ! CVE-2026-28214 6.0 Firebird server hangs when using specific clumplet on batch creation ! CVE-2025-54989 5.3 Firebird XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability databases/firebird40-server firebird40-server-4.0.5_2 ! CVE-2026-40342 10.0 Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution ! CVE-2026-27890 8.2 Firebird has Pre-Auth DOS when Processing Out of Order CNCT_specific_data Segments ! CVE-2026-28224 8.2 Firebird Null Pointer Dereference via CryptCallback causes DOS ! CVE-2026-28212 7.5 Firebird has potential server crash via null pointer dereference when processing op_slice ! CVE-2026-33337 7.5 Firebird has a buffer overflow when parsing corrupted slice packets ! CVE-2026-34232 7.5 Firebird: DoS via `op_response` packet from client ! CVE-2026-35215 7.5 Firebird: DoS via malicious slice descriptor in slice packet ! CVE-2025-24975 7.1 Firebird Non-Authorized Access to Encrypted Database Using Execute Statement on External ! CVE-2026-28214 6.0 Firebird server hangs when using specific clumplet on batch creation ! CVE-2025-54989 5.3 Firebird XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability databases/immudb immudb15-1.5.0_33 ! CVE-2024-41262 7.4 mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetrics databases/influxdb influxdb-1.8.10_47 ! CVE-2024-30896 9.1 InfluxDB: Privilege Escalation via Authorization Token in InfluxDB databases/libgda5 libgda5-5.2.10_7 ! CVE-2021-39359 5.9 In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verifica databases/libgda5-jdbc libgda5-jdbc-5.2.10_6 ! CVE-2021-39359 5.9 In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verifica databases/libgda5-ldap libgda5-ldap-5.2.10_6 ! CVE-2021-39359 5.9 In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verifica databases/libgda5-mysql libgda5-mysql-5.2.10_7 ! CVE-2021-39359 5.9 In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verifica databases/libgda5-postgresql libgda5-postgresql-5.2.10_6 ! CVE-2021-39359 5.9 In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verifica databases/libgda5-ui libgda5-ui-5.2.10_6 ! CVE-2021-39359 5.9 In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verifica databases/linux-c7-sqlite3 linux-c7-sqlite-3.7.17_2 ! CVE-2017-10989 9.8 sqlite: Heap-buffer overflow in the getNodeSize function ! CVE-2019-19646 9.8 sqlite: pragma.c mishandles NOT NULL in an integrity_check PRAGMA command in certain cases ! CVE-2019-8457 9.8 sqlite: heap out-of-bound read in function rtreenode() ! CVE-2020-11656 9.8 sqlite: use-after-free in the ALTER TABLE implementation ! CVE-2026-11822 8.5 SQLite before 3.53.2 Memory Corruption in FTS5 Extension ! CVE-2026-11824 8.5 SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate ! CVE-2018-20346 8.1 sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases ( ! CVE-2018-20506 8.1 sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases ( ! CVE-2015-3414 7.5 sqlite: use of uninitialized memory when parsing collation sequences in src/where.c ! CVE-2015-3415 7.5 sqlite: invalid free() in src/vdbe.c ! CVE-2015-3416 7.5 sqlite: stack buffer overflow in src/printf.c ! CVE-2015-3717 7.5 Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS befo ! CVE-2018-20505 7.5 sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases ( ! CVE-2018-8740 7.5 sqlite: NULL pointer dereference with databases with schema corrupted with CREATE TABLE AS ! CVE-2020-11655 7.5 sqlite: malformed window-function query leads to DoS ! CVE-2022-35737 7.5 sqlite: an array-bounds overflow if billions of bytes are used in a string argument to a C ! CVE-2025-70873 7.5 sqlite: SQLite: Information Disclosure via Crafted ZIP File ! CVE-2025-6965 7.2 Integer Truncation on SQLite ! CVE-2020-13630 7.0 sqlite: Use-after-free in fts3EvalNextRow in ext/fts3/fts3.c ! CVE-2025-3277 6.9 SQLite: integer overflow in SQLite ! CVE-2016-6153 5.9 sqlite: Tempdir selection vulnerability ! CVE-2019-19645 5.5 sqlite: infinite recursion via certain types of self-referential views in conjunction with ! CVE-2020-13434 5.5 sqlite: integer overflow in sqlite3_str_vappendf function in printf.c ! CVE-2020-13435 5.5 sqlite: NULL pointer dereference in sqlite3ExprCodeTarget() ! CVE-2020-13631 5.5 sqlite: Virtual table can be renamed into the name of one of its shadow tables ! CVE-2020-13632 5.5 sqlite: NULL pointer dereference in ext/fts3/fts3_snippet.c via a crafted matchinfo() quer ! CVE-2020-15358 5.5 sqlite: heap-based buffer overflow in multiSelectOrderBy due to mishandling of query-flatt ! CVE-2023-7104 5.5 SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow ! CVE-2024-0232 4.7 Sqlite: use-after-free bug in jsonparseaddnodearray databases/linux-c7-unixODBC linux-c7-unixODBC-2.3.1 ! CVE-2018-7409 9.8 unixODBC: Buffer overflow in unicode_to_ansi_copy() can lead to crash or other unspecified databases/liquibase liquibase-4.3.5_2 ! CVE-2022-0839 9.8 Improper Restriction of XML External Entity Reference in liquibase/liquibase databases/mantis mantis-php84-2.26.0,1 ! CVE-2026-30849 9.3 MantisBT SOAP API has an authentication bypass vulnerability on MySQL ! CVE-2026-47156 9.3 MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator ! CVE-2025-47776 8.8 MantisBT: Authentication bypass for some passwords due to PHP type juggling ! CVE-2026-34463 8.6 MantisBT has Stored HTML Injection/XSS via Clone Issue Form ! CVE-2026-44655 8.6 MantisBT: Stored XSS on Move Attachments Admin Page ! CVE-2024-23830 8.3 MantisBT Host Header Injection vulnerability ! CVE-2026-40597 7.6 MantisBT has a Content Security Policy bypass via attachments ! CVE-2026-40607 7.5 MantisBT is Vulnerable to Stored XSS Through its Saved-Filter Owner Column ! CVE-2026-44657 7.5 MantisBT: Stored XSS in File Download ! CVE-2024-34077 7.3 MantisBT user account takeover in the signup/reset password process ! CVE-2026-40596 7.2 MantisBT is vulnerable to XSS and potential account takeover via user font family preferen ! CVE-2026-42071 7.2 MantisBT: Private Bugnote Attachment Content Leak via REST API ! CVE-2026-40598 6.9 MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page ! CVE-2024-34081 6.6 MantisBT Cross-site Scripting vulnerability ! CVE-2025-46556 6.5 MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Length ! CVE-2025-55155 5.4 MantisBT: Authentication bypass for some passwords due to PHP type juggling ! CVE-2026-39960 5.4 MantisBT is Vulnerable to Stored XSS through Custom Field Textarea Values ! CVE-2024-34080 5.3 MantisBT Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor ! CVE-2024-45792 5.3 MantisBT vulnerable to information disclosure with user profiles ! CVE-2025-62520 5.3 MantisBT unauthorized disclosure of private project column configuration ! CVE-2026-34579 5.3 MantisBT has an authorization bypass via private issue monitoring ! CVE-2026-34744 5.3 MantisBT authorization bypass allows continued access to self-uploaded attachments on priv ! CVE-2026-34970 5.3 MantisBT Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked ! CVE-2026-41897 5.3 MantisBT: Reflected XSS in Rendering Dynamic Custom Textarea Field ! CVE-2026-42070 5.3 MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API ! CVE-2026-34390 5.1 MantisBT: Privilege Escalation from Manager to Administrator ! CVE-2026-34754 4.3 MantisBT allows unauthorized users to upload attachments to restricted issues via REST API databases/mariadb1011-client mariadb1011-client-10.11.19 ! CVE-2026-35549 6.5 MariaDB Server: MariaDB Server: Denial of Service via large packet with caching_sha2_passw databases/mariadb1011-server mariadb1011-server-10.11.19 ! CVE-2026-35549 6.5 MariaDB Server: MariaDB Server: Denial of Service via large packet with caching_sha2_passw databases/metabase metabase-0.58.24 ! CVE-2023-38646 9.8 Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attacke ! CVE-2026-33725 7.2 Metabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serial ! CVE-2026-86116 7.1 Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary Management API ! CVE-2022-43776 6.5 The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to p ! CVE-2025-30371 2.1 Metabase vulnerable to circumvention of local link access protection in GeoJson endpoint ! CVE-2026-22805 2.1 Metabase channel test endpoint can reach internal local addresses databases/mongodb80 mongodb80-8.0.12_12 ! CVE-2026-13072 9.2 MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memo ! CVE-2025-14847 8.7 KEV Zlib compressed protocol header length confusion may allow memory read ! CVE-2026-11933 8.7 Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion ! CVE-2026-4148 8.7 ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation op ! CVE-2026-8053 8.7 FlatBSON Duplicate Field Index Drift ! CVE-2026-9740 8.7 Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow ! CVE-2026-13059 8.6 Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Contr ! CVE-2026-1848 8.2 Connections received from the proxy port may not count towards total accepted connections ! CVE-2026-13067 7.2 tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket ! CVE-2026-9753 7.2 Server crash via malformed binary diff passed to $_internalApplyOplogUpdate. ! CVE-2025-13507 7.1 Time-series operations may cause internal BSON size limit to be exceed ! CVE-2025-13644 7.1 MongoDB may be susceptible to Invariant Failure due to batched delete ! CVE-2026-13055 7.1 Server crash via aggregation pipeline expression with compound wildcard index specificatio ! CVE-2026-13056 7.1 A user with read access can cause a DoS by executing a specifically crafted query to consu ! CVE-2026-13058 7.1 Transaction Command Insufficient Input Validation Leading to Process Termination ! CVE-2026-13060 7.1 $graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Col ! CVE-2026-13062 7.1 MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Command ! CVE-2026-13064 7.1 MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service ! CVE-2026-13065 7.1 MongoDB $linearFill Window Function Improper Input Validation Leading to Process Terminati ! CVE-2026-13066 7.1 Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure ! CVE-2026-13069 7.1 Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhaus ! CVE-2026-13071 7.1 Server-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process Termi ! CVE-2026-13077 7.1 Out-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn Data ! CVE-2026-1847 7.1 MongoDB Server may crash when inserting large documents ! CVE-2026-1849 7.1 Mongod can run out of stack memory when expressions create deeply nested documents ! CVE-2026-1850 7.1 An authorized user may disable the MongoDB server by issuing a certain type of complex que ! CVE-2026-25610 7.1 Invalid $geoNear index hint may cause server crash ! CVE-2026-25613 7.1 An unsafe cast in the MongoDB query planner can result in a segmentation fault. ! CVE-2026-4147 7.1 Stack memory disclosure in filemd5 command ! CVE-2026-6914 7.1 MD5 checksum creation may cause availability loss ! CVE-2026-8199 7.1 Post-auth memory exhaustion via bitwise match expressions ! CVE-2026-9741 7.1 Client side encryption fails to encrypt values in a $vectorSearch ! CVE-2026-9743 7.1 Aggregation sub-pipeline null dereference may allow DoS via crafted getMore ! CVE-2026-9746 7.1 Server crashes in case of the use of exchange ! CVE-2026-9747 7.1 Crafted cross-shard merge aggregation crashes MongoDB Server ! CVE-2026-9749 7.1 Using MaxKey() may crash the server ! CVE-2026-9750 7.1 Metadata name collision on $-prefixed fields causes post-auth server crash ! CVE-2026-9752 7.1 GeometryCollection with strict-winding polygon causes server crash during 2dsphere index k ! CVE-2026-13074 6.9 Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of Ser ! CVE-2026-9751 6.8 Sensitive data could be written to mongod.log ! CVE-2026-13078 6.3 Local File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader ! CVE-2026-4358 6.1 Memory safety issues in slot-based execution hash table spill ! CVE-2026-8201 6.1 Use-After-Free in MongoDB FLE Query Analysis When Processing Positional Projections on Enc ! CVE-2026-13057 6.0 Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collec ! CVE-2026-13070 6.0 Improper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Term ! CVE-2026-5170 6.0 Users could trigger a crash of mongod primaries during promotion to sharded ! CVE-2025-11979 5.3 Use-after-free in the MongoDB server query planner may lead to crash or undefined behavior ! CVE-2026-13061 5.3 Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions A ! CVE-2026-13073 5.3 MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Termination ! CVE-2026-25609 5.3 profile command may permit unauthorized configuration ! CVE-2026-6915 5.3 Flaw in the updateUser Command May Allow Unauthorized Configuration Change ! CVE-2026-8202 5.3 Post-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operators ! CVE-2026-8200 4.8 Schema validation log messages may not redact user data ! CVE-2025-12893 2.3 Improper Certificate Validation May Allow Successful TLS Handshaking Despite Invalid Exten ! CVE-2025-13643 2.3 MongoDB Server may allow queries to be terminated by unauthorized users ! CVE-2025-14345 2.3 Cross-Shard Failovers May Lead to Partial Transaction Commit in MongoDB Server ! CVE-2026-13068 2.3 MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database databases/mysql-connector-j mysql-connector-j-9.7.0 ! CVE-2026-60586 7.7 Unauthorized Data Access via Network Exploit in MySQL Connector/J 9.7.0–9.7.1 ! CVE-2026-60623 7.1 Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). S ! CVE-2026-60624 6.5 Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). S ! CVE-2026-61082 6.5 Multiple Weaknesses in Oracle MySQL Connector/J Allow Unauthorized Data Access databases/mysql80-server mysql80-server-8.0.46_3 ! CVE-2025-21566 6.5 mysql: Denial of Service Vulnerability in MySQL Server Optimizer ! CVE-2024-21176 5.3 mysql: Thread Pooling unspecified vulnerability (CPU Jul 2024) ! CVE-2024-21204 4.9 mysql: PS unspecified vulnerability (CPU Oct 2024) ! CVE-2025-21499 4.9 mysql: DDL unspecified vulnerability (CPU Jan 2025) ! CVE-2025-21493 4.4 mysql: Denial of Service Vulnerability in Oracle MySQL Server Privilege Management ! CVE-2025-21567 4.3 mysql: Privilege Handling Flaw in MySQL Server ! CVE-2024-21232 2.2 mysql: Components Services unspecified vulnerability (CPU Oct 2024) ! CVE-2024-21243 2.2 mysql: Telemetry unspecified vulnerability (CPU Oct 2024) ! CVE-2024-21244 2.2 mysql: Telemetry unspecified vulnerability (CPU Oct 2024) databases/mysql84-server mysql84-server-8.4.11_3 ! CVE-2025-21566 6.5 mysql: Denial of Service Vulnerability in MySQL Server Optimizer ! CVE-2024-21204 4.9 mysql: PS unspecified vulnerability (CPU Oct 2024) ! CVE-2025-21567 4.3 mysql: Privilege Handling Flaw in MySQL Server databases/neo4j neo4j-4.4.48 ! CVE-2026-1471 2.1 Caching of authentication context ! CVE-2026-1524 2.1 Auth misconfiguration when multiple providers enabled ! CVE-2026-1497 2.0 Incorrect privilege assignment in composite databases ! CVE-2026-1337 1.1 Insufficient escaping of unicode characters in query log databases/p5-DBI p5-DBI-1.647_1 ! CVE-2026-10879 9.8 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements wit ! CVE-2026-14739 9.8 DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements wit ! CVE-2026-14740 9.1 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting a ! CVE-2026-14380 8.8 DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced ! CVE-2026-9698 7.5 DBI versions before 1.648 for Perl saved errors in a limited-sized buffer databases/pgbouncer pgbouncer-1.25.1_1 ! CVE-2026-6665 8.1 PgBouncer buffer overflow in SCRAM ! CVE-2026-6664 7.5 PgBouncer integer overflow in PgBouncer network packet parsing ! CVE-2026-6666 5.9 PgBouncer crash in kill_pool_logins_server_error ! CVE-2026-6667 4.3 PgBouncer missing authorization check in KILL_CLIENT admin command databases/phpliteadmin phpLiteAdmin-1.9.8.2 ! CVE-2021-46709 6.1 phpLiteAdmin through 1.9.8.2 allows XSS via the index.php newRows parameter (aka num or nu databases/postgis33 postgis33-3.3.8_10 ! CVE-2026-73515 7.2 PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer databases/postgis34 postgis34-3.4.4_10 ! CVE-2026-73515 7.2 PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer databases/postgis35 postgis35-3.5.6_3 ! CVE-2026-73515 7.2 PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer databases/postgis36 postgis-3.6.3_3 ! CVE-2026-73515 7.2 PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer databases/proftpd-mod_sql_mysql proftpd-mod_sql_mysql-1.3.8c_2 ! CVE-2026-63090 8.7 ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly ! CVE-2026-35025 8.6 ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR ! CVE-2026-42167 8.1 mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a u ! CVE-2026-44331 8.1 SQL Injection via Reverse DNS Lookup in ProFTPD ! CVE-2026-53994 7.7 ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation ! CVE-2026-63091 7.1 ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser databases/proftpd-mod_sql_odbc proftpd-mod_sql_odbc-1.3.8c_2 ! CVE-2026-63090 8.7 ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly ! CVE-2026-35025 8.6 ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR ! CVE-2026-42167 8.1 mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a u ! CVE-2026-44331 8.1 SQL Injection via Reverse DNS Lookup in ProFTPD ! CVE-2026-53994 7.7 ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation ! CVE-2026-63091 7.1 ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser databases/proftpd-mod_sql_postgres proftpd-mod_sql_postgres-1.3.8c_4 ! CVE-2026-63090 8.7 ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly ! CVE-2026-35025 8.6 ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR ! CVE-2026-42167 8.1 mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a u ! CVE-2026-44331 8.1 SQL Injection via Reverse DNS Lookup in ProFTPD ! CVE-2026-53994 7.7 ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation ! CVE-2026-63091 7.1 ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser databases/proftpd-mod_sql_sqlite proftpd-mod_sql_sqlite-1.3.8c_5 ! CVE-2026-63090 8.7 ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly ! CVE-2026-35025 8.6 ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR ! CVE-2026-42167 8.1 mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a u ! CVE-2026-44331 8.1 SQL Injection via Reverse DNS Lookup in ProFTPD ! CVE-2026-53994 7.7 ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation ! CVE-2026-63091 7.1 ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser databases/recutils recutils-1.9_2 ! CVE-2025-65409 7.5 Recutils: Recutils: Denial of Service due to divide-by-zero with empty password input databases/rubygem-activerecord4 rubygem-activerecord4-4.2.11.3 ! CVE-2022-32224 9.8 activerecord: Possible RCE escalation bug with Serialized Columns in Active Record ! CVE-2022-44566 7.5 rubygem-activerecord: Denial of Service databases/rubygem-activerecord5 rubygem-activerecord5-5.1.7 ! CVE-2022-32224 9.8 activerecord: Possible RCE escalation bug with Serialized Columns in Active Record ! CVE-2022-44566 7.5 rubygem-activerecord: Denial of Service databases/rubygem-activerecord50 rubygem-activerecord50-5.0.7.2 ! CVE-2022-32224 9.8 activerecord: Possible RCE escalation bug with Serialized Columns in Active Record ! CVE-2022-44566 7.5 rubygem-activerecord: Denial of Service databases/rubygem-activerecord52 rubygem-activerecord52-5.2.8.1 ! CVE-2022-44566 7.5 rubygem-activerecord: Denial of Service databases/rubygem-activerecord60 rubygem-activerecord60-6.0.6.1 ! CVE-2022-44566 7.5 rubygem-activerecord: Denial of Service databases/rubygem-globalid rubygem-globalid-0.4.2 ! CVE-2023-22799 7.5 rubygem-globalid: ReDoS vulnerability databases/rubygem-pghero-rails5 rubygem-pghero-rails5-2.8.3 ! CVE-2023-22626 7.5 PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be databases/rubygem-pghero-rails50 rubygem-pghero-rails50-2.8.3 ! CVE-2023-22626 7.5 PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be databases/sqlite2 sqlite-2.8.17_5 ! CVE-2017-10989 9.8 sqlite: Heap-buffer overflow in the getNodeSize function ! CVE-2019-19646 9.8 sqlite: pragma.c mishandles NOT NULL in an integrity_check PRAGMA command in certain cases ! CVE-2020-11656 9.8 sqlite: use-after-free in the ALTER TABLE implementation ! CVE-2026-11822 8.5 SQLite before 3.53.2 Memory Corruption in FTS5 Extension ! CVE-2026-11824 8.5 SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate ! CVE-2018-20346 8.1 sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases ( ! CVE-2018-20506 8.1 sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases ( ! CVE-2015-3414 7.5 sqlite: use of uninitialized memory when parsing collation sequences in src/where.c ! CVE-2015-3415 7.5 sqlite: invalid free() in src/vdbe.c ! CVE-2015-3416 7.5 sqlite: stack buffer overflow in src/printf.c ! CVE-2015-3717 7.5 Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS befo ! CVE-2018-20505 7.5 sqlite: Multiple flaws in sqlite which can be triggered via corrupted internal databases ( ! CVE-2018-8740 7.5 sqlite: NULL pointer dereference with databases with schema corrupted with CREATE TABLE AS ! CVE-2020-11655 7.5 sqlite: malformed window-function query leads to DoS ! CVE-2022-35737 7.5 sqlite: an array-bounds overflow if billions of bytes are used in a string argument to a C ! CVE-2025-70873 7.5 sqlite: SQLite: Information Disclosure via Crafted ZIP File ! CVE-2025-6965 7.2 Integer Truncation on SQLite ! CVE-2020-13630 7.0 sqlite: Use-after-free in fts3EvalNextRow in ext/fts3/fts3.c ! CVE-2025-3277 6.9 SQLite: integer overflow in SQLite ! CVE-2016-6153 5.9 sqlite: Tempdir selection vulnerability ! CVE-2019-19645 5.5 sqlite: infinite recursion via certain types of self-referential views in conjunction with ! CVE-2020-13434 5.5 sqlite: integer overflow in sqlite3_str_vappendf function in printf.c ! CVE-2020-13435 5.5 sqlite: NULL pointer dereference in sqlite3ExprCodeTarget() ! CVE-2020-13631 5.5 sqlite: Virtual table can be renamed into the name of one of its shadow tables ! CVE-2020-13632 5.5 sqlite: NULL pointer dereference in ext/fts3/fts3_snippet.c via a crafted matchinfo() quer ! CVE-2020-15358 5.5 sqlite: heap-based buffer overflow in multiSelectOrderBy due to mishandling of query-flatt ! CVE-2023-7104 5.5 SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow ! CVE-2024-0232 4.7 Sqlite: use-after-free bug in jsonparseaddnodearray databases/sqlitemanager sqlitemanager-1.2.4 ! CVE-2012-5105 4.3 Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.4 allow remote at deskutils/anydesk anydesk-6.1.1_2 ! CVE-2025-27918 9.8 An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0. ! CVE-2021-44426 8.8 An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an ar ! CVE-2025-27919 8.2 An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Cont ! CVE-2021-40854 7.8 AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator pr ! CVE-2024-52940 7.5 AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently ! CVE-2025-27916 7.5 An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before ! CVE-2025-27917 7.5 An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0. ! CVE-2021-44425 6.5 An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3. An unnecessarily o deskutils/calibre calibre-8.16.2_5 ! CVE-2026-26064 9.3 calibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code Executi ! CVE-2026-26065 9.3 calibre: Path Traversal can Lead to Arbitrary File Write and Potential Code Execution ! CVE-2026-25635 8.6 calibre has a Path Traversal Leading to Arbitrary File Write and Potential Code Execution ! CVE-2026-25636 8.2 calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execution ! CVE-2026-33206 8.2 calibre has a path traversal vulnerability ! CVE-2026-25731 7.8 Calibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre ! CVE-2026-27810 6.4 calibre Vulnerable to HTTP Response Header Injection ! CVE-2026-27824 5.3 calibre has IP Ban Bypass via X-Forwarded-For Header Spoofing ! CVE-2026-30853 5.0 calibre has a Path Traversal Leading to Arbitrary File Write ! CVE-2026-33205 4.8 calibre has Server-Side Request Forgery in ebook viewer backend deskutils/phpicalendar phpicalendar-RC7-2.4,1 ! CVE-2008-5840 7.5 PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting ! CVE-2008-5968 7.5 Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows re deskutils/xdg-desktop-portal xdg-desktop-portal-1.20.3 ! CVE-2026-40354 2.9 flatpak: xdg-desktop-portal: Flatpak xdg-desktop-portal: File deletion via symlink attack devel/allegro allegro-4.4.3.1_4 ! CVE-2021-36489 6.5 Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial devel/apache-ant apache-ant-1.10.17 ! CVE-2026-78254 7.4 Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write devel/apr1 apr-1.7.6.1.6.3 ! CVE-2017-12613 7.1 apr: Out-of-bounds array deref in apr_time_exp*() functions ! CVE-2023-49582 5.5 Apache Portable Runtime (APR): Unexpected lax shared memory permissions devel/arm-elf-binutils arm-elf-binutils-2.47 ! CVE-2023-25584 6.3 Out of bounds read in parse_module function in bfd/vms-alpha.c ! CVE-2023-25585 4.7 Field `file_table` of `struct module *module` is uninitialized ! CVE-2023-25586 4.7 Local variable `ch_type` in function `bfd_init_section_decompress_status` can be uninitial ! CVE-2023-25588 4.7 Field `the_bfd` of `asymbol` is uninitialized in function `bfd_mach_o_get_synthetic_symtab devel/atlantis atlantis-0.43.0_5 ! CVE-2026-82282 8.8 Atlantis GitHub App Setup Endpoint Returns App Credentials to Unauthenticated Callers ! CVE-2026-64679 8.1 Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Del devel/axmldec axmldec-1.2.0_17 ! CVE-2018-14402 7.5 axmldec 1.2.0 has an out-of-bounds write in the jitana::axml_parser::parse_start_namespace devel/binutils binutils-2.44,1 ! CVE-2026-6846 7.8 Binutils: binutils: arbitrary code execution via malformed xcoff object file processing ! CVE-2023-25584 6.3 Out of bounds read in parse_module function in bfd/vms-alpha.c ! CVE-2025-69647 6.2 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data ! CVE-2025-69648 6.2 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists ! CVE-2025-69652 6.2 binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug inf ! CVE-2025-69645 5.5 binutils: Binutils objdump: Denial of Service via crafted DWARF debug information ! CVE-2025-69646 5.5 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data ! CVE-2025-69649 5.5 binutils: NULL pointer dereference in readelf via crafted ELF binary ! CVE-2025-69644 5.0 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug inform ! CVE-2025-3198 4.8 GNU Binutils objdump bucomm.c display_info memory leak ! CVE-2025-5244 4.8 GNU Binutils ld elflink.c elf_gc_sweep memory corruption ! CVE-2025-5245 4.8 GNU Binutils objdump debug.c debug_type_samep memory corruption ! CVE-2025-8224 4.8 GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference ! CVE-2025-8225 4.8 GNU Binutils DWARF Section dwarf.c process_debug_info memory leak ! CVE-2023-25585 4.7 Field `file_table` of `struct module *module` is uninitialized ! CVE-2023-25586 4.7 Local variable `ch_type` in function `bfd_init_section_decompress_status` can be uninitial ! CVE-2023-25588 4.7 Field `the_bfd` of `asymbol` is uninitialized in function `bfd_mach_o_get_synthetic_symtab ! CVE-2025-1153 2.3 GNU Binutils format.c bfd_set_format memory corruption devel/bison bison-3.8.2_2,1 ! CVE-2026-56389 6.8 Arbitrary Command Execution in GNU Bison ! CVE-2026-56390 4.6 Arbitrary Output Location Change in GNU Bison devel/capnproto-tiledb capnproto-tiledb-1.3.0_1 ! CVE-2026-32239 6.3 Cap'n Proto has an integer overflow in KJ-HTTP ! CVE-2026-32240 6.3 Cap'n Proto: Integer overflow in KJ-HTTP chunk size devel/capstone capstone-5.0.9 ! CVE-2026-55893 7.3 Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode ! CVE-2026-55894 6.8 Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode ! CVE-2026-49282 5.1 Capstone M68K and RISCV `cs_insn_name()` invalid IDs can trigger out-of-bounds reads and p ! CVE-2025-67873 4.8 Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow ! CVE-2025-68114 4.8 Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow a ! CVE-2026-49263 2.0 Capstone WASM `br_table` instruction-size truncation can cause no-progress disassembly and devel/capstone4 capstone4-4.0.2_1 ! CVE-2026-55893 7.3 Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode ! CVE-2026-55894 6.8 Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode ! CVE-2026-47143 5.1 Capstone has a NULL Pointer Dereference with 3DNow! opcodes ! CVE-2026-49282 5.1 Capstone M68K and RISCV `cs_insn_name()` invalid IDs can trigger out-of-bounds reads and p ! CVE-2025-67873 4.8 Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow ! CVE-2025-68114 4.8 Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow a ! CVE-2026-49263 2.0 Capstone WASM `br_table` instruction-size truncation can cause no-progress disassembly and devel/cbang cbang-1.8.0_2 ! CVE-2023-31483 7.5 tar/TarFileReader.cpp in Cauldron cbang before bastet-v8.1.17 has a directory traversal du devel/cvs-devel cvs-devel-1.12.13_15 ! CVE-2017-12836 7.5 cvs: Command injection via malicious ssh URLs devel/cvsweb cvsweb-2.0.6_2 ! CVE-2018-1000998 6.1 FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all page devel/etcd coreos-etcd-2.3.8_52 ! CVE-2026-33413 8.8 etcd: Authorization bypasses in multiple APIs ! CVE-2026-73500 8.7 etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline ! CVE-2026-73499 7.1 etcd: Watch API authorization bypass via open-ended range requests ! CVE-2020-15106 6.5 Improper Input Validation in etcd ! CVE-2020-15112 6.5 Improper Input Validation in etcd ! CVE-2026-59818 6.5 etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation ! CVE-2020-15113 5.7 Improper Preservation of Permissions in etcd ! CVE-2023-32082 3.1 etcd key name can be accessed via LeaseTimeToLive API ! CVE-2026-33343 0.0 etcd: Nested etcd transactions bypass RBAC authorization checks ! CVE-2026-44283 0.0 etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks devel/etcd34 coreos-etcd34-3.4.37_12 <0mp@FreeBSD.org> ! CVE-2026-33413 8.8 etcd: Authorization bypasses in multiple APIs ! CVE-2026-73500 8.7 etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline ! CVE-2026-73499 7.1 etcd: Watch API authorization bypass via open-ended range requests ! CVE-2026-59818 6.5 etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation ! CVE-2026-33343 0.0 etcd: Nested etcd transactions bypass RBAC authorization checks ! CVE-2026-44283 0.0 etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks devel/etcd35 coreos-etcd35-3.5.28_7 ! CVE-2026-73500 8.7 etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline ! CVE-2026-73499 7.1 etcd: Watch API authorization bypass via open-ended range requests ! CVE-2026-59818 6.5 etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation ! CVE-2026-44283 0.0 etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks devel/etcd36 coreos-etcd36-3.6.5_11 <0mp@FreeBSD.org> ! CVE-2026-33413 8.8 etcd: Authorization bypasses in multiple APIs ! CVE-2026-73500 8.7 etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline ! CVE-2026-73499 7.1 etcd: Watch API authorization bypass via open-ended range requests ! CVE-2026-59818 6.5 etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation ! CVE-2026-33343 0.0 etcd: Nested etcd transactions bypass RBAC authorization checks ! CVE-2026-44283 0.0 etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks devel/flyspray flyspray-0.9.9.7_5 ! CVE-2017-15213 5.4 Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject devel/fossology-nomos-standalone fossology-nomos-standalone-4.2.1 ! CVE-2022-4875 2.4 fossology cross site scripting devel/gcc-msp430-ti-toolchain gcc-msp430-ti-toolchain-9.3.1.2.20210722_1 ! CVE-2021-37322 7.8 binutils: use-after-free in c++filt in cplus-dem.c devel/ghidra ghidra-12.0.4 ! CVE-2026-49498 8.7 Ghidra 11.0 < 12.1 - SQL Injection in PostgreSQL Password Change via Unescaped Username ! CVE-2026-52754 8.7 Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModule ! CVE-2026-52758 8.7 Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search ! CVE-2026-52751 8.6 Ghidra < 12.1 - Remote Code Execution via Unfiltered RMI Deserialization in Shared Project ! CVE-2026-52750 8.4 Ghidra < 12.1- Command Injection via URL Annotation Click ! CVE-2026-18718 7.1 Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State ! CVE-2026-49496 6.9 Ghidra < 12.1 - Heap-Use-After-Free in SleighBuilder::generatePointerAdd via Vector Reallo ! CVE-2026-49495 6.7 Ghidra 10.2 < 12.1 - Denial of Service via Circular Reference in Mach-O Export Trie Parser ! CVE-2026-52759 6.7 Ghidra < 12.1.1 - Denial of Service via Uncontrolled Memory Allocation in Mach-O Parser ! CVE-2026-52756 6.3 Ghidra < 12.2 - Unauthenticated Path Traversal in Debugger ISF Server ! CVE-2026-49497 4.6 Ghidra < 12.1 - Path Traversal via .gnu_debuglink in DWARF External Debug File Resolution ! CVE-2026-52757 4.6 Ghidra < 12.1 - Heap-use-after-free in HighVariable::merge() during decompilation devel/gitolite2 gitolite2-2.3.1_1 ! CVE-2018-16976 8.1 Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) prope ! CVE-2018-20683 8.1 commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rs ! CVE-2013-7203 5.5 gitolite before commit fa06a34 might allow local users to read arbitrary files in reposito devel/gitoxide gitoxide-0.58.0_1 ! CVE-2026-82247 8.7 gitoxide before 0.37.1 HTTP Basic credential leak via URL parsing ! CVE-2026-82251 8.7 gitoxide before 0.52.1 Path Traversal via Submodule Name ! CVE-2026-82252 8.7 gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodules ! CVE-2026-82253 8.7 gitoxide before 0.82.0 Path Traversal via Submodule Name Validation Bypass ! CVE-2026-82254 8.7 gitoxide before 0.69.0 Denial of Service via gix-pack ! CVE-2026-82255 7.6 gitoxide 0.25.4 HTTP Credential Leak via Redirect ! CVE-2026-82248 6.0 gitoxide before 0.33.0 Path Traversal via symlink following devel/glib20 glib-2.88.3,2 ! CVE-2026-58016 7.5 Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" devel/gnucflow gnucflow-1.8 ! CVE-2025-8735 4.8 GNU cflow Lexer c.c yylex null pointer dereference ! CVE-2025-8736 4.8 GNU cflow Lexer c.c yylex buffer overflow devel/go-git go-git-5.19.2 ! CVE-2026-41506 4.7 go-git Credential leak via cross-host redirect in smart HTTP transport devel/gogs gogs-0.14.3_4 ! CVE-2026-52795 4.3 Gogs: Authorization Bypass in Watch API allows any user to monitor private repository acti devel/gradle-completion gradle-completion-1.4.1 <0mp@FreeBSD.org> ! CVE-2026-25063 8.3 gradle-completion has a Bash command injection issue devel/gradle5 gradle5-5.0_3 ! CVE-2019-15052 9.8 gradle: sends authentication credentials originally destined for the configured host ! CVE-2021-29428 8.8 Local privilege escalation through system temporary directory ! CVE-2026-22816 8.6 Gradle fails to disable repositories which can expose builds to malicious artifacts ! CVE-2026-22865 8.6 Gradle's failure to disable repositories failing to answer can expose builds to malicious ! CVE-2020-11979 7.5 ant: insecure temporary file ! CVE-2021-32751 7.5 Arbitrary code execution via specially crafted environment variables ! CVE-2023-35946 6.9 Dependency cache path traversal in Gradle ! CVE-2023-35947 6.9 Path traversal vulnerabilities in handling of Tar archives in Gradle ! CVE-2023-42445 6.8 Possible local file exfiltration by XML External entity injection ! CVE-2019-11065 5.9 gradle: Insecure HTTP URL used to download dependencies leading to possibly maliciously co ! CVE-2019-16370 5.9 gradle: PGP signing plugin security bypass ! CVE-2021-29429 4.0 Information disclosure through temporary directory permissions ! CVE-2023-44387 3.2 Gradle has incorrect permission assignment for symlinked files used in copy or archiving o devel/gradle6 gradle6-6.9.4_2 ! CVE-2021-29428 8.8 Local privilege escalation through system temporary directory ! CVE-2026-22816 8.6 Gradle fails to disable repositories which can expose builds to malicious artifacts ! CVE-2026-22865 8.6 Gradle's failure to disable repositories failing to answer can expose builds to malicious ! CVE-2021-32751 7.5 Arbitrary code execution via specially crafted environment variables ! CVE-2022-23630 7.5 Dependency verification bypass in Gradle ! CVE-2023-35946 6.9 Dependency cache path traversal in Gradle ! CVE-2023-35947 6.9 Path traversal vulnerabilities in handling of Tar archives in Gradle ! CVE-2023-42445 6.8 Possible local file exfiltration by XML External entity injection ! CVE-2022-31156 6.6 Gradle's dependency verification can ignore checksum verification when signature verificat ! CVE-2021-29429 4.0 Information disclosure through temporary directory permissions ! CVE-2023-44387 3.2 Gradle has incorrect permission assignment for symlinked files used in copy or archiving o devel/gradle62 gradle62-6.2.2_3 ! CVE-2021-29428 8.8 Local privilege escalation through system temporary directory ! CVE-2026-22816 8.6 Gradle fails to disable repositories which can expose builds to malicious artifacts ! CVE-2026-22865 8.6 Gradle's failure to disable repositories failing to answer can expose builds to malicious ! CVE-2021-29427 8.0 Repository content filters do not work in Settings pluginManagement ! CVE-2020-11979 7.5 ant: insecure temporary file ! CVE-2021-32751 7.5 Arbitrary code execution via specially crafted environment variables ! CVE-2022-23630 7.5 Dependency verification bypass in Gradle ! CVE-2023-35946 6.9 Dependency cache path traversal in Gradle ! CVE-2023-35947 6.9 Path traversal vulnerabilities in handling of Tar archives in Gradle ! CVE-2023-42445 6.8 Possible local file exfiltration by XML External entity injection ! CVE-2022-31156 6.6 Gradle's dependency verification can ignore checksum verification when signature verificat ! CVE-2023-26053 6.6 Gradle usage of long IDs for PGP keys opens potential for collision attacks ! CVE-2021-29429 4.0 Information disclosure through temporary directory permissions ! CVE-2023-44387 3.2 Gradle has incorrect permission assignment for symlinked files used in copy or archiving o devel/gradle761 gradle761-7.6.1_2 ! CVE-2026-22816 8.6 Gradle fails to disable repositories which can expose builds to malicious artifacts ! CVE-2026-22865 8.6 Gradle's failure to disable repositories failing to answer can expose builds to malicious ! CVE-2023-35946 6.9 Dependency cache path traversal in Gradle ! CVE-2023-42445 6.8 Possible local file exfiltration by XML External entity injection ! CVE-2023-44387 3.2 Gradle has incorrect permission assignment for symlinked files used in copy or archiving o devel/gradle8 gradle8-8.8_2 ! CVE-2026-22816 8.6 Gradle fails to disable repositories which can expose builds to malicious artifacts ! CVE-2026-22865 8.6 Gradle's failure to disable repositories failing to answer can expose builds to malicious devel/gstreamer1-plugins-soup gstreamer1-plugins-soup-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p devel/jenkins-lts jenkins-lts-2.568.3 ! CVE-2026-70429 8.1 jenkins: Jenkins: Privilege escalation via inconsistent case sensitivity in user and group ! CVE-2026-70427 4.3 jenkins: Jenkins: Arbitrary file write via crafted archives and symbolic links ! CVE-2026-70428 4.3 jenkins: Jenkins: Arbitrary file write via path traversal ! CVE-2026-70430 2.7 Jenkins: Jenkins: Privilege escalation via unrestricted object instantiation in project na devel/jetbrains-goland jetbrains-goland-2025.2.4_2 ! CVE-2026-64802 7.8 In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting pr ! CVE-2026-64803 7.8 In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting pr ! CVE-2026-53915 7.1 Remote Code Execution via Untrusted Project Configuration in JetBrains GoLand ! CVE-2026-86506 5.9 Missing Authentication Exposes Profiling Data in JetBrains GoLand Profiler ! CVE-2026-64800 3.5 In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by d devel/jetbrains-phpstorm jetbrains-phpstorm-2025.2.4_2 ! CVE-2026-64808 8.4 In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting ! CVE-2026-64809 8.4 In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting devel/jetbrains-webstorm jetbrains-webstorm-2025.2.4_2 ! CVE-2026-64804 8.4 In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting ! CVE-2026-64805 8.4 Arbitrary Code Execution via Untrusted Project-Local Package Manager in WebStorm ! CVE-2026-64806 8.4 In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting ! CVE-2026-64807 7.8 In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-su devel/jline jline-0.9.94_2 ! CVE-2026-56740 7.5 JLine: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables ! CVE-2026-56741 7.5 JLine: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry ! CVE-2023-50572 5.5 An issue in the component GroovyEngine.execute of jline-groovy v3.24.1 allows attackers to devel/kf5-kcoreaddons kf5-kcoreaddons-5.116.0 ! CVE-2026-41526 6.5 Shell Argument Quoting Vulnerability Leading to Escape in KCoreAddons devel/libcjson libcjson-1.7.19_1 ! CVE-2026-29036 8.7 cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding ! CVE-2026-67215 8.7 cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion ! CVE-2026-67216 8.2 cJSON cJSON_Compare Exponential Complexity Denial of Service ! CVE-2026-67217 6.9 cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation ! CVE-2026-87933 6.9 DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free ! CVE-2026-16554 5.1 Integer Overflow Leading to Heap Buffer Overflow in cJSON devel/libconfuse libconfuse-3.3_2 ! CVE-2022-40320 8.8 cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read. devel/libevent libevent-2.1.13 ! CVE-2026-63380 5.7 Libevent: Null Pointer Dereference in `evws_new_session` devel/libevent-devel libevent-devel-2.2.1_1 ! CVE-2026-63382 9.2 libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling ! CVE-2026-63385 9.2 Libevent: HTTP header handling bugs create risk of access control bypass. ! CVE-2026-63383 8.7 Libevent: decode_tag_internal() can lead to out-of-bounds read ! CVE-2026-63384 8.7 Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` re ! CVE-2026-63388 8.4 Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via A ! CVE-2026-63495 7.5 Libevent: Unbounded memory accumulation in WebSocket server via fragmented frames ! CVE-2026-63387 7.0 Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server res ! CVE-2026-63379 6.3 Libevent: HTTP Header smuggling ! CVE-2026-63381 5.8 Libevent: Dangling Pointer in `evbuffer_add_buffer_reference` ! CVE-2026-63380 5.7 Libevent: Null Pointer Dereference in `evws_new_session` devel/libfastcommon libfastcommon-1.0.43 ! CVE-2026-2016 4.8 happyfish100 libfastcommon base64.c base64_decode stack-based overflow devel/libsoup libsoup-2.74.3_1 ! CVE-2024-52530 7.5 libsoup: HTTP request smuggling via stripping null bytes from the ends of header names ! CVE-2024-52532 7.5 libsoup: infinite loop while reading websocket data ! CVE-2025-2784 7.0 Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content ! CVE-2024-52531 6.5 libsoup: buffer overflow via UTF-8 conversion in soup_header_parse_param_list_strict devel/libzookeeper libzookeeper-3.8.3 ! CVE-2026-24308 6.5 Apache ZooKeeper: Sensitive information disclosure in client configuration handling ! CVE-2026-24281 5.9 Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper Z ! CVE-2024-23944 5.3 Apache ZooKeeper: Information disclosure in persistent watcher handling devel/linux-c7-dbus-libs linux-c7-dbus-libs-1.10.24_4 ! CVE-2019-12749 7.1 dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass ! CVE-2022-42010 6.5 dbus: dbus-daemon crashes when receiving message with incorrectly nested parentheses and c ! CVE-2022-42011 6.5 dbus: dbus-daemon can be crashed by messages with array length inconsistent with element t ! CVE-2022-42012 6.5 dbus: `_dbus_marshal_byteswap` doesn't process fds in messages with "foreign" endianness c ! CVE-2020-12049 5.5 dbus: denial of service via file descriptor leak devel/linux-c7-icu linux-c7-icu-50.2_1 ! CVE-2015-5922 10.0 Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as ! CVE-2014-9654 9.8 icu: insufficient size limit checks in regular expression compiler ! CVE-2014-9911 9.8 icu: stack-based buffer overflow in uloc_getDisplayName ! CVE-2016-6293 9.8 icu: Out-of-bounds access in uloc_acceptLanguageFromHTTP ! CVE-2016-7415 9.8 icu: Stack based buffer overflow in locid.cpp ! CVE-2017-14952 9.8 icu: Double free in i18n/zonemeta.cpp ! CVE-2017-17484 9.8 icu: stack-based buffer overflow in ucnv_u8.cpp:ucnv_UTF8FromUTF8 can lead to denial of se ! CVE-2020-10531 8.8 ICU: Integer overflow in UnicodeString::doAppend() ! CVE-2014-7923 7.5 ICU: regexp engine missing look-behind expression range check ! CVE-2014-7926 7.5 ICU: regexp engine incorrect handling of a zero length quantifier ! CVE-2014-7940 7.5 ICU: uninitialized value use in the collation component ! CVE-2014-8146 7.5 icu: heap overflow via incorrect isolateCount ! CVE-2014-8147 7.5 icu: integer truncation in the resolveImplicitLevels function ! CVE-2017-7867 7.5 icu: Heap-buffer overflow in utext_setNativeIndex function ! CVE-2017-7868 7.5 icu: Heap-buffer overflow in utext_moveIndex32 function ! CVE-2017-15396 6.5 chromium-browser: stack overflow in v8 ! CVE-2017-15422 6.5 chromium-browser: integer overflow in icu devel/linux-c7-qt linux-c7-qt-4.8.7_5 ! CVE-2017-10904 9.8 Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via ! CVE-2018-19873 9.8 qt5-qtbase: QBmpHandler segmentation fault on malformed BMP file ! CVE-2024-36048 9.8 qtnetworkauth: badly seeded PRNG may result in guessable values ! CVE-2015-1290 8.8 The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in ! CVE-2018-19870 8.8 qt5-qtbase: QImage allocation failure in qgifhandler ! CVE-2024-39936 8.6 qtbase: qtbase: Delay any communication until encrypted() can be responded to ! CVE-2025-5455 8.4 Possible denial of service when passing malformed data in a URL to qDecodeDataUrl ! CVE-2018-21035 7.5 qt5-qtwebsockets: websocket implementation allows only limited size for frames and message ! CVE-2022-25634 7.5 qt: allows loading of system library files from an unintended working directory. ! CVE-2023-32763 7.5 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x be ! CVE-2023-37369 7.5 qtbase: buffer overflow in QXmlStreamReader ! CVE-2023-38197 7.5 qtbase: infinite loops in QXmlStreamReader ! CVE-2020-0570 7.3 qt: files placed by attacker can influence the working directory and lead to malicious cod ! CVE-2025-4211 7.3 Improper Link Resolution Before File Access in QFileSystemEngine on Windows ! CVE-2018-19869 6.5 qt5-qtsvg: Invalid parsing of malformed url reference resulting in a denial of service ! CVE-2018-19871 6.5 qt5-qtimageformats: QTgaFile CPU exhaustion ! CVE-2023-32573 6.5 qt: Uninitialized variable usage in m_unitsPerEm ! CVE-2026-9499 6.3 Out-of-bounds read in QTextCodec::codecForName() in Qt ! CVE-2025-30348 5.8 encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy an ! CVE-2017-10905 5.3 A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attacke ! CVE-2020-17507 5.3 qt: buffer over-read in read_xbm_body in gui/image/qxbmhandler.cpp ! CVE-2014-0190 4.3 qt: NULL pointer dereference flaw in QGIFFormat::fillRect ! CVE-2025-23050 3.1 qt: qt5: qt6: Qt missing length checks ! CVE-2026-15037 2.9 XML injection vulnerability in QDom comment, CDATA and processing-instruction serializatio devel/linux-c7-sdl12 linux-c7-sdl-1.2.15_3 ! CVE-2019-14906 9.8 SDL: not fixed in Red Hat Enterprise Linux 7 erratum RHSA-2019:3950 ! CVE-2019-7572 8.8 SDL: buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c ! CVE-2019-7573 8.8 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c ! CVE-2019-7574 8.8 SDL: heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c ! CVE-2019-7575 8.8 SDL: heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c ! CVE-2019-7576 8.8 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c ! CVE-2019-7577 8.8 SDL: buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c ! CVE-2019-7637 8.8 SDL: heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c ! CVE-2019-7638 8.8 SDL: heap-based buffer over-read in Map1toN in video/SDL_pixels.c ! CVE-2019-13616 8.1 SDL: heap-based buffer overflow in SDL blit functions in video/SDL_blit*.c ! CVE-2019-7578 8.1 SDL: heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c ! CVE-2019-7635 8.1 SDL: heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c ! CVE-2019-7636 8.1 SDL: heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c ! CVE-2022-34568 7.5 SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x devel/linux-c7-sdl20 linux-c7-sdl20-2.0.14 ! CVE-2021-33657 8.8 There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2 ! CVE-2020-14409 7.8 SDL2: Integer overflow in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file ! CVE-2022-4743 7.5 SDL2: memory leak in GLES_CreateTexture() in render/opengles/SDL_render_gles.c ! CVE-2020-14410 5.4 SDL2: Heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c devel/linux-c7-zlib-devel linux-c7-zlib-devel-1.2.7 ! CVE-2016-9841 9.8 zlib: Out-of-bounds pointer arithmetic in inffast.c ! CVE-2016-9843 9.8 zlib: Big-endian out-of-bounds pointer ! CVE-2022-37434 9.8 zlib: heap-based buffer over-read and overflow in inflate() in inflate.c via a large gzip ! CVE-2016-9840 8.8 zlib: Out-of-bound pointer arithmetic in inftrees.c ! CVE-2016-9842 8.8 zlib: Undefined left shift of negative number ! CVE-2023-45853 8.8 zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6 ! CVE-2018-25032 7.5 zlib: A flaw found in zlib when compressing (not decompressing) certain inputs ! CVE-2026-27171 2.9 zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions devel/linux-rl9-dbus-libs linux-rl9-dbus-libs-1.12.20_3 ! CVE-2022-42010 6.5 dbus: dbus-daemon crashes when receiving message with incorrectly nested parentheses and c ! CVE-2022-42011 6.5 dbus: dbus-daemon can be crashed by messages with array length inconsistent with element t ! CVE-2022-42012 6.5 dbus: `_dbus_marshal_byteswap` doesn't process fds in messages with "foreign" endianness c ! CVE-2023-34969 6.5 dbus: dbus-daemon: assertion failure when a monitor is active and a message from the drive devel/linux-rl9-libevent linux-rl9-libevent-2.1.12_2 ! CVE-2026-63382 9.2 libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling ! CVE-2026-63385 9.2 Libevent: HTTP header handling bugs create risk of access control bypass. ! CVE-2026-63383 8.7 Libevent: decode_tag_internal() can lead to out-of-bounds read ! CVE-2026-63384 8.7 Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` re ! CVE-2026-63388 8.4 Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via A ! CVE-2026-63387 7.0 Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server res ! CVE-2026-63379 6.3 Libevent: HTTP Header smuggling ! CVE-2026-63381 5.8 Libevent: Dangling Pointer in `evbuffer_add_buffer_reference` ! CVE-2026-63380 5.7 Libevent: Null Pointer Dereference in `evws_new_session` devel/linux-rl9-orc linux-rl9-orc-0.4.31_4 ! CVE-2024-40897 7.0 orc: Stack-based buffer overflow vulnerability in ORC devel/linux-rl9-systemd-libs linux-rl9-systemd-libs-252_13 ! CVE-2026-40225 6.4 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsaniti ! CVE-2026-40226 6.4 systemd: systemd nspawn: Escape-to-host action via crafted config file ! CVE-2022-4415 5.5 systemd: local information leak due to systemd-coredump not respecting fs.suid_dumpable ke ! CVE-2026-29111 5.5 systemd: Local unprivileged user can trigger an assert ! CVE-2025-4598 4.7 Systemd-coredump: race condition that allows a local attacker to crash a suid program and devel/log4net log4net-1.2.10_5 ! CVE-2018-1285 9.8 Apache log4net versions before 2.0.10 do not disable XML external entities when parsing lo ! CVE-2026-40021 6.3 Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescap devel/maven363 maven363-3.6.3_2 ! CVE-2021-26291 9.1 block repositories using http by default devel/mongo-c-driver mongo-c-driver-2.3.3 ! CVE-2026-84964 8.2 Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS cli ! CVE-2026-84963 6.3 Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON ! CVE-2026-84969 6.3 Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output ! CVE-2026-88036 6.1 GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD ! CVE-2026-84965 5.9 Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds ! CVE-2026-88035 5.7 Heap buffer overflow via wrapped size check during SASL username canonicalization in Mongo ! CVE-2026-81524 5.3 Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driv devel/nexus2-oss nexus2-oss-2.15.2_1 ! CVE-2020-10199 8.8 KEV Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). ! CVE-2020-10204 7.2 Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution. ! CVE-2020-10203 4.8 Sonatype Nexus Repository before 3.21.2 allows XSS. devel/node-thrift node-thrift-0.22.0_1 ! CVE-2026-55971 9.3 Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() ! CVE-2026-48144 9.1 Apache Thrift: c_glib TLS Client Missing Hostname Verification ! CVE-2026-41636 8.7 Apache Thrift: Node.js skip() recursion ! CVE-2026-43871 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-c ! CVE-2026-48586 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: ! CVE-2026-55968 8.7 Apache Thrift: Node.js quadratic-time DoS in server receive transports ! CVE-2026-55969 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: ! CVE-2026-58389 8.7 Apache Thrift: Rust binary protocol non-strict path missing string size limit ! CVE-2026-58662 8.7 Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass ! CVE-2026-41604 8.2 Apache Thrift: Swift Range crash in skip() ! CVE-2026-48145 8.2 Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass ! CVE-2025-48431 7.5 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid point ! CVE-2026-41602 7.5 Apache Thrift: Go TFramedTransport uint32 overflow ! CVE-2026-41608 7.5 Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport ! CVE-2026-49158 7.5 Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb ! CVE-2026-41605 7.3 Apache Thrift: Swift Compact Protocol integer overflow ! CVE-2026-43869 7.3 Apache Thrift: TSSLTransportFactory.java hostname verification ! CVE-2026-43870 7.3 Apache Thrift: Node.js web_server.js multi-vulnerability ! CVE-2026-45112 6.9 Apache Thrift: Unbounded Read Leading to Denial of Service ! CVE-2026-55970 6.9 Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() ! CVE-2026-58023 6.9 Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path ! CVE-2026-41607 6.5 Apache Thrift: C++ JSON OOB read ! CVE-2026-66053 5.9 Apache Thrift: Python TSSLSocket Hostname Matcher Import ! CVE-2026-41606 5.3 Apache Thrift: c_glib dispatch stack overflow ! CVE-2026-43868 5.3 Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern devel/open62541 open62541-1.5.5 ! CVE-2026-82623 6.9 open62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange ! CVE-2026-18784 4.8 o6 open62541 ua_client_highlevel.c UA_Client_readNodeClassAttribute heap-based overflow ! CVE-2026-15690 2.3 open62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer deref devel/opengrok opengrok-1.14.1_2 ! CVE-2025-30755 6.1 OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross devel/p5-Storable p5-Storable-3.25 ! CVE-2026-57433 9.8 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a devel/p5-Thrift p5-Thrift-0.22.0_1,1 ! CVE-2026-55971 9.3 Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() ! CVE-2026-48144 9.1 Apache Thrift: c_glib TLS Client Missing Hostname Verification ! CVE-2026-41636 8.7 Apache Thrift: Node.js skip() recursion ! CVE-2026-43871 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-c ! CVE-2026-48586 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: ! CVE-2026-55968 8.7 Apache Thrift: Node.js quadratic-time DoS in server receive transports ! CVE-2026-55969 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: ! CVE-2026-58389 8.7 Apache Thrift: Rust binary protocol non-strict path missing string size limit ! CVE-2026-58662 8.7 Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass ! CVE-2026-41604 8.2 Apache Thrift: Swift Range crash in skip() ! CVE-2026-48145 8.2 Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass ! CVE-2025-48431 7.5 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid point ! CVE-2026-41602 7.5 Apache Thrift: Go TFramedTransport uint32 overflow ! CVE-2026-41608 7.5 Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport ! CVE-2026-49158 7.5 Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb ! CVE-2026-41605 7.3 Apache Thrift: Swift Compact Protocol integer overflow ! CVE-2026-43869 7.3 Apache Thrift: TSSLTransportFactory.java hostname verification ! CVE-2026-43870 7.3 Apache Thrift: Node.js web_server.js multi-vulnerability ! CVE-2026-45112 6.9 Apache Thrift: Unbounded Read Leading to Denial of Service ! CVE-2026-55970 6.9 Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() ! CVE-2026-58023 6.9 Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path ! CVE-2026-41607 6.5 Apache Thrift: C++ JSON OOB read ! CVE-2026-66053 5.9 Apache Thrift: Python TSSLSocket Hostname Matcher Import ! CVE-2026-41606 5.3 Apache Thrift: c_glib dispatch stack overflow ! CVE-2026-43868 5.3 Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern devel/patch patch-2.8 ! CVE-2026-56288 4.6 NULL Pointer Dereference in GNU patch ! CVE-2026-56289 4.6 Loop with Unreachable Exit Condition in GNU patch devel/pear-geshi php84-pear-geshi-geshi-1.0.9.1 ! CVE-2025-2123 5.1 GeSHi CSS cssgen.php get_var cross site scripting devel/php-geshi php-geshi-1.0.9.1_1 ! CVE-2025-2123 5.1 GeSHi CSS cssgen.php get_var cross site scripting devel/pmd pmd-7.21.0_2 ! CVE-2026-28338 6.8 PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation m devel/poco poco-1.13.3 ! CVE-2025-6375 4.8 poco MultipartReader.cpp MultipartInputStream null pointer dereference devel/protobuf protobuf-29.6,1 ! CVE-2026-0994 8.2 Denial of Service in Python Protobuf devel/protobuf25 protobuf25-2.5.0_5 ! CVE-2015-5237 8.8 protobuf: integer overflow in serialization ! CVE-2024-7254 8.7 Stack overflow in Protocol Buffers Java Lite ! CVE-2026-0994 8.2 Denial of Service in Python Protobuf ! CVE-2021-22570 6.5 Nullptr Dereference in Protobuf devel/protobuf3 protobuf3-3.21.12 ! CVE-2024-7254 8.7 Stack overflow in Protocol Buffers Java Lite ! CVE-2026-0994 8.2 Denial of Service in Python Protobuf devel/py-capstone py312-capstone-5.0.9 ! CVE-2026-55893 7.3 Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode ! CVE-2026-55894 6.8 Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode ! CVE-2026-49282 5.1 Capstone M68K and RISCV `cs_insn_name()` invalid IDs can trigger out-of-bounds reads and p ! CVE-2025-67873 4.8 Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow ! CVE-2025-68114 4.8 Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow a ! CVE-2026-49263 2.0 Capstone WASM `br_table` instruction-size truncation can cause no-progress disassembly and devel/py-configobj py312-configobj-5.0.9 ! CVE-2023-26112 3.7 python-configobj: Regular expression denial of service exists in ./src/configobj/validate. devel/py-jupyterlab py312-jupyterlab-4.6.3 ! CVE-2026-73627 6.0 JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass devel/py-lief py312-lief-0.12.3_1 ! CVE-2025-15504 4.8 lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference devel/py-pip py312-pip-23.3.2_4 ! CVE-2026-13346 5.6 pip absolute path traversal during download from malicious package indexes ! CVE-2023-5752 5.5 Mercurial configuration injectable in repo revision when installing via pip ! CVE-2026-6357 5.3 pip self-update functionality can import newly installed modules after wheel installation devel/py-protobuf py312-protobuf-7.36.1,1 ! CVE-2024-7254 8.7 Stack overflow in Protocol Buffers Java Lite ! CVE-2026-0994 8.2 Denial of Service in Python Protobuf devel/py-pydash py312-pydash-4.8.0_1 ! CVE-2023-26145 7.4 This affects versions of the package pydash before 6.0.0. A number of pydash methods such devel/py-setuptools py312-setuptools-63.1.0_3 ! CVE-2025-47273 7.7 setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbit ! CVE-2026-59890 6.1 setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC ! CVE-2022-40897 5.9 pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py devel/py-setuptools44 py27-setuptools44-44.1.1_2 ! CVE-2025-47273 7.7 setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbit ! CVE-2026-59890 6.1 setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC ! CVE-2022-40897 5.9 pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py devel/py-setuptools58 py312-setuptools58-58.5.3_3 ! CVE-2025-47273 7.7 setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbit ! CVE-2026-59890 6.1 setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC ! CVE-2022-40897 5.9 pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py devel/py-twisted py312-twisted-25.5.0 ! CVE-2026-42304 7.5 Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chai devel/py-wheel044 py312-wheel044-0.44.0_1 ! CVE-2026-24049 7.1 wheel Allows Arbitrary File Permission Modification via Path Traversal devel/py-wlc py312-wlc-1.15_2 ! CVE-2026-23535 8.1 wlc Path traversal: Unsanitized API slugs in download command ! CVE-2026-22251 5.3 wlc may leak API keys due to an insecure API key configuration ! CVE-2026-42150 5.1 wlc: print_html outputs API data without HTML escaping, enabling stored XSS ! CVE-2026-22250 2.5 wlc can skip SSL verification devel/pycdc pycdc-g20250704 ! CVE-2022-48078 9.8 pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack ov devel/pycharm pycharm-2026.1.2 ! CVE-2026-65908 8.6 In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python ! CVE-2026-75060 8.4 Unauthenticated Code Execution via Jupyter MCP Tools in JetBrains PyCharm ! CVE-2026-75059 4.4 Code Execution via PyCharm Quick Documentation in Pre‑2026.2.1 Versions devel/radare2 radare2-6.1.4 ! CVE-2026-8695 8.7 radare2 6.1.5 Use-After-Free via gdbr_threads_list() ! CVE-2026-8696 8.7 radare2 6.1.5 Use-After-Free via gdbr_pids_list() ! CVE-2026-40527 8.5 radare2 Command Injection via DWARF Parameter Names ! CVE-2026-14757 4.8 radareorg radare2 cmd_anal.inc core_anal_bytes integer overflow ! CVE-2026-14758 4.8 radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow ! CVE-2026-14759 4.8 radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes_attr_calc_si ! CVE-2026-14760 4.8 radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free ! CVE-2026-14761 4.8 radareorg radare2 str.c r_str_append integer overflow ! CVE-2026-14786 4.8 radareorg radare2 str.c r_str_word_get0set integer overflow ! CVE-2026-14787 4.8 radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow ! CVE-2026-14788 4.8 radareorg radare2 cfile.c r_core_bin_load use after free ! CVE-2026-14789 4.8 radareorg radare2 Memory64ListStream mdmp.c stack-based overflow devel/raylib raylib-6.0 ! CVE-2025-15533 4.8 raysan5 raylib rtext.c GenImageFontAtlas heap-based overflow ! CVE-2025-15534 4.8 raysan5 raylib rtext.c LoadFontData integer overflow devel/resteasy resteasy-3.15.6 ! CVE-2021-20293 6.1 RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack ! CVE-2021-20289 5.3 resteasy: Error message exposes endpoint class information devel/ruby-gems ruby34-gems-4.0.20 ! CVE-2022-36073 8.3 RubyGems allows creation of users with arbitrary unverified emails devel/rubygem-actionview4 rubygem-actionview4-4.2.11.3 ! CVE-2020-5267 4.0 Possible XSS vulnerability in ActionView ! CVE-2026-33168 2.3 Rails has a possible XSS vulnerability in its Action View tag helpers devel/rubygem-actionview5 rubygem-actionview5-5.1.7 ! CVE-2020-5267 4.0 Possible XSS vulnerability in ActionView ! CVE-2026-33168 2.3 Rails has a possible XSS vulnerability in its Action View tag helpers devel/rubygem-actionview50 rubygem-actionview50-5.0.7.2 ! CVE-2020-5267 4.0 Possible XSS vulnerability in ActionView ! CVE-2026-33168 2.3 Rails has a possible XSS vulnerability in its Action View tag helpers devel/rubygem-actionview52 rubygem-actionview52-5.2.8.1 ! CVE-2026-33168 2.3 Rails has a possible XSS vulnerability in its Action View tag helpers devel/rubygem-actionview60 rubygem-actionview60-6.0.6.1 ! CVE-2026-33168 2.3 Rails has a possible XSS vulnerability in its Action View tag helpers devel/rubygem-actionview61 rubygem-actionview61-6.1.7.10 ! CVE-2026-33168 2.3 Rails has a possible XSS vulnerability in its Action View tag helpers devel/rubygem-actionview70 rubygem-actionview70-7.0.10 ! CVE-2026-33168 2.3 Rails has a possible XSS vulnerability in its Action View tag helpers devel/rubygem-actionview71 rubygem-actionview71-7.1.6 ! CVE-2026-33168 2.3 Rails has a possible XSS vulnerability in its Action View tag helpers devel/rubygem-activesupport4 rubygem-activesupport4-4.2.11.3 ! CVE-2023-22796 7.5 rubygem-activesupport: Regular Expression Denial of Service devel/rubygem-activesupport5 rubygem-activesupport5-5.1.7_1 ! CVE-2023-22796 7.5 rubygem-activesupport: Regular Expression Denial of Service devel/rubygem-activesupport50 rubygem-activesupport50-5.0.7.2_1 ! CVE-2023-22796 7.5 rubygem-activesupport: Regular Expression Denial of Service devel/rubygem-activesupport52 rubygem-activesupport52-5.2.8.1 ! CVE-2023-22796 7.5 rubygem-activesupport: Regular Expression Denial of Service devel/rubygem-activesupport60 rubygem-activesupport60-6.0.6.1 ! CVE-2023-22796 7.5 rubygem-activesupport: Regular Expression Denial of Service devel/rubygem-excon-gitlab rubygem-excon-gitlab-1.3.2 ! CVE-2026-54171 6.5 Excon: redact additional sensitive/risky headers when following redirects devel/rubygem-excon0 rubygem-excon0-0.112.0 ! CVE-2026-54171 6.5 Excon: redact additional sensitive/risky headers when following redirects devel/rubygem-excon1-gitlab rubygem-excon1-gitlab-1.2.9 ! CVE-2026-54171 6.5 Excon: redact additional sensitive/risky headers when following redirects devel/rubygem-gems rubygem-gems-2.0.0 ! CVE-2017-0899 9.8 rubygems: Escape sequence in the "summary" field of gemspec ! CVE-2017-0903 9.8 rubygems: Unsafe object deserialization through YAML formatted gem specifications ! CVE-2018-1000076 9.8 rubygems: Improper verification of signatures in tarball allows to install mis-signed gem ! CVE-2022-36073 8.3 RubyGems allows creation of users with arbitrary unverified emails ! CVE-2017-0902 8.1 rubygems: DNS hijacking vulnerability ! CVE-2018-1000074 7.8 rubygems: Unsafe Object Deserialization Vulnerability in gem owner allowing arbitrary code ! CVE-2017-0900 7.5 rubygems: No size limit in summary length of gem spec ! CVE-2017-0901 7.5 rubygems: Arbitrary file overwrite due to incorrect validation of specification name ! CVE-2018-1000073 7.5 rubygems: Path traversal when writing to a symlinked basedir outside of the root ! CVE-2018-1000075 7.5 rubygems: Infinite loop vulnerability due to negative size in tar header causes Denial of ! CVE-2018-1000078 6.1 rubygems: XSS vulnerability in homepage attribute when displayed via gem server ! CVE-2018-1000079 5.5 rubygems: Path traversal issue during gem installation allows to write to arbitrary filesy ! CVE-2018-1000077 5.3 rubygems: Missing URL validation on spec home attribute allows malicious gem to set an inv ! CVE-2015-3900 5.0 rubygems: DNS hijacking vulnerability in api_endpoint() ! CVE-2013-4287 4.3 rubygems: version regex algorithmic complexity vulnerability ! CVE-2013-4363 4.3 rubygems: version regex algorithmic complexity vulnerability, incomplete CVE-2013-4287 fix ! CVE-2015-4020 4.3 rubygems: incomplete fix for CVE-2015-3900 devel/rubygem-gitlab_meta rubygem-gitlab_meta-7.0 ! CVE-2019-9174 10.0 An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x ! CVE-2024-45409 10.0 The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selec ! CVE-2018-14364 9.8 GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x befo ! CVE-2018-17452 9.8 An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x b ! CVE-2018-8971 9.8 The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10. ! CVE-2019-12428 9.8 An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. User ! CVE-2019-9217 9.8 An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x ! CVE-2019-9218 9.8 An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x ! CVE-2019-9485 9.8 An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x ! CVE-2020-10077 9.8 GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a partic ! CVE-2019-5883 9.1 An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Editio ! CVE-2017-12426 8.8 GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0. ! CVE-2018-14603 8.8 An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x b ! CVE-2018-17451 8.8 An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x b ! CVE-2018-18646 8.8 An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x b ! CVE-2019-15589 8.8 An improper access control vulnerability exists in Gitlab ! CVE-2024-7254 8.7 Stack overflow in Protocol Buffers Java Lite ! CVE-2026-0994 8.2 Denial of Service in Python Protobuf devel/rubygem-i18n rubygem-i18n-1.15.2,2 ! CVE-2020-7791 7.5 Denial of Service (DoS) devel/rubygem-netaddr rubygem-netaddr-2.0.1 ! CVE-2019-17383 9.8 The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem devel/rubygem-simple_form rubygem-simple_form-4.0.0 ! CVE-2019-16676 9.8 Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/ devel/rubygem-thrift rubygem-thrift-0.22.0,1 ! CVE-2026-55971 9.3 Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() ! CVE-2026-48144 9.1 Apache Thrift: c_glib TLS Client Missing Hostname Verification ! CVE-2026-41636 8.7 Apache Thrift: Node.js skip() recursion ! CVE-2026-43871 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-c ! CVE-2026-48586 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: ! CVE-2026-55968 8.7 Apache Thrift: Node.js quadratic-time DoS in server receive transports ! CVE-2026-55969 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: ! CVE-2026-58389 8.7 Apache Thrift: Rust binary protocol non-strict path missing string size limit ! CVE-2026-58662 8.7 Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass ! CVE-2026-41604 8.2 Apache Thrift: Swift Range crash in skip() ! CVE-2026-48145 8.2 Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass ! CVE-2025-48431 7.5 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid point ! CVE-2026-41602 7.5 Apache Thrift: Go TFramedTransport uint32 overflow ! CVE-2026-41608 7.5 Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport ! CVE-2026-49158 7.5 Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb ! CVE-2026-41605 7.3 Apache Thrift: Swift Compact Protocol integer overflow ! CVE-2026-43869 7.3 Apache Thrift: TSSLTransportFactory.java hostname verification ! CVE-2026-43870 7.3 Apache Thrift: Node.js web_server.js multi-vulnerability ! CVE-2026-45112 6.9 Apache Thrift: Unbounded Read Leading to Denial of Service ! CVE-2026-55970 6.9 Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() ! CVE-2026-58023 6.9 Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path ! CVE-2026-41607 6.5 Apache Thrift: C++ JSON OOB read ! CVE-2026-66053 5.9 Apache Thrift: Python TSSLSocket Hostname Matcher Import ! CVE-2026-41606 5.3 Apache Thrift: c_glib dispatch stack overflow ! CVE-2026-43868 5.3 Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern devel/rubymine rubymine-2023.1.1_4 ! CVE-2024-37051 9.3 GitHub access token could be exposed to third-party sites in JetBrains IDEs after version ! CVE-2025-43015 8.3 In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all in devel/sdl12 sdl-1.2.15_17,2 ! CVE-2019-14906 9.8 SDL: not fixed in Red Hat Enterprise Linux 7 erratum RHSA-2019:3950 ! CVE-2019-7572 8.8 SDL: buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c ! CVE-2019-7573 8.8 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c ! CVE-2019-7574 8.8 SDL: heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c ! CVE-2019-7575 8.8 SDL: heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c ! CVE-2019-7576 8.8 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c ! CVE-2019-7577 8.8 SDL: buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c ! CVE-2019-7637 8.8 SDL: heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c ! CVE-2019-7638 8.8 SDL: heap-based buffer over-read in Map1toN in video/SDL_pixels.c ! CVE-2019-13616 8.1 SDL: heap-based buffer overflow in SDL blit functions in video/SDL_blit*.c ! CVE-2019-7578 8.1 SDL: heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c ! CVE-2019-7635 8.1 SDL: heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c ! CVE-2019-7636 8.1 SDL: heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c ! CVE-2022-34568 7.5 SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x devel/soapui soapui-5.5.0_2 ! CVE-2019-12180 7.8 An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5 devel/sonarqube-community sonarqube-community-24.12.0.100206_5 ! CVE-2025-62292 4.3 In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privilege devel/spark apache-spark-3.3.4_4 ! CVE-2025-54920 8.8 Apache Spark: Spark History Server Code Execution Vulnerability ! CVE-2025-55039 6.5 Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabl ! CVE-2023-22946 6.4 Apache Spark proxy-user privilege escalation from malicious configuration class ! CVE-2026-32773 6.1 Apache Spark: XSS Vulnerability in Spark Web 3.5.4 devel/t1lib t1lib-5.1.2_5,1 ! CVE-2010-2642 7.6 t1lib: Heap based buffer overflow in DVI file AFM font parser ! CVE-2011-0764 6.8 t1lib: Invalid pointer dereference via crafted Type 1 font ! CVE-2011-1552 4.3 t1lib: invalid read crash via crafted Type 1 font ! CVE-2011-1553 4.3 t1lib: Use-after-free via crafted Type 1 font ! CVE-2011-1554 4.3 t1lib: Off-by-one via crafted Type 1 font devel/thrift thrift-0.22.0,1 ! CVE-2026-55971 9.3 Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() ! CVE-2026-48144 9.1 Apache Thrift: c_glib TLS Client Missing Hostname Verification ! CVE-2026-41636 8.7 Apache Thrift: Node.js skip() recursion ! CVE-2026-43871 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-c ! CVE-2026-48586 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: ! CVE-2026-55968 8.7 Apache Thrift: Node.js quadratic-time DoS in server receive transports ! CVE-2026-55969 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: ! CVE-2026-58389 8.7 Apache Thrift: Rust binary protocol non-strict path missing string size limit ! CVE-2026-58662 8.7 Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass ! CVE-2026-41604 8.2 Apache Thrift: Swift Range crash in skip() ! CVE-2026-48145 8.2 Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass ! CVE-2025-48431 7.5 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid point ! CVE-2026-41602 7.5 Apache Thrift: Go TFramedTransport uint32 overflow ! CVE-2026-41608 7.5 Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport ! CVE-2026-49158 7.5 Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb ! CVE-2026-41605 7.3 Apache Thrift: Swift Compact Protocol integer overflow ! CVE-2026-43869 7.3 Apache Thrift: TSSLTransportFactory.java hostname verification ! CVE-2026-43870 7.3 Apache Thrift: Node.js web_server.js multi-vulnerability ! CVE-2026-45112 6.9 Apache Thrift: Unbounded Read Leading to Denial of Service ! CVE-2026-55970 6.9 Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() ! CVE-2026-58023 6.9 Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path ! CVE-2026-41607 6.5 Apache Thrift: C++ JSON OOB read ! CVE-2026-66053 5.9 Apache Thrift: Python TSSLSocket Hostname Matcher Import ! CVE-2026-41606 5.3 Apache Thrift: c_glib dispatch stack overflow ! CVE-2026-43868 5.3 Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern devel/thrift-c_glib thrift-c_glib-0.22.0,1 ! CVE-2026-55971 9.3 Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() ! CVE-2026-48144 9.1 Apache Thrift: c_glib TLS Client Missing Hostname Verification ! CVE-2026-41636 8.7 Apache Thrift: Node.js skip() recursion ! CVE-2026-43871 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-c ! CVE-2026-48586 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: ! CVE-2026-55968 8.7 Apache Thrift: Node.js quadratic-time DoS in server receive transports ! CVE-2026-55969 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: ! CVE-2026-58389 8.7 Apache Thrift: Rust binary protocol non-strict path missing string size limit ! CVE-2026-58662 8.7 Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass ! CVE-2026-41604 8.2 Apache Thrift: Swift Range crash in skip() ! CVE-2026-48145 8.2 Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass ! CVE-2025-48431 7.5 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid point ! CVE-2026-41602 7.5 Apache Thrift: Go TFramedTransport uint32 overflow ! CVE-2026-41608 7.5 Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport ! CVE-2026-49158 7.5 Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb ! CVE-2026-41605 7.3 Apache Thrift: Swift Compact Protocol integer overflow ! CVE-2026-43869 7.3 Apache Thrift: TSSLTransportFactory.java hostname verification ! CVE-2026-43870 7.3 Apache Thrift: Node.js web_server.js multi-vulnerability ! CVE-2026-45112 6.9 Apache Thrift: Unbounded Read Leading to Denial of Service ! CVE-2026-55970 6.9 Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() ! CVE-2026-58023 6.9 Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path ! CVE-2026-41607 6.5 Apache Thrift: C++ JSON OOB read ! CVE-2026-66053 5.9 Apache Thrift: Python TSSLSocket Hostname Matcher Import ! CVE-2026-41606 5.3 Apache Thrift: c_glib dispatch stack overflow ! CVE-2026-43868 5.3 Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern devel/thrift-cpp thrift-cpp-0.22.0_1,1 ! CVE-2026-55971 9.3 Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() ! CVE-2026-48144 9.1 Apache Thrift: c_glib TLS Client Missing Hostname Verification ! CVE-2026-41636 8.7 Apache Thrift: Node.js skip() recursion ! CVE-2026-43871 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-c ! CVE-2026-48586 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: ! CVE-2026-55968 8.7 Apache Thrift: Node.js quadratic-time DoS in server receive transports ! CVE-2026-55969 8.7 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: ! CVE-2026-58389 8.7 Apache Thrift: Rust binary protocol non-strict path missing string size limit ! CVE-2026-58662 8.7 Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass ! CVE-2026-41604 8.2 Apache Thrift: Swift Range crash in skip() ! CVE-2026-48145 8.2 Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass ! CVE-2025-48431 7.5 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid point ! CVE-2026-41602 7.5 Apache Thrift: Go TFramedTransport uint32 overflow ! CVE-2026-41608 7.5 Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport ! CVE-2026-49158 7.5 Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb ! CVE-2026-41605 7.3 Apache Thrift: Swift Compact Protocol integer overflow ! CVE-2026-43869 7.3 Apache Thrift: TSSLTransportFactory.java hostname verification ! CVE-2026-43870 7.3 Apache Thrift: Node.js web_server.js multi-vulnerability ! CVE-2026-45112 6.9 Apache Thrift: Unbounded Read Leading to Denial of Service ! CVE-2026-55970 6.9 Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() ! CVE-2026-58023 6.9 Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path ! CVE-2026-41607 6.5 Apache Thrift: C++ JSON OOB read ! CVE-2026-66053 5.9 Apache Thrift: Python TSSLSocket Hostname Matcher Import ! CVE-2026-41606 5.3 Apache Thrift: c_glib dispatch stack overflow ! CVE-2026-43868 5.3 Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern devel/wasm3 wasm3-0.5.0_2 ! CVE-2024-34249 9.8 wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation ! CVE-2022-28990 7.8 WASM3 v0.5.0 was discovered to contain a heap overflow via the component /wabt/bin/poc.was ! CVE-2021-38592 7.5 Wasm3 0.5.0 has a heap-based buffer overflow in op_Const64 (called from EvaluateExpression ! CVE-2022-39974 7.5 WASM3 v0.5.0 was discovered to contain a segmentation fault via the component op_Select_i3 ! CVE-2024-34246 7.5 wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmenta ! CVE-2024-34252 7.5 wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentatio ! CVE-2021-45929 5.5 Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from CompileElseBlock and C ! CVE-2021-45946 5.5 Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from Compile_LoopOrBlock an ! CVE-2021-45947 5.5 Wasm3 0.5.0 has an out-of-bounds write in Runtime_Release (called from EvaluateExpression ! CVE-2022-28966 5.5 Wasm3 0.5.0 has a heap-based buffer overflow in NewCodePage in m3_code.c (called indirectl ! CVE-2022-34529 5.5 WASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memo ! CVE-2025-15413 4.8 wasm3 m3_exec.h op_CallIndirect memory corruption ! CVE-2025-15572 4.8 wasm3 NewCodePage memory leak ! CVE-2025-6272 4.8 wasm3 m3_compile.c MarkSlotAllocated out-of-bounds write devel/xdg-utils xdg-utils-1.2.1 ! CVE-2020-27748 6.5 xdg-utils: local file inclusion vulnerability devel/zookeeper zookeeper-3.8.3_2 ! CVE-2026-24308 6.5 Apache ZooKeeper: Sensitive information disclosure in client configuration handling ! CVE-2026-24281 5.9 Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper Z ! CVE-2024-23944 5.3 Apache ZooKeeper: Information disclosure in persistent watcher handling dns/dnsdist dnsdist-2.1.2 ! CVE-2025-30193 7.5 Denial of service via crafted TCP exchange dns/hesiod hesiod-3.2.1_5 ! CVE-2016-10152 9.8 hesiod: Use of hard-coded unsafe configuration if configuration file cannot be opened ! CVE-2016-10151 7.0 hesiod: Weak SUID check allowing privilege elevation dns/maradns maradns-3.5.0036 ! CVE-2026-40719 7.5 Deadwood Exploit Causing Connection Slot Exhaustion in MaraDNS dns/powerdns-recursor powerdns-recursor-5.4.6_1 ! CVE-2025-30192 7.5 A Recursor configured to send out ECS enabled queries can be sensitive to spoofing attempt ! CVE-2026-52684 3.7 Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack editors/vim vim-9.2.0738 ! CVE-2026-34714 9.2 vim: Vim: Arbitrary code execution via crafted file ! CVE-2026-73078 8.6 Vim: Arbitrary Code Execution via Netrw Menu Construction ! CVE-2026-73072 8.5 Vim: Heap Buffer Overflow when Loading a Spell File ! CVE-2026-51400 8.4 vim: Vim: Arbitrary code execution via vms_fixfilename() function ! CVE-2026-57456 8.4 Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings ! CVE-2026-59856 8.4 Vim: Arbitrary Code Execution via PHP Omni-Completion ! CVE-2026-59858 8.4 Vim: Arbitrary Code Execution via C Omni-Completion ! CVE-2026-73076 8.4 Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.v ! CVE-2026-73077 8.4 Vim: Arbitrary Code Execution via Shell Keyword Lookup ! CVE-2026-34982 8.2 Vim modeline bypass via various options affects Vim < 9.2.0276 ! CVE-2026-43961 7.8 Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() filter() expres ! CVE-2026-51401 7.7 vim: Vim: Arbitrary code execution via vms_fixfilename() function ! CVE-2026-52860 7.5 Vim: Arbitrary Code Execution via Python Omni-Completion ! CVE-2026-47162 7.3 Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name ! CVE-2026-52858 7.3 Vim: Arbitrary Code Execution via Python Omni-Completion ! CVE-2026-73073 7.1 Vim: Arbitrary Ex Command Execution in C Omni-Completion ! CVE-2026-73074 7.1 Vim: Heap Buffer Overflow in Text Property Handling ! CVE-2026-52859 6.9 Vim: Out-of-bounds Read in Terminal Screen Snapshot ! CVE-2026-73070 6.8 Vim: Stack Buffer Overflow in the Vim Socket Server ! CVE-2026-41411 6.6 Vim: Command injection via backtick expansion in tag filenames ! CVE-2026-45130 6.6 Vim: Heap Buffer Overflow in spell file loading ! CVE-2026-57453 6.5 Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction ! CVE-2026-55693 5.7 Vim: Out-of-bounds Write in Spell File Word Count ! CVE-2026-55895 5.7 Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename ! CVE-2026-33412 5.6 Vim affected by Command injection via newline in glob() ! CVE-2026-59857 5.6 Vim: Out-of-bounds Write in SAL Soundfolding ! CVE-2026-55892 5.5 Vim: Out-of-bounds Write in Spell File Prefix Dump ! CVE-2026-57452 5.5 Vim: Out-of-bounds Read with libsodium-encrypted Files ! CVE-2026-28419 5.3 Vim has Heap-based Buffer Underflow in Emacs tags parsing ! CVE-2026-28421 5.3 Vim has a heap-buffer-overflow and a segmentation fault ! CVE-2026-32249 5.3 NFA regex engine NULL pointer dereference affects Vim < 9.2.0137 ! CVE-2026-57451 5.3 Vim: Out-of-bounds Read in Text Property Count ! CVE-2026-47167 5.1 Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition rege ! CVE-2026-39881 5.0 Vim Ex command injection in Vims NetBeans integration ! CVE-2026-44656 4.6 Vim: OS Command Injection via 'path' completion ! CVE-2026-28417 4.4 Vim has OS Command Injection in netrw ! CVE-2026-28418 4.4 Vim has Heap-based Buffer Overflow in Emacs tags parsing ! CVE-2026-28420 4.4 Vim has Heap-based Buffer Overflow and OOB Read in :terminal ! CVE-2026-42307 4.4 Vim: OS Command Injection in netrw ! CVE-2026-35177 4.1 Path traversal issue with zip.vim in Vim ! CVE-2026-57455 4.0 Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold() ! CVE-2026-46483 3.6 Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag ! CVE-2026-28422 2.2 Vim has stack-buffer-overflow in build_stl_str_hl() emulators/qemu qemu-11.1.1 ! CVE-2024-6519 8.2 Qemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerability ! CVE-2023-2680 7.5 Dma reentrancy issue (incomplete fix for cve-2021-3750) ! CVE-2023-3354 7.5 Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of s ! CVE-2023-3180 6.0 Heap buffer overflow in virtio_crypto_sym_op_helper() ! CVE-2024-8354 5.5 Qemu-kvm: usb: assertion failure in usb_ep_get() ! CVE-2023-1386 3.3 Qemu: 9pfs: suid/sgid bits not dropped on file write emulators/qemu-cheri qemu-cheri-0.d20260108 ! CVE-2015-8556 10.0 Qemu: virtfs: local privilege escalation via virtfs-proxy-helper ! CVE-2017-16845 10.0 Qemu: ps2: information leakage via post_load routine ! CVE-2009-3616 9.9 Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earl ! CVE-2016-4002 9.8 Qemu: net: buffer overflow in MIPSnet emulator ! CVE-2016-7161 9.8 Qemu: net: xilinx_ethlite: heap buffer overflow in eth_rx ! CVE-2018-17963 9.8 QEMU: net: ignore packets with large size ! CVE-2012-6075 9.3 qemu: e1000 driver buffer overflow when processing large packets when SBP and LPE flags ar ! CVE-2015-7512 9.0 Qemu: net: pcnet: buffer overflow in non-loopback mode ! CVE-2017-7471 9.0 Qemu: 9p: virtfs allows guest to change filesystem attributes on host ! CVE-2013-4535 8.8 qemu: virtio: insufficient validation of num_sg when mapping ! CVE-2015-7504 8.8 Qemu: net: pcnet: heap overflow vulnerability in pcnet_receive ! CVE-2016-1568 8.8 Qemu: ide: ahci use-after-free vulnerability in aio port commands ! CVE-2016-3710 8.8 qemu: incorrect banked access bounds checking in vga module ! CVE-2017-14167 8.8 Qemu: i386: multiboot OOB access while loading kernel image ! CVE-2017-5931 8.8 Qemu: virtio: integer overflow in handling virtio-crypto requests ! CVE-2018-7550 8.8 QEMU: i386: multiboot OOB access while loading kernel image ! CVE-2022-1050 8.8 QEMU: pvrdma: use-after-free issue in pvrdma_exec_cmd() ! CVE-2024-24474 8.8 QEMU: esp: integer underflow leads to heap buffer overflow in esp_do_nodma() ! CVE-2014-0144 8.6 Qemu: block: missing input validation ! CVE-2015-1779 8.6 qemu: vnc: insufficient resource limiting in VNC websockets decoder ! CVE-2016-4001 8.6 Qemu: net: buffer overflow in stellaris_enet emulator ! CVE-2022-3872 8.6 QEMU: sdhci: buffer data port register off-by-one read/write ! CVE-2021-3682 8.5 QEMU: usbredir: free() call on invalid pointer in bufp_alloc() ! CVE-2016-2857 8.4 Qemu: net: out of bounds read in net_checksum_calculate() ! CVE-2017-15118 8.3 Qemu: stack buffer overflow in NBD server triggered via long export name ! CVE-2018-11806 8.2 QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams ! CVE-2021-3546 8.2 QEMU: vhost-user-gpu: out-of-bounds write in virgl_cmd_get_capset() ! CVE-2021-3750 8.2 QEMU: hcd-ehci: DMA reentrancy issue leads to use-after-free ! CVE-2021-3929 8.2 QEMU: nvme: DMA reentrancy issue leads to use-after-free ! CVE-2021-4206 8.2 QEMU: QXL: integer overflow in cursor_alloc() can lead to heap buffer overflow ! CVE-2021-4207 8.2 QEMU: QXL: double fetch in qxl_cursor() can lead to heap buffer overflow ! CVE-2024-6519 8.2 Qemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerability ! CVE-2016-1714 8.1 Qemu: nvram: OOB r/w access in processing firmware configurations ! CVE-2015-8666 7.9 Qemu: acpi: heap based buffer overrun during VM migration ! CVE-2013-4536 7.8 qemu: virtio: insufficient validation of num_sg when mapping ! CVE-2014-0145 7.8 Qemu: prevent possible buffer overflows ! CVE-2016-5126 7.8 Qemu: block: iscsi: buffer overflow in iscsi_aio_ioctl ! CVE-2016-5338 7.8 Qemu: scsi: esp: OOB r/w access while processing ESP_FIFO ! CVE-2017-7493 7.8 Qemu: 9pfs: guest privilege escalation in virtfs mapped-file mode ! CVE-2017-7980 7.8 Qemu: display: cirrus: OOB r/w access issues in bitblt routines ! CVE-2018-16847 7.8 QEMU: nvme: Out-of-bounds r/w buffer access in cmb operations ! CVE-2018-16867 7.8 QEMU: dev-mtp: path traversal in usb_mtp_write_data of the Media Transfer Protocol (MTP) ! CVE-2022-0358 7.8 QEMU: virtiofsd: potential privilege escalation via CVE-2018-13405 ! CVE-2015-3456 7.7 qemu: fdc: out-of-bounds fifo buffer memory access ! CVE-2015-8567 7.7 Qemu: net: vmxnet3: host memory leakage ! CVE-2016-9602 7.6 Qemu: 9p: virtfs allows guest to access host filesystem ! CVE-2013-4526 7.5 qemu: ahci: fix buffer overrun on invalid state load ! CVE-2013-4527 7.5 qemu: hpet: buffer overrun on invalid state load ! CVE-2013-4529 7.5 qemu: hw/pci/pcie_aer.c: buffer overrun on invalid state load ! CVE-2013-4530 7.5 qemu: pl022: fix buffer overun on invalid state load ! CVE-2013-4531 7.5 qemu: target-arm/machine.c: fix buffer overflow on invalid state load ! CVE-2013-4533 7.5 qemu: pxa2xx: buffer overrun on incoming migration ! CVE-2013-4534 7.5 qemu: openpic: buffer overrun on incoming migration ! CVE-2013-4537 7.5 qemu: ssi-sd: buffer overrun on invalid state load ! CVE-2013-4538 7.5 qemu: ssd0323: fix buffer overun on invalid state load ! CVE-2013-4539 7.5 qemu: tsc210x: buffer overrun on invalid state load ! CVE-2013-4540 7.5 qemu: zaurus: buffer overrun on invalid state load ! CVE-2013-4541 7.5 qemu: usb: insufficient sanity checking of setup_index+setup_len in post_load ! CVE-2013-4542 7.5 qemu: virtio-scsi: buffer overrun on invalid state load ! CVE-2013-6399 7.5 qemu: virtio: buffer overrun on incoming migration ! CVE-2014-0182 7.5 qemu: virtio: out-of-bounds buffer write on state load with invalid config_len ! CVE-2014-0222 7.5 Qemu: qcow1: validate L2 table size to avoid integer overflows ! CVE-2014-7840 7.5 qemu: insufficient parameter validation during ram load ! CVE-2015-3209 7.5 qemu: pcnet: multi-tmd buffer overflow in the tx path ! CVE-2015-6855 7.5 Qemu: ide: divide by zero issue ! CVE-2015-8619 7.5 Qemu: hmp: stack based OOB write in hmp_sendkey routine ! CVE-2016-9381 7.5 xen: qemu incautious about shared ring processing (XSA-197) ! CVE-2017-10664 7.5 Qemu: qemu-nbd: server breaks with SIGPIPE upon client abort ! CVE-2017-13711 7.5 QEMU: Slirp: use-after-free when sending response ! CVE-2017-15124 7.5 Qemu: memory exhaustion through framebuffer update request message in VNC server ! CVE-2017-15268 7.5 QEMU: I/O: potential memory exhaustion via websock connection to VNC ! CVE-2017-6058 7.5 Qemu: net: vmxnet3: OOB NetRxPkt::ehdr_buf access when doing vlan stripping ! CVE-2017-8309 7.5 Qemu: audio: host memory leakage via capture buffer ! CVE-2017-9524 7.5 Qemu: nbd: segmentation fault due to client non-negotiation ! CVE-2018-12617 7.5 Qemu: qemu-guest-agent: Integer overflow causes segmentation fault in qmp_guest_file_read( ! CVE-2018-17958 7.5 QEMU: rtl8139: integer overflow leads to buffer overflow ! CVE-2018-20125 7.5 QEMU: pvrdma: null dereference or excessive memory allocation when creating QP/CQ ! CVE-2018-20191 7.5 QEMU: pvrdma: uar_read leads to NULL dereference ! CVE-2018-20216 7.5 QEMU: pvrdma: infinite loop in pvrdma_qp_send/recv ! CVE-2021-20181 7.5 qemu: 9pfs: TOCTOU privilege escalation vulnerability ! CVE-2023-2680 7.5 Dma reentrancy issue (incomplete fix for cve-2021-3750) ! CVE-2023-3354 7.5 Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of s ! CVE-2011-2212 7.4 qemu-kvm: virtqueue: too-large indirect descriptor buffer overflow ! CVE-2021-3713 7.4 QEMU: out-of-bounds write in UAS (USB Attached SCSI) device emulation ! CVE-2024-7730 7.4 Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb() ! CVE-2010-0297 7.2 kvm-userspace-rhel5: usb-linux.c: fix buffer overflow ! CVE-2012-3515 7.2 qemu: VT100 emulation vulnerability ! CVE-2013-4344 7.2 qemu: buffer overflow in scsi_target_emulate_report_luns ! CVE-2014-2894 7.2 QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART ! CVE-2014-3689 7.2 qemu: vmware_vga: insufficient parameter validation in rectangle functions ! CVE-2015-5154 7.2 qemu: ide: atapi: heap overflow during I/O buffer memory access ! CVE-2015-5225 7.2 Qemu: ui: vnc: heap memory corruption in vnc_refresh_server_surface ! CVE-2015-5279 7.2 qemu: Heap overflow vulnerability in ne2000_receive() function ! CVE-2015-8743 7.1 Qemu: net: ne2000: OOB memory access in ioport r/w functions ! CVE-2016-2538 7.1 Qemu: usb: integer overflow in remote NDIS control message handling ! CVE-2014-0143 7.0 Qemu: block: multiple integer overflow flaws ! CVE-2015-3214 6.9 qemu/kvm: i8254: out-of-bounds memory access in pit_ioport_read function ! CVE-2011-4111 6.8 qemu: ccid: buffer overflow in handling of VSC_ATR message ! CVE-2016-4439 6.7 Qemu: scsi: esp: OOB write while writing to 's->cmdbuf' in esp_reg_write ! CVE-2016-6351 6.7 Qemu: scsi: esp: OOB write access in esp_do_dma ! CVE-2020-13754 6.7 QEMU: msix: OOB access during mmio operations may lead to DoS ! CVE-2020-35506 6.7 QEMU: use after free vulnerability in esp_do_dma() in hw/scsi/esp.c ! CVE-2015-5239 6.5 qemu-kvm: Integer overflow in vnc_client_read() and protocol_client_msg() ! CVE-2015-5278 6.5 qemu: Infinite loop in ne2000_receive() function ! CVE-2015-5745 6.5 kernel: qemu buffer overflow in virtio-serial ! CVE-2015-8345 6.5 Qemu: net: eepro100: infinite loop in processing command block list ! CVE-2015-8504 6.5 Qemu: ui: vnc: avoid floating point exception ! CVE-2015-8568 6.5 Qemu: net: vmxnet3: host memory leakage ! CVE-2015-8613 6.5 Qemu: scsi: stack based buffer overflow in megasas_ctrl_get_info ! CVE-2015-8701 6.5 Qemu: net: rocker: stack buffer overflow(off-by-one) in tx_consume routine ! CVE-2016-2858 6.5 Qemu: rng-random: arbitrary stack based allocation leading to corruption ! CVE-2016-4020 6.5 Qemu: i386: leakage of stack memory to guest in kvmvapic.c ! CVE-2016-9845 6.5 Qemu: display: virtio-gpu-3d: information leakage in virgl_cmd_get_capset_info ! CVE-2016-9846 6.5 Qemu: display: virtio-gpu: memory leakage while updating cursor data ! CVE-2016-9907 6.5 Qemu: usb: redirector: memory leakage when destroying redirector ! CVE-2016-9911 6.5 Qemu: usb: ehci: memory leakage in ehci_init_transfer ! CVE-2016-9912 6.5 Qemu: display: virtio-gpu: memory leakage when destroying gpu resource ! CVE-2016-9913 6.5 Qemu: 9pfs: memory leakage via proxy/handle callbacks ! CVE-2016-9914 6.5 Qemu: 9pfs: memory leakage via proxy/handle callbacks ! CVE-2016-9915 6.5 Qemu: 9pfs: memory leakage via proxy/handle callbacks ! CVE-2016-9916 6.5 Qemu: 9pfs: memory leakage via proxy/handle callbacks ! CVE-2016-9921 6.5 Qemu: display: cirrus_vga: a divide by zero in cirrus_do_copy ! CVE-2017-12809 6.5 Qemu: ide: flushing of empty CDROM drives leads to NULL dereference ! CVE-2017-17381 6.5 Qemu: virtio: divide by zero exception while updating rings ! CVE-2017-5525 6.5 Qemu: audio: memory leakage in ac97 device ! CVE-2017-5526 6.5 Qemu: audio: memory leakage in es1370 device ! CVE-2017-5552 6.5 Qemu: display: virtio-gpu-3d: memory leakage in virgl_resource_attach_backing ! CVE-2017-5578 6.5 Qemu: display: virtio-gpu: host memory leakage in virtio_gpu_resource_attach_backing ! CVE-2017-5579 6.5 Qemu: serial: host memory leakage 16550A UART emulation ! CVE-2017-5667 6.5 Qemu: sd: sdhci OOB access during multi block SDMA transfer ! CVE-2017-5856 6.5 Qemu: scsi: megasas: host memory leakage in megasas_handle_dcmd ! CVE-2017-5857 6.5 Qemu: display: virtio-gpu-3d: host memory leakage in virgl_cmd_resource_unref ! CVE-2017-6505 6.5 Qemu: usb: an infinite loop issue in ohci_service_ed_list ! CVE-2017-8086 6.5 Qemu: 9pfs: host memory leakage via v9pfs_list_xattr ! CVE-2017-8112 6.5 Qemu: scsi: vmw_pvscsi: infinite loop in pvscsi_log2 ! CVE-2017-8379 6.5 Qemu: input: host memory lekage via keyboard events ! CVE-2018-10839 6.5 QEMU: ne2000: integer overflow leads to buffer overflow issue ! CVE-2020-27661 6.5 QEMU: divide by zero in dwc2_handle_packet() in hw/usb/hcd-dwc2.c ! CVE-2021-20257 6.5 QEMU: net: e1000: infinite loop while processing transmit descriptors ! CVE-2021-20295 6.5 QEMU: Regression of CVE-2020-10756 fix in virt:rhel/qemu-kvm in Red Hat Enterprise Linux 8 ! CVE-2021-3544 6.5 QEMU: vhost-user-gpu: multiple memory leaks ! CVE-2021-3545 6.5 QEMU: vhost-user-gpu: information disclosure due to uninitialized memory read ! CVE-2021-3582 6.5 QEMU: pvrdma: unproperly mremap in pvrdma_map_to_pdir() ! CVE-2021-3611 6.5 QEMU: intel-hda: segmentation fault due to stack overflow ! CVE-2021-3930 6.5 QEMU: off-by-one error in mode_sense_page() in hw/scsi/scsi-disk.c ! CVE-2022-4144 6.5 QEMU: QXL: qxl_phys2virt unsafe address translation can lead to out-of-bounds read ! CVE-2023-3255 6.5 Qemu: vnc: infinite loop in inflate_buffer() leads to denial of service ! CVE-2023-5088 6.4 Qemu: improper ide controller reset can lead to mbr overwrite ! CVE-2020-17380 6.3 QEMU: heap buffer overflow in sdhci_sdma_transfer_multi_blocks() in hw/sd/sdhci.c ! CVE-2014-0147 6.2 Qemu: block: possible crash due signed types or logic error ! CVE-2021-3507 6.1 QEMU: fdc: heap buffer overflow in DMA read data transfers ! CVE-2015-7549 6.0 Qemu: pci: null pointer dereference issue ! CVE-2016-10155 6.0 Qemu: watchdog: memory leakage in virtual hardware watchdog wdt_i6300esb ! CVE-2016-2841 6.0 Qemu: net: ne2000: infinite loop in ne2000_receive ! CVE-2016-4037 6.0 Qemu: usb: Infinite loop vulnerability in usb_ehci using siTD process ! CVE-2016-4441 6.0 Qemu: scsi: esp: OOB write while writing to 's->cmdbuf' in get_cmd ! CVE-2016-4454 6.0 Qemu: display: vmsvga: out-of-bounds read in vmsvga_fifo_read_raw() routine ! CVE-2016-4952 6.0 Qemu: scsi: pvscsi: out-of-bounds access issue in pvsci_ring_init_msg/data routines ! CVE-2016-4964 6.0 Qemu: scsi: mptsas infinite loop in mptsas_fetch_requests ! CVE-2016-5106 6.0 Qemu: scsi: megasas: out-of-bounds write while setting controller properties ! CVE-2016-5107 6.0 Qemu: scsi: megasas: out-of-bounds read in megasas_lookup_frame() function ! CVE-2016-6835 6.0 Qemu: net: vmxnet: buffer overflow in vmxnet_tx_pkt_parse_headers() in vmxnet3 device emul ! CVE-2016-6836 6.0 Qemu: net: vmxnet: Information leakage in vmxnet3_complete_packet ! CVE-2016-7116 6.0 Qemu: 9p: directory traversal flaw in 9p virtio backend ! CVE-2016-7422 6.0 Qemu: virtio: null pointer dereference in virtqueu_map_desc ! CVE-2016-7466 6.0 Qemu: usb: xhci memory leakage during device unplug ! CVE-2016-7994 6.0 Qemu: virtio-gpu: memory leak in virtio_gpu_resource_create_2d ! CVE-2016-7995 6.0 Qemu: usb: hcd-ehci: memory leak in ehci_process_itd ! CVE-2016-8576 6.0 Qemu: usb: xHCI: infinite loop vulnerability in xhci_ring_fetch ! CVE-2016-8577 6.0 Qemu: 9pfs: host memory leakage in v9fs_read ! CVE-2016-8578 6.0 Qemu: 9pfs: potential NULL dereferencein 9pfs routines ! CVE-2016-8667 6.0 Qemu: hw: dma: divide by zero error in set_next_tick ! CVE-2016-8668 6.0 Qemu: net: OOB buffer access in rocker switch emulation ! CVE-2016-8669 6.0 Qemu: char: divide by zero error in serial_update_parameters ! CVE-2016-8909 6.0 Qemu: audio: intel-hda: infinite loop in processing dma buffer stream ! CVE-2016-8910 6.0 Qemu: net: rtl8139: infinite loop while transmit in C+ mode ! CVE-2016-9101 6.0 Qemu: net: eepro100 memory leakage at device unplug ! CVE-2016-9102 6.0 Qemu: 9pfs: memory leakage when creating extended attribute ! CVE-2016-9103 6.0 Qemu: 9pfs: information leakage via xattr ! CVE-2016-9105 6.0 Qemu: 9pfs: memory leakage in v9fs_link ! CVE-2016-9106 6.0 Qemu: 9pfs: memory leakage in v9fs_write ! CVE-2017-15289 6.0 Qemu: cirrus: OOB access issue in mode4and5 write functions ! CVE-2017-7377 6.0 Qemu: 9pfs: host memory leakage via v9fs_create ! CVE-2018-5683 6.0 Qemu: Out-of-bounds read in vga_draw_text routine ! CVE-2020-27821 6.0 QEMU: heap buffer overflow in msix_table_mmio_write() in hw/pci/msix.c ! CVE-2020-35503 6.0 QEMU: NULL pointer dereference issue in megasas-gen2 host bus adapter ! CVE-2020-35504 6.0 QEMU: NULL pointer dereference in scsi_req_continue() in hw/scsi/scsi-bus.c ! CVE-2021-20221 6.0 qemu: out-of-bound heap buffer access via an interrupt ID field ! CVE-2021-3416 6.0 QEMU: net: Infinite loop in loopback mode may lead to stack overflow ! CVE-2021-3607 6.0 QEMU: pvrdma: unchecked malloc size due to integer overflow in init_dev_ring() ! CVE-2021-3608 6.0 QEMU: pvrdma: uninitialized memory unmap in pvrdma_ring_init() ! CVE-2023-1544 6.0 Qemu: pvrdma: out-of-bounds read in pvrdma_ring_next_elem_read() ! CVE-2023-2861 6.0 Qemu: 9pfs: improper access control on special files ! CVE-2023-3019 6.0 Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest() ! CVE-2023-3180 6.0 Heap buffer overflow in virtio_crypto_sym_op_helper() ! CVE-2017-15119 5.8 qemu: DoS via large option request ! CVE-2018-19665 5.7 Qemu: bt: Integer overflow in Bluetooth routines allows memory corruption ! CVE-2021-3409 5.7 QEMU: sdhci: incomplete fix for CVE-2020-17380/CVE-2020-25085 ! CVE-2017-15038 5.6 Qemu: 9p: virtfs: information disclosure when reading extended attributes ! CVE-2017-9310 5.6 Qemu: net: infinite loop in e1000e NIC emulation ! CVE-2017-9330 5.6 Qemu: usb: ohci: infinite loop due to incorrect return value ! CVE-2023-3301 5.6 Triggerable assertion due to race condition in hot-unplug ! CVE-2014-0142 5.5 qemu: crash by possible division by zero ! CVE-2014-0146 5.5 Qemu: qcow2: NULL dereference in qcow2_open() error path ! CVE-2014-0148 5.5 Qemu: vhdx: bounds checking for block_size and logical_sector_size ! CVE-2014-3471 5.5 Qemu: hw: pci: use after free triggered via guest ! CVE-2015-8558 5.5 Qemu: usb: infinite loop in ehci_advance_state results in DoS ! CVE-2015-8744 5.5 Qemu: net: vmxnet3: incorrect l2 header validation leads to a crash via assert(2) call ! CVE-2015-8745 5.5 Qemu: net: vmxnet3: reading IMR registers leads to a crash via assert(2) call ! CVE-2015-8818 5.5 Qemu: OOB access in address_space_rw leads to segmentation fault ! CVE-2016-10028 5.5 Qemu: display: virtio-gpu-3d: OOB access while reading virgl capabilities ! CVE-2016-10029 5.5 Qemu: display: virtio-gpu: out of bounds read in virtio_gpu_set_scanout ! CVE-2016-1922 5.5 Qemu: i386: null pointer dereference in vapic_write() ! CVE-2016-1981 5.5 Qemu: net: e1000 infinite loop in start_xmit and e1000_receive_iov routines ! CVE-2016-2197 5.5 Qemu: ide: ahci null pointer dereference when using FIS CLB engines ! CVE-2016-2198 5.5 Qemu: usb: ehci null pointer dereference in ehci_caps_write ! CVE-2016-3712 5.5 qemu-kvm: Out-of-bounds read when creating weird vga screen surface ! CVE-2016-5337 5.5 Qemu: scsi: megasas: information leakage in megasas_ctrl_get_info ! CVE-2016-5403 5.5 Qemu: virtio: unbounded memory allocation on host via guest leading to DoS ! CVE-2016-9603 5.5 Qemu: cirrus: heap buffer overflow via vnc connection ! CVE-2016-9776 5.5 Qemu: net: mcf_fec: infinite loop while receiving data in mcf_fec_receive ! CVE-2016-9922 5.5 Qemu: display: cirrus_vga: a divide by zero in cirrus_do_copy ! CVE-2016-9923 5.5 Qemu: char: use-after-free issue during hotplug and unplugging device ! CVE-2017-10806 5.5 Qemu: usb-redirect: stack buffer overflow in debug logging ! CVE-2017-11434 5.5 Qemu: slirp: out-of-bounds read while parsing dhcp options ! CVE-2017-13672 5.5 QEMU: vga: OOB read access during display update ! CVE-2017-2615 5.5 Qemu: display: cirrus: oob access while doing bitblt copy backward mode ! CVE-2017-2620 5.5 Qemu: display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo ! CVE-2017-2630 5.5 Qemu: nbd: oob stack write in client routine drop_sync ! CVE-2017-5898 5.5 Qemu: usb: integer overflow in emulated_apdu_from_guest ! CVE-2017-5973 5.5 Qemu: usb: infinite loop while doing control transfer in xhci_kick_epctx ! CVE-2017-5987 5.5 Qemu: sd: infinite loop issue in multi block transfers ! CVE-2017-7718 5.5 Qemu: display: cirrus: OOB read access issue ! CVE-2017-9060 5.5 Qemu: virtio-gpu: host memory leakage in Virtio GPU device ! CVE-2017-9373 5.5 Qemu: ide: ahci host memory leakage during hotunplug ! CVE-2017-9374 5.5 Qemu: usb: ehci host memory leakage during hotunplug ! CVE-2017-9375 5.5 Qemu: usb: xhci infinite recursive call via xhci_kick_ep ! CVE-2017-9503 5.5 Qemu: scsi: megasas: null pointer dereference while processing megasas command ! CVE-2018-15746 5.5 QEMU: seccomp: blacklist is not applied to all threads ! CVE-2018-18954 5.5 QEMU: ppc64: Out-of-bounds r/w stack access in pnv_lpc_do_eccb ! CVE-2018-19364 5.5 Qemu: 9pfs: Use-after-free due to race condition while updating fid path ! CVE-2018-20123 5.5 QEMU: pvrdma: memory leakage in device hotplug ! CVE-2018-20124 5.5 QEMU: rdma: OOB access when building scatter-gather array ! CVE-2018-20126 5.5 QEMU: pvrdma: memory leakage when creating cq/qp ! CVE-2018-7858 5.5 QEMU: cirrus: OOB access when updating VGA display ! CVE-2020-13253 5.5 QEMU: sd: OOB access could crash the guest resulting in DoS ! CVE-2020-13791 5.5 QEMU: ati-vga: OOB access while reading PCI configuration may lead to DoS ! CVE-2020-24352 5.5 QEMU: out-of-bounds read/write in ati-vga device emulation in ati_2d_blt() ! CVE-2021-3527 5.5 QEMU: usb: unbounded stack allocation in usbredir ! CVE-2023-42467 5.5 QEMU: am53c974: denial of service due to division by zero ! CVE-2024-8354 5.5 Qemu-kvm: usb: assertion failure in usb_ep_get() ! CVE-2017-2633 5.4 Qemu: VNC: memory corruption due to unchecked resolution limit ! CVE-2017-7539 5.3 Qemu: qemu-nbd crashes due to undefined I/O coroutine ! CVE-2018-16872 5.3 QEMU: usb-mtp: path traversal by host filesystem manipulation in Media Transfer Protocol ( ! CVE-2020-15863 5.3 QEMU: stack-based overflow in xgmac_enet_send() in hw/net/xgmac.c ! CVE-2023-0330 5.3 Qemu: lsi53c895a: dma reentrancy issue leads to stack overflow ! CVE-2008-2382 5.0 qemu/kvm: remote DoS (infinite loop) via specially-crafted VNC message received by the dom ! CVE-2014-7815 5.0 qemu: vnc: insufficient bits_per_pixel from the client sanitization ! CVE-2015-7295 5.0 Qemu: net: virtio-net possible remote DoS ! CVE-2016-2391 5.0 Qemu: usb: multiple eof_timers in ohci module leads to null pointer dereference ! CVE-2020-10761 5.0 QEMU: nbd: reachable assertion failure in nbd_negotiate_send_rep_verr via remote client ! CVE-2020-14364 5.0 QEMU: usb: out-of-bounds r/w access issue while processing usb packets ! CVE-2013-4544 4.9 Qemu: vmxnet3: bounds checking buffer overrun ! CVE-2014-0150 4.9 qemu: virtio-net: buffer overflow in virtio_net_handle_mac() function ! CVE-2023-6693 4.9 Qemu: virtio-net: stack buffer overflow in virtio_net_flush_tx() ! CVE-2018-19489 4.7 QEMU: 9pfs: crash due to race condition in renaming files ! CVE-2014-0223 4.6 Qemu: qcow1: validate image size to avoid out-of-bounds memory access ! CVE-2014-5388 4.6 Qemu: out of bounds memory access ! CVE-2014-8106 4.6 qemu: cirrus: insufficient blit region checks ! CVE-2015-4106 4.6 xen: unmediated PCI register access in qemu (xsa-131) ! CVE-2016-4453 4.4 Qemu: display: vmsvga: infinite loop in vmsvga_fifo_run() routine ! CVE-2016-5105 4.4 Qemu: scsi: megasas: stack information leakage while reading configuration ! CVE-2016-5238 4.4 Qemu: scsi: esp: OOB write when using non-DMA mode in get_cmd ! CVE-2016-6490 4.4 Qemu: virtio: infinite loop in virtqueue_pop ! CVE-2016-6833 4.4 Qemu: net: vmxnet3: use-after-free while writing to device ! CVE-2016-6834 4.4 Qemu: net: vmxnet3: an infinite loop during packet fragmentation ! CVE-2016-6888 4.4 Qemu: net: vmxnet: integer overflow in packet initialisation ! CVE-2016-7155 4.4 Qemu: scsi: pvscsi: OOB read and infinite loop while setting descriptor rings ! CVE-2016-7156 4.4 Qemu: scsi: pvscsi: infintie loop when building SG list ! CVE-2016-7157 4.4 Qemu: scsi: mptsas: invalid memory access while building configuration pages ! CVE-2016-7170 4.4 Qemu: vmware_vga: OOB stack memory access when processing svga command ! CVE-2016-7421 4.4 Qemu: scsi: pvscsi: infinite loop when processing IO requests ! CVE-2016-7423 4.4 Qemu: scsi: mptsas: OOB access when freeing MPTSASRequest object ! CVE-2016-7907 4.4 Qemu: net: inifinte loop in imx_fec_do_tx() function ! CVE-2016-7908 4.4 Qemu: net: Infinite loop in mcf_fec_do_tx() ! CVE-2016-7909 4.4 Qemu: net: pcnet: infinite loop in pcnet_rdra_addr() ! CVE-2016-9104 4.4 Qemu: 9pfs: integer overflow leading to OOB access ! CVE-2017-11334 4.4 Qemu: exec: oob access during dma operation ! CVE-2017-18030 4.4 Qemu: Out-of-bounds access in cirrus_invalidate_region routine ! CVE-2020-35505 4.4 QEMU: NULL pointer dereference in do_busid_cmd() in hw/scsi/esp.c ! CVE-2022-0216 4.4 QEMU: use-after-free in lsi_do_msgout function in hw/scsi/lsi53c895a.c ! CVE-2011-0011 4.3 qemu-kvm: Setting VNC password to empty string silently disables all authentication ! CVE-2011-3346 4.0 qemu: local DoS with SCSI CD-ROM ! CVE-2020-13361 3.9 QEMU: es1370: OOB access due to incorrect frame count leads to DoS ! CVE-2020-12829 3.8 qemu: OOB read and write due to integer overflow in sm501_2d_operation() in hw/display/sm5 ! CVE-2020-16092 3.8 QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c ! CVE-2015-6815 3.5 qemu: net: e1000: infinite loop issue ! CVE-2016-9908 3.3 Qemu: display: virtio-gpu: information leakage in virgl_cmd_get_capset ! CVE-2019-8934 3.3 QEMU: ppc64: sPAPR emulator leaks the host hardware identity ! CVE-2020-14415 3.3 QEMU: division by zero in oss_write() in audio/ossaudio.c ! CVE-2023-1386 3.3 Qemu: 9pfs: suid/sgid bits not dropped on file write ! CVE-2020-13362 3.2 QEMU: megasas: OOB read access due to invalid index leads to DoS ! CVE-2020-25723 3.2 QEMU: assertion failure through usb_packet_unmap() in hw/usb/hcd-ehci.c ! CVE-2020-25742 3.2 QEMU: scsi: lsi: null pointer dereference during memory move ! CVE-2020-25743 3.2 QEMU: ide: null pointer dereference while cancelling i/o operation ! CVE-2021-20203 3.2 qemu: Failed malloc in vmxnet3_activate_device() in hw/net/vmxnet3.c ! CVE-2022-26354 3.2 QEMU: vhost-vsock: missing virtqueue detach on error can lead to memory leak ! CVE-2020-15469 2.3 QEMU: MMIO ops null pointer dereference may lead to DoS ! CVE-2011-2527 2.1 qemu: when started as root, extra groups are not dropped correctly ! CVE-2014-3615 2.1 Qemu: information leakage when guest sets high resolution ! CVE-2015-4037 1.9 qemu: insecure temporary file use in /net/slirp.c emulators/qemu-devel qemu-devel-11.0.20260731 ! CVE-2024-6519 8.2 Qemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerability ! CVE-2023-2680 7.5 Dma reentrancy issue (incomplete fix for cve-2021-3750) ! CVE-2023-3354 7.5 Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of s ! CVE-2023-3180 6.0 Heap buffer overflow in virtio_crypto_sym_op_helper() ! CVE-2024-8354 5.5 Qemu-kvm: usb: assertion failure in usb_ep_get() ! CVE-2023-1386 3.3 Qemu: 9pfs: suid/sgid bits not dropped on file write emulators/qemu-user-static qemu-user-static-3.1.0_16 ! CVE-2018-20815 9.8 QEMU: device_tree: heap buffer overflow while loading device tree blob ! CVE-2024-24474 8.8 QEMU: esp: integer underflow leads to heap buffer overflow in esp_do_nodma() ! CVE-2022-3872 8.6 QEMU: sdhci: buffer data port register off-by-one read/write ! CVE-2021-3682 8.5 QEMU: usbredir: free() call on invalid pointer in bufp_alloc() ! CVE-2021-3546 8.2 QEMU: vhost-user-gpu: out-of-bounds write in virgl_cmd_get_capset() ! CVE-2021-3750 8.2 QEMU: hcd-ehci: DMA reentrancy issue leads to use-after-free ! CVE-2021-3929 8.2 QEMU: nvme: DMA reentrancy issue leads to use-after-free ! CVE-2021-4206 8.2 QEMU: QXL: integer overflow in cursor_alloc() can lead to heap buffer overflow ! CVE-2021-4207 8.2 QEMU: QXL: double fetch in qxl_cursor() can lead to heap buffer overflow ! CVE-2024-6519 8.2 Qemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerability ! CVE-2018-16867 7.8 QEMU: dev-mtp: path traversal in usb_mtp_write_data of the Media Transfer Protocol (MTP) ! CVE-2019-13164 7.8 Qemu: qemu-bridge-helper ACL can be bypassed when names are too long ! CVE-2022-0358 7.8 QEMU: virtiofsd: potential privilege escalation via CVE-2018-13405 ! CVE-2020-1711 7.7 QEMU: block: iscsi: OOB heap access via an unexpected response of iSCSI Server ! CVE-2018-20125 7.5 QEMU: pvrdma: null dereference or excessive memory allocation when creating QP/CQ ! CVE-2018-20191 7.5 QEMU: pvrdma: uar_read leads to NULL dereference ! CVE-2018-20216 7.5 QEMU: pvrdma: infinite loop in pvrdma_qp_send/recv ! CVE-2021-20181 7.5 qemu: 9pfs: TOCTOU privilege escalation vulnerability ! CVE-2021-3748 7.5 QEMU: virtio-net: heap use-after-free in virtio_net_receive_rcu ! CVE-2023-2680 7.5 Dma reentrancy issue (incomplete fix for cve-2021-3750) ! CVE-2023-3354 7.5 Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of s ! CVE-2021-3713 7.4 QEMU: out-of-bounds write in UAS (USB Attached SCSI) device emulation ! CVE-2024-7730 7.4 Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb() ! CVE-2020-13754 6.7 QEMU: msix: OOB access during mmio operations may lead to DoS ! CVE-2020-35506 6.7 QEMU: use after free vulnerability in esp_do_dma() in hw/scsi/esp.c ! CVE-2020-27661 6.5 QEMU: divide by zero in dwc2_handle_packet() in hw/usb/hcd-dwc2.c ! CVE-2021-20257 6.5 QEMU: net: e1000: infinite loop while processing transmit descriptors ! CVE-2021-20295 6.5 QEMU: Regression of CVE-2020-10756 fix in virt:rhel/qemu-kvm in Red Hat Enterprise Linux 8 ! CVE-2021-3544 6.5 QEMU: vhost-user-gpu: multiple memory leaks ! CVE-2021-3545 6.5 QEMU: vhost-user-gpu: information disclosure due to uninitialized memory read ! CVE-2021-3611 6.5 QEMU: intel-hda: segmentation fault due to stack overflow ! CVE-2021-3930 6.5 QEMU: off-by-one error in mode_sense_page() in hw/scsi/scsi-disk.c ! CVE-2022-4144 6.5 QEMU: QXL: qxl_phys2virt unsafe address translation can lead to out-of-bounds read ! CVE-2023-3255 6.5 Qemu: vnc: infinite loop in inflate_buffer() leads to denial of service ! CVE-2023-5088 6.4 Qemu: improper ide controller reset can lead to mbr overwrite ! CVE-2020-17380 6.3 QEMU: heap buffer overflow in sdhci_sdma_transfer_multi_blocks() in hw/sd/sdhci.c ! CVE-2021-3507 6.1 QEMU: fdc: heap buffer overflow in DMA read data transfers ! CVE-2020-27821 6.0 QEMU: heap buffer overflow in msix_table_mmio_write() in hw/pci/msix.c ! CVE-2020-35503 6.0 QEMU: NULL pointer dereference issue in megasas-gen2 host bus adapter ! CVE-2020-35504 6.0 QEMU: NULL pointer dereference in scsi_req_continue() in hw/scsi/scsi-bus.c ! CVE-2021-20221 6.0 qemu: out-of-bound heap buffer access via an interrupt ID field ! CVE-2021-3416 6.0 QEMU: net: Infinite loop in loopback mode may lead to stack overflow ! CVE-2021-3607 6.0 QEMU: pvrdma: unchecked malloc size due to integer overflow in init_dev_ring() ! CVE-2021-3608 6.0 QEMU: pvrdma: uninitialized memory unmap in pvrdma_ring_init() ! CVE-2023-1544 6.0 Qemu: pvrdma: out-of-bounds read in pvrdma_ring_next_elem_read() ! CVE-2023-2861 6.0 Qemu: 9pfs: improper access control on special files ! CVE-2023-3019 6.0 Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest() ! CVE-2023-3180 6.0 Heap buffer overflow in virtio_crypto_sym_op_helper() ! CVE-2024-3447 6.0 Qemu: sdhci: heap buffer overflow in sdhci_write_dataport() ! CVE-2021-3409 5.7 QEMU: sdhci: incomplete fix for CVE-2020-17380/CVE-2020-25085 ! CVE-2023-3301 5.6 Triggerable assertion due to race condition in hot-unplug ! CVE-2018-20123 5.5 QEMU: pvrdma: memory leakage in device hotplug ! CVE-2018-20124 5.5 QEMU: rdma: OOB access when building scatter-gather array ! CVE-2018-20126 5.5 QEMU: pvrdma: memory leakage when creating cq/qp ! CVE-2019-6501 5.5 QEMU: scsi-generic: possible OOB access while handling inquiry request ! CVE-2020-13253 5.5 QEMU: sd: OOB access could crash the guest resulting in DoS ! CVE-2020-13791 5.5 QEMU: ati-vga: OOB access while reading PCI configuration may lead to DoS ! CVE-2020-24352 5.5 QEMU: out-of-bounds read/write in ati-vga device emulation in ati_2d_blt() ! CVE-2021-3527 5.5 QEMU: usb: unbounded stack allocation in usbredir ! CVE-2023-42467 5.5 QEMU: am53c974: denial of service due to division by zero ! CVE-2024-8354 5.5 Qemu-kvm: usb: assertion failure in usb_ep_get() ! CVE-2018-16872 5.3 QEMU: usb-mtp: path traversal by host filesystem manipulation in Media Transfer Protocol ( ! CVE-2020-15863 5.3 QEMU: stack-based overflow in xgmac_enet_send() in hw/net/xgmac.c ! CVE-2023-0330 5.3 Qemu: lsi53c895a: dma reentrancy issue leads to stack overflow ! CVE-2020-10761 5.0 QEMU: nbd: reachable assertion failure in nbd_negotiate_send_rep_verr via remote client ! CVE-2020-14364 5.0 QEMU: usb: out-of-bounds r/w access issue while processing usb packets ! CVE-2023-6693 4.9 Qemu: virtio-net: stack buffer overflow in virtio_net_flush_tx() ! CVE-2019-3812 4.4 qemu: Out-of-bounds read in hw/i2c/i2c-ddc.c allows for memory disclosure ! CVE-2020-35505 4.4 QEMU: NULL pointer dereference in do_busid_cmd() in hw/scsi/esp.c ! CVE-2022-0216 4.4 QEMU: use-after-free in lsi_do_msgout function in hw/scsi/lsi53c895a.c ! CVE-2020-13361 3.9 QEMU: es1370: OOB access due to incorrect frame count leads to DoS ! CVE-2020-12829 3.8 qemu: OOB read and write due to integer overflow in sm501_2d_operation() in hw/display/sm5 ! CVE-2020-16092 3.8 QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c ! CVE-2019-8934 3.3 QEMU: ppc64: sPAPR emulator leaks the host hardware identity ! CVE-2020-14415 3.3 QEMU: division by zero in oss_write() in audio/ossaudio.c ! CVE-2023-1386 3.3 Qemu: 9pfs: suid/sgid bits not dropped on file write ! CVE-2020-13362 3.2 QEMU: megasas: OOB read access due to invalid index leads to DoS ! CVE-2020-25723 3.2 QEMU: assertion failure through usb_packet_unmap() in hw/usb/hcd-ehci.c ! CVE-2020-25742 3.2 QEMU: scsi: lsi: null pointer dereference during memory move ! CVE-2020-25743 3.2 QEMU: ide: null pointer dereference while cancelling i/o operation ! CVE-2021-20203 3.2 qemu: Failed malloc in vmxnet3_activate_device() in hw/net/vmxnet3.c ! CVE-2021-3392 3.2 QEMU: scsi: mptsas: use-after-free while processing io requests ! CVE-2022-26354 3.2 QEMU: vhost-vsock: missing virtqueue detach on error can lead to memory leak ! CVE-2020-15469 2.3 QEMU: MMIO ops null pointer dereference may lead to DoS emulators/qemu-user-static-devel qemu-user-static-devel-6.2.50_4 ! CVE-2024-24474 8.8 QEMU: esp: integer underflow leads to heap buffer overflow in esp_do_nodma() ! CVE-2022-3872 8.6 QEMU: sdhci: buffer data port register off-by-one read/write ! CVE-2021-3750 8.2 QEMU: hcd-ehci: DMA reentrancy issue leads to use-after-free ! CVE-2021-3929 8.2 QEMU: nvme: DMA reentrancy issue leads to use-after-free ! CVE-2021-4206 8.2 QEMU: QXL: integer overflow in cursor_alloc() can lead to heap buffer overflow ! CVE-2021-4207 8.2 QEMU: QXL: double fetch in qxl_cursor() can lead to heap buffer overflow ! CVE-2024-6519 8.2 Qemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerability ! CVE-2022-2962 7.8 QEMU: tulip: DMA reentrancy issue leads to stack or heap overflow ! CVE-2023-2680 7.5 Dma reentrancy issue (incomplete fix for cve-2021-3750) ! CVE-2023-3354 7.5 Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of s ! CVE-2024-7730 7.4 Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb() ! CVE-2024-6505 6.8 Qemu-kvm: virtio-net: queue index out-of-bounds access in software rss ! CVE-2021-3611 6.5 QEMU: intel-hda: segmentation fault due to stack overflow ! CVE-2022-3165 6.5 QEMU: VNC: integer underflow in vnc_client_cut_text_ext leads to CPU exhaustion ! CVE-2022-4144 6.5 QEMU: QXL: qxl_phys2virt unsafe address translation can lead to out-of-bounds read ! CVE-2023-3255 6.5 Qemu: vnc: infinite loop in inflate_buffer() leads to denial of service ! CVE-2023-6683 6.5 Qemu: vnc: null pointer dereference in qemu_clipboard_request() ! CVE-2023-5088 6.4 Qemu: improper ide controller reset can lead to mbr overwrite ! CVE-2021-4158 6.0 QEMU: NULL pointer dereference in pci_write() in hw/acpi/pcihp.c ! CVE-2023-1544 6.0 Qemu: pvrdma: out-of-bounds read in pvrdma_ring_next_elem_read() ! CVE-2023-2861 6.0 Qemu: 9pfs: improper access control on special files ! CVE-2023-3019 6.0 Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest() ! CVE-2023-3180 6.0 Heap buffer overflow in virtio_crypto_sym_op_helper() ! CVE-2024-3447 6.0 Qemu: sdhci: heap buffer overflow in sdhci_write_dataport() ! CVE-2023-3301 5.6 Triggerable assertion due to race condition in hot-unplug ! CVE-2023-42467 5.5 QEMU: am53c974: denial of service due to division by zero ! CVE-2024-8354 5.5 Qemu-kvm: usb: assertion failure in usb_ep_get() ! CVE-2023-0330 5.3 Qemu: lsi53c895a: dma reentrancy issue leads to stack overflow ! CVE-2023-6693 4.9 Qemu: virtio-net: stack buffer overflow in virtio_net_flush_tx() ! CVE-2023-1386 3.3 Qemu: 9pfs: suid/sgid bits not dropped on file write emulators/virtualbox-ose virtualbox-ose-6.1.50_20 ! CVE-2024-21112 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21113 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21114 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21115 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22098 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22099 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21141 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22100 7.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21103 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21111 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21116 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21259 7.5 Oracle Virtualization: From CVEorg collector ! CVE-2024-21110 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2025-21571 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21107 6.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21106 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21121 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21263 6.1 core: From CVEorg collector ! CVE-2024-21273 6.0 Oracle Virtualization: From CVEorg collector ! CVE-2024-21109 5.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21161 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2025-21533 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21248 5.3 Core: From CVEorg collector ! CVE-2024-21108 3.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21164 2.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21253 2.3 Oracle VM VirtualBox: From CVEorg collector emulators/virtualbox-ose-additions virtualbox-ose-additions-6.1.50.1501000_4 ! CVE-2024-21112 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21113 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21114 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21115 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22098 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22099 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21141 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22100 7.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21103 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21111 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21116 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21259 7.5 Oracle Virtualization: From CVEorg collector ! CVE-2024-21110 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2025-21571 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21107 6.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21106 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21121 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21263 6.1 core: From CVEorg collector ! CVE-2024-21273 6.0 Oracle Virtualization: From CVEorg collector ! CVE-2024-21109 5.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21161 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2025-21533 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21248 5.3 Core: From CVEorg collector ! CVE-2024-21108 3.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21164 2.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21253 2.3 Oracle VM VirtualBox: From CVEorg collector emulators/virtualbox-ose-additions-legacy virtualbox-ose-additions-legacy-5.2.44.1501000_11 ! CVE-2022-39427 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21112 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21113 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21114 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21115 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2264 8.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14872 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2074 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2250 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2409 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21571 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21990 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22098 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22099 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21141 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2279 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39424 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39425 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39426 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21886 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22018 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2129 7.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22100 7.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-35538 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21491 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21987 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21103 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21111 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21116 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2145 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2309 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2310 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21620 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39422 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21259 7.5 Oracle Virtualization: From CVEorg collector ! CVE-2021-2443 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39421 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21110 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2025-21571 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2280 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2281 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2282 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2283 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2284 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2285 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2286 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2287 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-2913 7.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-2914 7.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2454 7.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-35545 6.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21465 6.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21107 6.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-2910 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2128 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21394 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21471 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21106 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21121 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2019-10219 6.1 hibernate-validator: safeHTML validator allows XSS ! CVE-2024-21263 6.1 core: From CVEorg collector ! CVE-2020-14881 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14884 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14885 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14886 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14889 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2086 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2111 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2112 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2119 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2120 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2121 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2124 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2126 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2131 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2266 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2306 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2321 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2442 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21621 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39423 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21989 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22002 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21273 6.0 Oracle Virtualization: From CVEorg collector ! CVE-2018-0735 5.9 Timing attack against ECDSA signature generation ! CVE-2024-21109 5.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14892 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-35540 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21898 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21899 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22017 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21161 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2025-21533 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2296 5.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2297 5.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21248 5.3 Core: From CVEorg collector ! CVE-2018-5407 4.7 openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) ! CVE-2021-2291 4.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2125 4.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21998 4.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22000 4.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22001 4.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2073 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2127 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2130 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2312 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2475 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-35542 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21554 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21627 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21884 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22016 4.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21295 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21487 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21488 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21885 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21889 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21988 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21999 3.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21108 3.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2123 3.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21991 3.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21164 2.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21253 2.3 Oracle VM VirtualBox: From CVEorg collector emulators/virtualbox-ose-kmod virtualbox-ose-kmod-6.1.50.1501000_1 ! CVE-2024-21112 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21113 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21114 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21115 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22098 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22099 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21141 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22100 7.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21103 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21111 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21116 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21259 7.5 Oracle Virtualization: From CVEorg collector ! CVE-2024-21110 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2025-21571 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21107 6.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21106 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21121 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21263 6.1 core: From CVEorg collector ! CVE-2024-21273 6.0 Oracle Virtualization: From CVEorg collector ! CVE-2024-21109 5.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21161 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2025-21533 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21248 5.3 Core: From CVEorg collector ! CVE-2024-21108 3.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21164 2.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21253 2.3 Oracle VM VirtualBox: From CVEorg collector emulators/virtualbox-ose-kmod-legacy virtualbox-ose-kmod-legacy-5.2.44.1501000_7 ! CVE-2022-39427 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21112 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21113 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21114 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21115 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2264 8.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14872 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2074 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2250 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2409 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21571 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21990 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22098 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22099 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21141 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2279 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39424 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39425 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39426 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21886 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22018 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2129 7.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22100 7.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-35538 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21491 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21987 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21103 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21111 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21116 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2145 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2309 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2310 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21620 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39422 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21259 7.5 Oracle Virtualization: From CVEorg collector ! CVE-2021-2443 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39421 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21110 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2025-21571 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2280 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2281 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2282 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2283 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2284 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2285 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2286 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2287 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-2913 7.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-2914 7.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2454 7.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-35545 6.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21465 6.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21107 6.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-2910 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2128 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21394 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21471 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21106 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21121 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2019-10219 6.1 hibernate-validator: safeHTML validator allows XSS ! CVE-2024-21263 6.1 core: From CVEorg collector ! CVE-2020-14881 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14884 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14885 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14886 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14889 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2086 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2111 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2112 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2119 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2120 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2121 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2124 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2126 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2131 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2266 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2306 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2321 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2442 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21621 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39423 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21989 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22002 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21273 6.0 Oracle Virtualization: From CVEorg collector ! CVE-2018-0735 5.9 Timing attack against ECDSA signature generation ! CVE-2024-21109 5.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14892 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-35540 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21898 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21899 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22017 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21161 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2025-21533 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2296 5.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2297 5.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21248 5.3 Core: From CVEorg collector ! CVE-2018-5407 4.7 openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) ! CVE-2021-2291 4.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2125 4.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21998 4.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22000 4.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22001 4.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2073 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2127 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2130 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2312 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2475 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-35542 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21554 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21627 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21884 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22016 4.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21295 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21487 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21488 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21885 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21889 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21988 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21999 3.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21108 3.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2123 3.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21991 3.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21164 2.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21253 2.3 Oracle VM VirtualBox: From CVEorg collector emulators/virtualbox-ose-legacy virtualbox-ose-legacy-5.2.44_36 ! CVE-2022-39427 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21112 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21113 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21114 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21115 8.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2264 8.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14872 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2074 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2250 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2409 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21571 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21990 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22098 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22099 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21141 8.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2279 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39424 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39425 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39426 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21886 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22018 8.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2129 7.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22100 7.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-35538 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21491 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21987 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21103 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21111 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21116 7.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2145 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2309 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2310 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21620 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39422 7.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21259 7.5 Oracle Virtualization: From CVEorg collector ! CVE-2021-2443 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39421 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21110 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2025-21571 7.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2280 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2281 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2282 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2283 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2284 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2285 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2286 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2287 7.1 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-2913 7.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-2914 7.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2454 7.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-35545 6.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21465 6.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21107 6.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-2910 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2128 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21394 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21471 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21106 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21121 6.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2019-10219 6.1 hibernate-validator: safeHTML validator allows XSS ! CVE-2024-21263 6.1 core: From CVEorg collector ! CVE-2020-14881 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14884 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14885 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14886 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14889 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2086 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2111 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2112 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2119 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2120 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2121 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2124 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2126 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2131 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2266 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2306 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2321 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2442 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21621 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-39423 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21989 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22002 6.0 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21273 6.0 Oracle Virtualization: From CVEorg collector ! CVE-2018-0735 5.9 Timing attack against ECDSA signature generation ! CVE-2024-21109 5.9 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2020-14892 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-35540 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21898 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21899 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22017 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21161 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2025-21533 5.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2296 5.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2297 5.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21248 5.3 Core: From CVEorg collector ! CVE-2018-5407 4.7 openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) ! CVE-2021-2291 4.7 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2125 4.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21998 4.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22000 4.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22001 4.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2073 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2127 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2130 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2312 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2475 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-35542 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21554 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21627 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21884 4.4 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-22016 4.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21295 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21487 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2022-21488 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21885 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21889 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21988 3.8 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21999 3.6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21108 3.3 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2021-2123 3.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2023-21991 3.2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21164 2.5 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Cor ! CVE-2024-21253 2.3 Oracle VM VirtualBox: From CVEorg collector emulators/xen-kernel xen-kernel-4.21.0.20260212_1 ! CVE-2021-28701 7.8 Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xe ! CVE-2022-23033 7.8 xen: arm: guest_physmap_remove_page not removing the p2m mappings (XSA-393) ! CVE-2022-42332 7.8 x86 shadow plus log-dirty mode use-after-free In environments where host assisted address ! CVE-2023-34319 7.8 Linux: buffer overrun in netback due to unusual packet ! CVE-2026-23554 7.8 Use after free of paging structures in EPT ! CVE-2026-23558 7.8 grant table v2 race in status page mapping ! CVE-2024-31145 7.5 error handling in x86 IOMMU identity mapping ! CVE-2024-31146 7.5 PCI device pass-through with shared resources ! CVE-2025-1713 7.5 deadlock potential with VT-d and legacy PCI device pass-through ! CVE-2025-58147 7.5 x86: Incorrect input sanitisation in Viridian hypercalls ! CVE-2025-58148 7.5 x86: Incorrect input sanitisation in Viridian hypercalls ! CVE-2025-58149 7.5 Incorrect removal of permissions on PCI device unplug ! CVE-2024-45817 7.3 x86: Deadlock in vlapic_error() ! CVE-2021-28692 7.1 inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to the ! CVE-2026-23555 7.1 Xenstored DoS by unprivileged domain ! CVE-2018-5244 6.5 xen: memory leak with MSR emulation (XSA-253) ! CVE-2022-42319 6.5 Xenstore: Guests can cause Xenstore to not free temporary memory When working on a request ! CVE-2023-46841 6.5 x86: shadow stack vs exceptions from emulation stubs ! CVE-2023-46842 6.5 x86 HVM hypercalls may trigger Xen bug check ! CVE-2026-23557 6.5 Xenstored DoS via XS_RESET_WATCHES command ! CVE-2022-33748 5.6 lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanu ! CVE-2021-28698 5.5 long running loops in grant table handling In order to properly monitor resource use, Xen ! CVE-2021-28699 5.5 inadequate grant-v2 status frames array bounds check The v2 grant table interface separate ! CVE-2022-42325 5.5 Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA informati ! CVE-2022-42326 5.5 Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA informati ! CVE-2023-34327 5.5 x86/AMD: Debug Mask handling ! CVE-2024-45819 5.5 libxl leaks data to PVH guests via ACPI tables ! CVE-2021-28700 4.9 xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator t ! CVE-2022-23035 4.6 xen: Insufficient cleanup of passed-through device IRQs (XSA-395) ! CVE-2025-27465 4.3 x86: Incorrect stubs exception handling for flags recovery ! CVE-2023-46840 4.1 VT-d: Failure to quarantine devices in !HVM builds ! CVE-2026-23553 2.9 x86: incomplete IBPB for vCPU isolation filesystems/linux-c7-dosfstools linux-c7-dosfstools-3.0.20 ! CVE-2015-8872 6.2 dosfstools: Off-by-2 error leading to corruption in FAT12 ! CVE-2016-4804 6.2 dosfstools: Heap-buffer-overflows in read_fat() and get_fat() functions finance/frontaccounting frontaccounting-2.4.20 ! CVE-2026-80211 8.2 FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storage ! CVE-2026-80210 7.1 FrontAccounting through 2.4.20 Cross-Site Request Forgery on Financial Transaction Forms finance/ledgersmb12 ledgersmb-1.2.26_2 ! CVE-2021-3693 8.8 Cross-site Scripting (XSS) - DOM in ledgersmb/ledgersmb ! CVE-2021-3694 8.2 Cross-site Scripting (XSS) - Reflected in ledgersmb/ledgersmb ! CVE-2007-1923 7.5 (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing th ! CVE-2024-23831 7.5 Privilege escalation through CSRF attack on 'setup.pl' ! CVE-2021-3882 6.8 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ledgersmb/ledgersmb ! CVE-2021-3731 5.9 Improper Restriction of Rendered UI Layers or Frames in ledgersmb/ledgersmb finance/odoo16 py312-odoo16-16.0.20260618 ! CVE-2024-34533 7.3 A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka finance/prestashop prestashop-8.2.5 ! CVE-2026-44212 9.3 PrestaShop: Stored XSS executable in customer service view ! CVE-2026-84186 6.9 Incorrect access control in PrestaShop finance/weberp weberp-4.15.2 ! CVE-2025-46052 9.8 An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to ex ! CVE-2025-46053 5.1 A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL french/wordpress fr-wordpress-fr_FR-7.1,1 ! CVE-2026-64638 8.9 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. ftp/gstreamer1-plugins-curl gstreamer1-plugins-curl-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p ftp/linux-c7-curl linux-c7-curl-7.29.0_13 ! CVE-2016-4606 9.8 Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local ! CVE-2017-8817 9.8 curl: FTP wildcard out of bounds read ! CVE-2018-1000007 9.8 curl: HTTP authentication leak in redirects ! CVE-2018-1000120 9.8 curl: FTP path trickery leads to NIL byte out of bounds write ! CVE-2019-5482 9.8 curl: heap buffer overflow in function tftp_receive_packet() ! CVE-2022-32221 9.8 curl: POST following PUT confusion ! CVE-2023-27533 9.8 curl: TELNET option IAC injection ! CVE-2026-11856 9.8 cross-origin Digest auth state leak ! CVE-2018-1000122 9.1 curl: RTSP RTP buffer over-read ! CVE-2018-1000301 9.1 curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial ! CVE-2026-8927 9.1 env-set cross-proxy Digest auth state leak ! CVE-2023-27534 8.8 curl: SFTP path ~ resolving discrepancy ! CVE-2016-9952 8.1 The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, w ! CVE-2016-4802 7.8 Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when bui ! CVE-2019-5443 7.8 curl: Windows OpenSSL engine code injection ! CVE-2020-8177 7.8 curl: Incorrect argument check can allow remote servers to overwrite local files ! CVE-2018-1000121 7.5 curl: LDAP NULL pointer dereference ! CVE-2021-22946 7.5 curl: Requirement to use TLS not properly enforced for IMAP, POP3, and FTP protocols ! CVE-2022-27781 7.5 curl: CERTINFO never-ending busy-loop ! CVE-2022-27782 7.5 curl: TLS and SSH connection too eager reuse ! CVE-2023-28319 7.5 curl: use after free in SSH sha256 fingerprint check ! CVE-2026-8932 7.5 incomplete mTLS config matching in conn reuse ! CVE-2016-0755 7.3 curl: NTLM credentials not-checked for proxy connection re-use ! CVE-2025-0725 7.3 gzip integer overflow ! CVE-2013-2174 6.8 curl: Loop counter error, leading to heap-based buffer overflow when decoding certain URLs ! CVE-2016-8620 6.5 curl: Glob parser write/read out of bounds ! CVE-2016-9594 6.5 curl: Unitialized random ! CVE-2021-22922 6.5 curl: Content not matching hash in Metalink is not being discarded ! CVE-2022-27776 6.5 curl: auth/cookie leak on redirect ! CVE-2022-32206 6.5 curl: HTTP compression denial of service ! CVE-2026-1965 6.5 bad reuse of HTTP Negotiate connection ! CVE-2026-3784 6.5 wrong proxy connection reuse with credentials ! CVE-2026-5545 6.5 wrong reuse of HTTP Negotiate connection ! CVE-2014-0138 6.4 curl: wrong re-use of connections in libcurl ! CVE-2025-14017 6.3 broken TLS options for threaded LDAPS ! CVE-2016-9586 5.9 curl: printf floating point buffer overflow ! CVE-2021-22947 5.9 curl: Server responses received before STARTTLS processed after TLS handshake ! CVE-2022-32208 5.9 curl: FTP-KRB bad message verification ! CVE-2022-43552 5.9 curl: Use-after-free triggered by an HTTP proxy deny response ! CVE-2023-28320 5.9 curl: siglongjmp race condition may lead to crash ! CVE-2023-28321 5.9 curl: IDN wildcard match may lead to Improper Cerificate Validation ! CVE-2026-4873 5.9 connection reuse ignores TLS requirement ! CVE-2026-6253 5.9 proxy credentials leak over redirect-to proxy ! CVE-2014-0139 5.8 curl: IP address wildcard certificate validation issue in libcurl ! CVE-2022-27774 5.7 curl: credential leak on redirect ! CVE-2016-3739 5.3 curl: TLS certificate name check bypass with mbedTLS and PolarSSL ! CVE-2016-8615 5.3 curl: Cookie injection for other servers ! CVE-2016-8618 5.3 curl: Double-free in curl_maprintf ! CVE-2016-8619 5.3 curl: Double-free in krb5 code ! CVE-2016-8621 5.3 curl: curl_getdate out-of-bounds read ! CVE-2016-8624 5.3 curl: Invalid URL parsing with '#' ! CVE-2016-8625 5.3 curl: IDNA 2003 makes curl use wrong host ! CVE-2017-9502 5.3 curl: URL file scheme drive letter buffer overflow ! CVE-2021-22923 5.3 curl: Metalink download sends credentials ! CVE-2021-22925 5.3 curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure ! CVE-2022-27780 5.3 curl: percent-encoded path separator in URL host ! CVE-2023-28322 5.3 curl: more POST-after-PUT confusion ! CVE-2026-6429 5.3 netrc credential leak with reused proxy connection ! CVE-2026-7168 5.3 cross-proxy Digest auth state leak ! CVE-2013-1944 5.0 curl: Cookie domain suffix match vulnerability ! CVE-2014-3613 5.0 curl: incorrect handling of IP addresses in cookie domain ! CVE-2014-3620 5.0 curl: cookies accepted for TLDs ! CVE-2015-3143 5.0 curl: re-using authenticated connection when unauthenticated ! CVE-2015-3148 5.0 curl: Negotiate not treated as connection-oriented ! CVE-2015-3153 5.0 curl: sensitive HTTP server headers also sent to proxies ! CVE-2018-16842 4.4 curl: Heap-based buffer over-read in the curl tool warning formatting ! CVE-2013-4545 4.3 curl: TLS/SSL certificate name check disabled with peer verification ! CVE-2017-2629 4.3 curl: SSL_VERIFYSTATUS ignored ! CVE-2014-0015 4.0 curl: re-use of wrong HTTP NTLM connection in libcurl ! CVE-2016-8616 3.7 curl: Case insensitive password comparison ! CVE-2020-8284 3.7 curl: FTP PASV command response can cause curl to connect to arbitrary host ! CVE-2022-35252 3.7 curl: Incorrect handling of control code characters in cookies ! CVE-2024-11053 3.4 netrc and redirect credential leak ! CVE-2016-8617 3.3 curl: Out-of-bounds write via unchecked multiplication ! CVE-2016-8623 3.3 curl: Use-after-free via shared cookies ! CVE-2021-22898 3.1 curl: TELNET stack contents disclosure ftp/linux-rl9-curl linux-rl9-curl-7.76.1_13 ! CVE-2022-32207 9.8 curl: Unpreserved file permissions ! CVE-2022-32221 9.8 curl: POST following PUT confusion ! CVE-2023-27533 9.8 curl: TELNET option IAC injection ! CVE-2026-11856 9.8 cross-origin Digest auth state leak ! CVE-2026-8924 9.1 trailing dot domain super cookie ! CVE-2026-8927 9.1 env-set cross-proxy Digest auth state leak ! CVE-2023-27534 8.8 curl: SFTP path ~ resolving discrepancy ! CVE-2024-2398 8.6 HTTP/2 push headers memory-leak ! CVE-2021-22901 8.1 curl: Use-after-free in TLS session handling when using OpenSSL TLS backend ! CVE-2022-22576 8.1 curl: OAUTH2 bearer bypass in connection re-use ! CVE-2026-8286 8.1 wrong STARTTLS connection reuse ! CVE-2021-22926 7.5 curl: CURLOPT_SSLCERT mixup with Secure Transport ! CVE-2021-22946 7.5 curl: Requirement to use TLS not properly enforced for IMAP, POP3, and FTP protocols ! CVE-2022-27775 7.5 curl: bad local IPv6 connection reuse ! CVE-2022-27781 7.5 curl: CERTINFO never-ending busy-loop ! CVE-2022-27782 7.5 curl: TLS and SSH connection too eager reuse ! CVE-2023-28319 7.5 curl: use after free in SSH sha256 fingerprint check ! CVE-2026-5773 7.5 wrong reuse of SMB connection ! CVE-2026-6276 7.5 stale custom cookie host causes cookie leak ! CVE-2026-8932 7.5 incomplete mTLS config matching in conn reuse ! CVE-2026-9547 7.4 SSH improper host validation ! CVE-2025-0725 7.3 gzip integer overflow ! CVE-2021-22922 6.5 curl: Content not matching hash in Metalink is not being discarded ! CVE-2022-27776 6.5 curl: auth/cookie leak on redirect ! CVE-2022-32206 6.5 curl: HTTP compression denial of service ! CVE-2023-23916 6.5 curl: HTTP multi-header compression denial of service ! CVE-2023-46218 6.5 curl: information disclosure by exploiting a mixed case flaw ! CVE-2024-8096 6.5 OCSP stapling bypass with GnuTLS ! CVE-2026-1965 6.5 bad reuse of HTTP Negotiate connection ! CVE-2026-3784 6.5 wrong proxy connection reuse with credentials ! CVE-2026-5545 6.5 wrong reuse of HTTP Negotiate connection ! CVE-2026-8458 6.5 wrong reuse for different services ! CVE-2025-14017 6.3 broken TLS options for threaded LDAPS ! CVE-2021-22947 5.9 curl: Server responses received before STARTTLS processed after TLS handshake ! CVE-2022-32208 5.9 curl: FTP-KRB bad message verification ! CVE-2022-43552 5.9 curl: Use-after-free triggered by an HTTP proxy deny response ! CVE-2023-28320 5.9 curl: siglongjmp race condition may lead to crash ! CVE-2023-28321 5.9 curl: IDN wildcard match may lead to Improper Cerificate Validation ! CVE-2024-9681 5.9 HSTS subdomain overwrites parent cache entry ! CVE-2026-4873 5.9 connection reuse ignores TLS requirement ! CVE-2026-6253 5.9 proxy credentials leak over redirect-to proxy ! CVE-2022-27774 5.7 curl: credential leak on redirect ! CVE-2021-22897 5.3 curl: Cipher settings shared for all connections when using schannel TLS backed ! CVE-2021-22923 5.3 curl: Metalink download sends credentials ! CVE-2021-22925 5.3 curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure ! CVE-2022-27780 5.3 curl: percent-encoded path separator in URL host ! CVE-2023-28322 5.3 curl: more POST-after-PUT confusion ! CVE-2025-14524 5.3 bearer token leak on cross-protocol redirect ! CVE-2025-15079 5.3 libssh global known_hosts override ! CVE-2026-3783 5.3 token leak with redirect and netrc ! CVE-2026-6429 5.3 netrc credential leak with reused proxy connection ! CVE-2026-7168 5.3 cross-proxy Digest auth state leak ! CVE-2022-32205 4.3 curl: Set-Cookie denial of service ! CVE-2025-10966 4.3 missing SFTP host verification with wolfSSH ! CVE-2022-35252 3.7 curl: Incorrect handling of control code characters in cookies ! CVE-2024-11053 3.4 netrc and redirect credential leak ! CVE-2025-0167 3.4 netrc and default credential leak ! CVE-2021-22898 3.1 curl: TELNET stack contents disclosure ! CVE-2025-15224 3.1 libssh key passphrase bypass without agent set ftp/linux-rl9-wget linux-rl9-wget-1.21.1_1 ! CVE-2024-38428 9.1 wget: Misinterpretation of input may lead to improper behavior ! CVE-2026-58469 8.7 GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing ! CVE-2026-58470 6.9 GNU Wget 1.25.0 Integer Overflow via Content-Range Header Parsing ! CVE-2024-10524 6.5 GNU Wget is vulnerable to an SSRF attack when accessing partially-user-controlled shorthan ! CVE-2021-31879 6.1 wget: authorization header disclosure on redirect ! CVE-2026-58471 6.0 GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c ! CVE-2026-58472 6.0 GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding ! CVE-2026-16599 5.1 Denial of Service in GNU wget ftp/oftpd oftpd-0.3.7_2 ! CVE-2005-2239 5.0 oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a ftp/proftpd proftpd-1.3.8c_3 ! CVE-2026-63090 8.7 ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly ! CVE-2026-35025 8.6 ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR ! CVE-2026-42167 8.1 mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a u ! CVE-2026-44331 8.1 SQL Injection via Reverse DNS Lookup in ProFTPD ! CVE-2026-53994 7.7 ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation ! CVE-2026-63091 7.1 ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser ftp/wget wget-1.25.0 ! CVE-2026-58469 8.7 GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing ! CVE-2026-58470 6.9 GNU Wget 1.25.0 Integer Overflow via Content-Range Header Parsing ! CVE-2026-58471 6.0 GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c ! CVE-2026-58472 6.0 GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding ! CVE-2026-16599 5.1 Denial of Service in GNU wget ftp/wzdftpd wzdftpd-0.8.3_12 ! CVE-2007-0428 5.0 Unspecified vulnerability in the chtbl_lookup function in hash.c for WzdFTPD 8.0 and earli games/0verkill 0verkill-0.16_2 ! CVE-2004-0238 7.2 Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execu games/abuse_sdl abuse_sdl-0.8_9 ! CVE-2005-0098 4.6 Multiple buffer overflows in the SDL port of abuse (abuse-SDL) before 2.00 allow local use ! CVE-2005-0099 2.1 The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before cre games/falconseye falconseye-1.9.3_12 ! CVE-2003-0358 4.6 Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, wh games/freecol freecol-1.2.0_2 ! CVE-2018-1000825 10.0 FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability i games/ioquake3 ioquake3-1.36_17 ! CVE-2017-11721 9.8 Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of ! CVE-2017-6903 7.8 In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restr games/ioquake3-server ioquake3-server-1.36_17 ! CVE-2017-11721 9.8 Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of ! CVE-2017-6903 7.8 In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restr games/nethack32 nethack32-3.2.3_8 ! CVE-2020-5209 5.0 NetHack command line parsing of options starting with -de and -i is subject to a buffer ov ! CVE-2020-5210 5.0 NetHack command line -w option parsing is subject to a buffer overflow ! CVE-2020-5211 5.0 NetHack AUTOCOMPLETE configuration file option is subject to a buffer overflow ! CVE-2020-5212 5.0 NetHack MENUCOLOR configuration file option is subject to a buffer overflow ! CVE-2020-5213 5.0 NetHack SYMBOL configuration file option is subject to a buffer overflow ! CVE-2020-5214 5.0 NetHack error recovery after syntax error in configuration file is subject to a buffer ove ! CVE-2003-0358 4.6 Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, wh ! CVE-2020-5253 3.9 Privilege escalation in NetHack ! CVE-2020-5254 3.9 NetHack hilite_status parsing privilege escalation games/nethack33 nethack33-3.3.1_12 ! CVE-2020-5209 5.0 NetHack command line parsing of options starting with -de and -i is subject to a buffer ov ! CVE-2020-5210 5.0 NetHack command line -w option parsing is subject to a buffer overflow ! CVE-2020-5211 5.0 NetHack AUTOCOMPLETE configuration file option is subject to a buffer overflow ! CVE-2020-5212 5.0 NetHack MENUCOLOR configuration file option is subject to a buffer overflow ! CVE-2020-5213 5.0 NetHack SYMBOL configuration file option is subject to a buffer overflow ! CVE-2020-5214 5.0 NetHack error recovery after syntax error in configuration file is subject to a buffer ove ! CVE-2003-0358 4.6 Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, wh ! CVE-2020-5253 3.9 Privilege escalation in NetHack ! CVE-2020-5254 3.9 NetHack hilite_status parsing privilege escalation games/nethack33-nox11 nethack33-nox11-3.3.1_12 ! CVE-2020-5209 5.0 NetHack command line parsing of options starting with -de and -i is subject to a buffer ov ! CVE-2020-5210 5.0 NetHack command line -w option parsing is subject to a buffer overflow ! CVE-2020-5211 5.0 NetHack AUTOCOMPLETE configuration file option is subject to a buffer overflow ! CVE-2020-5212 5.0 NetHack MENUCOLOR configuration file option is subject to a buffer overflow ! CVE-2020-5213 5.0 NetHack SYMBOL configuration file option is subject to a buffer overflow ! CVE-2020-5214 5.0 NetHack error recovery after syntax error in configuration file is subject to a buffer ove ! CVE-2003-0358 4.6 Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, wh ! CVE-2020-5253 3.9 Privilege escalation in NetHack ! CVE-2020-5254 3.9 NetHack hilite_status parsing privilege escalation games/nethack34 nethack34-3.4.3_10 ! CVE-2020-5209 5.0 NetHack command line parsing of options starting with -de and -i is subject to a buffer ov ! CVE-2020-5210 5.0 NetHack command line -w option parsing is subject to a buffer overflow ! CVE-2020-5211 5.0 NetHack AUTOCOMPLETE configuration file option is subject to a buffer overflow ! CVE-2020-5212 5.0 NetHack MENUCOLOR configuration file option is subject to a buffer overflow ! CVE-2020-5213 5.0 NetHack SYMBOL configuration file option is subject to a buffer overflow ! CVE-2020-5214 5.0 NetHack error recovery after syntax error in configuration file is subject to a buffer ove ! CVE-2020-5253 3.9 Privilege escalation in NetHack ! CVE-2020-5254 3.9 NetHack hilite_status parsing privilege escalation games/nethack34-nox11 nethack34-nox11-3.4.3_10 ! CVE-2020-5209 5.0 NetHack command line parsing of options starting with -de and -i is subject to a buffer ov ! CVE-2020-5210 5.0 NetHack command line -w option parsing is subject to a buffer overflow ! CVE-2020-5211 5.0 NetHack AUTOCOMPLETE configuration file option is subject to a buffer overflow ! CVE-2020-5212 5.0 NetHack MENUCOLOR configuration file option is subject to a buffer overflow ! CVE-2020-5213 5.0 NetHack SYMBOL configuration file option is subject to a buffer overflow ! CVE-2020-5214 5.0 NetHack error recovery after syntax error in configuration file is subject to a buffer ove ! CVE-2020-5253 3.9 Privilege escalation in NetHack ! CVE-2020-5254 3.9 NetHack hilite_status parsing privilege escalation games/robocode-naval robocode-naval-0.9.2_4 ! CVE-2019-10648 9.8 Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DN ! CVE-2008-2078 7.5 Robocode before 1.6.0 allows user-assisted remote attackers to "access the internals of th ! CVE-2007-6382 6.8 The Event Dispatch Thread in Robocode before 1.5.1 allows remote attackers to execute arbi games/tremulous tremulous-1.1.0_14 ! CVE-2011-3012 10.0 The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUr games/xboing xboing-2.4_7 ! CVE-2004-0149 4.6 Multiple buffer overflows in xboing before 2.4 allow local users to gain privileges. german/wordpress de-wordpress-de_DE-7.1 ! CVE-2026-64638 8.9 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. graphics/ImageMagick6 ImageMagick6-6.9.13.50_1,1 ! CVE-2016-5118 9.8 ImageMagick: Remote code execution via filename ! CVE-2016-5841 9.8 ImageMagick: Integer overflow in MagickCore/profile.c ! CVE-2018-16328 9.8 ImageMagick: NULL pointer dereference in CheckEventLogging function in MagickCore/log.c ! CVE-2018-16329 9.8 ImageMagick: NULL pointer dereference in GetMagickProperty function in MagickCore/propert ! CVE-2023-34152 9.8 ImageMagick: RCE (shell command injection) vulnerability in OpenBlob with --enable-pipes c ! CVE-2026-56379 9.2 ImageMagick - Command Injection via SVG Decoder ! CVE-2019-17547 8.8 ImageMagick: use-after-free in TraceBezier function in MagickCore/draw.c ! CVE-2026-25794 8.2 ImageMagick has heap-buffer-overflow via signed integer overflow in `WriteUHDRImage` when ! CVE-2019-13136 7.8 ImageMagick: an integer overflow vulnerability in the function TIFFSeekCustomStream in cod ! CVE-2025-55004 7.6 ImageMagick: heap-buffer overflow read in MNG magnification with alpha ! CVE-2021-20310 7.5 ImageMagick: Division by zero in ConvertXYZToJzazbz() of MagickCore/colorspace.c ! CVE-2021-20311 7.5 ImageMagick: Division by zero in sRGBTransformImage() in MagickCore/colorspace.c ! CVE-2021-20312 7.5 ImageMagick: Integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c ! CVE-2021-20313 7.5 ImageMagick: Cipher leak when the calculating signatures in TransformSignatureof MagickCor ! CVE-2025-53015 7.5 ImageMagick has XMP profile write that triggers hang due to unbounded loop ! CVE-2025-66628 7.5 ImageMagick is vulnerable to an Integer Overflow in TIM decoder leading to out of bounds r ! CVE-2026-25967 7.4 ImageMagick has stack buffer overflow in FTXT reader via oversized integer field ! CVE-2020-27752 7.1 ImageMagick: heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h ! CVE-2022-0284 7.1 ImageMagick: Heap buffer overread in GetPixelAlpha() declared in MagickCore/pixel-accessor ! CVE-2024-41817 7.0 Arbitrary Code Execution in `AppImage` version `ImageMagick` ! CVE-2026-56371 6.9 ImageMagick - Memory Leak in TXT File Processing via Texture Attribute ! CVE-2026-30931 6.8 ImageMagick has a heap-based buffer overflow in UHDR encoder ! CVE-2016-7514 6.5 ImageMagick: out-of-bounds read in coders/psd.c ! CVE-2016-7523 6.5 ImageMagick: OOB read in coders/meta.c ! CVE-2016-7524 6.5 ImageMagick: heap-buffer-overflow in coders/meta.c ! CVE-2016-7531 6.5 ImageMagick: pbd file heap-based OOB write ! CVE-2017-11447 6.5 ImageMagick: Memory leak in ReadSCREENSHOTImage function in coders/screenshot.c ! CVE-2021-3596 6.5 ImageMagick: NULL pointer dereference in ReadSVGImage() in coders/svg.c ! CVE-2026-22770 6.5 ImageMagick vulnerable to Release of Invalid Pointer in BilateralBlur when memory allocati ! CVE-2026-23952 6.5 ImageMagick has a NULL pointer dereference in MSL parser via tag before image lo ! CVE-2026-28493 6.5 ImageMagick has a Integer Overflow leading to out of bounds write in SIXEL decoder ! CVE-2026-53466 6.5 ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow ! CVE-2026-56365 6.3 ImageMagick - Memory Leak in PNG Encoder via MNG Image Writing ! CVE-2026-56368 6.3 ImageMagick - Memory Leak in Raw Pixel Data Coders ! CVE-2026-56369 6.3 ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEncipherImage ! CVE-2026-56373 6.3 ImageMagick - Use-After-Free Write in PDB Decoder ! CVE-2026-56376 6.3 ImageMagick - Heap Use-After-Free in Meta Coder ! CVE-2026-56378 6.3 ImageMagick - Heap Out-of-Bounds Read in PCD Decoder ! CVE-2026-61857 6.3 ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP ! CVE-2026-61860 6.3 ImageMagick before 7.1.2-26 Use-After-Free via freetype ! CVE-2026-61861 6.3 ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption ! CVE-2026-61868 6.3 ImageMagick before 7.1.2-26 Memory Leak in YUV Decoder ! CVE-2026-61871 6.3 ImageMagick before 7.1.2-26 Memory Leak in ICON decoder ! CVE-2026-86420 6.3 ImageMagick before 7.1.2-30 Denial of Service Memory Budget ! CVE-2026-86421 6.3 ImageMagick before 7.1.2-30 Memory Leak via MSL decoder ! CVE-2023-3428 6.2 Imagemagick: heap-buffer-overflow in coders/tiff.c ! CVE-2026-40169 6.2 ImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encoders ! CVE-2026-40312 6.2 ImageMagick: Off-by-One in MSL decoder could result in crash ! CVE-2026-46557 6.2 ImageMagick: Stack overflow in fx operation ! CVE-2026-53465 6.2 ImageMagick: Heap Buffer Over-Write in SF3 encoder when writing multi-frame image ! CVE-2020-25664 6.1 ImageMagick: heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h ! CVE-2026-55577 5.9 ImageMagick: Heap Buffer Overflow in ImageMagick MVG decoder ! CVE-2016-10062 5.5 ImageMagick: Write path does not check return of fwrite ! CVE-2020-25663 5.5 ImageMagick: use-after-free, heap-buffer-overflow triggered by GetPixelRed, GetPixelBlue i ! CVE-2020-25665 5.5 ImageMagick: heap-based buffer overflow in WritePALMImage in coders/palm.c ! CVE-2020-25667 5.5 ImageMagick: heap-based buffer overflow in TIFFGetProfiles in coders/tiff.c ! CVE-2020-25674 5.5 ImageMagick: heap-based buffer overflow in WriteOnePNGImage in coders/png.c ! CVE-2020-25676 5.5 ImageMagick: outside the range of representable values of type 'long' and integer overflow ! CVE-2020-27750 5.5 ImageMagick: division by zero in MagickCore/colorspace-private.h ! CVE-2020-27753 5.5 ImageMagick: memory leaks in AcquireMagickMemory function ! CVE-2020-27756 5.5 ImageMagick: division by zero at MagickCore/geometry.c ! CVE-2020-27829 5.5 ImageMagick: heap buffer overflow in coders/tiff.c ! CVE-2021-20243 5.5 ImageMagick: Division by zero in GetResizeFilterWeight in MagickCore/resize.c ! CVE-2021-20244 5.5 ImageMagick: Division by zero in ImplodeImage in MagickCore/visual-effects.c ! CVE-2022-2719 5.5 ImageMagick: Assertion Failure could lead to DoS due to attempted writing of NULL image li ! CVE-2023-1289 5.5 ImageMagick: Specially crafted SVG leads to segmentation fault and generate trash files in ! CVE-2023-2157 5.5 ImageMagick: heap overflow vulnerability ! CVE-2023-34151 5.5 ImageMagick: Undefined behaviors of casting double to size_t in svg, mvg and other coders ! CVE-2023-34474 5.5 ImageMagick: heap-based buffer overflow in ReadTIM2ImageData() function in coders/tim2.c ! CVE-2023-34475 5.5 ImageMagick: heap use-after-free issue in ReplaceXmpValue() function in MagickCore/profile ! CVE-2025-55005 5.5 ImageMagick: heap-buffer overflow in log colorspace handling ! CVE-2026-23874 5.5 ImageMagick's MSL: Stack overflow via infinite recursion in ProcessMSLScript ! CVE-2026-40183 5.5 ImageMagick: Heap buffer overflow when encoding JXL image with a 16-bit float ! CVE-2026-48724 5.5 ImageMagick: Heap Buffer Underwrite in Floyd-Steinberg depth dithering ! CVE-2026-55510 5.5 ImageMagick: Use-After-Free in crafted 8BIM when identifying an image ! CVE-2026-55597 5.5 ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of argum ! CVE-2026-55628 5.5 ImageMagick: Policy Bypass in concatenate operation due to missing checks ! CVE-2025-68618 5.3 Magick's failure to limit the depth of SVG file reads caused a DoS attack. ! CVE-2025-69204 5.3 ImageMagick converting a malicious MVG file to SVG caused an integer overflow. ! CVE-2026-25637 5.3 ImageMagick: Possible memory leak in ASHLAR encoder ! CVE-2026-25969 5.3 ImageMagick has Memory Leak in coders/ashlar.c ! CVE-2026-53467 5.3 ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchan ! CVE-2026-55594 5.3 ImageMagick: Stack Overflow in MVG decoder due to missing depth check. ! CVE-2026-64685 5.3 ImageMagick: Heap Buffer Over-Read in BGR decoder due to mising end-of-file check ! CVE-2026-62946 5.1 ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing ! CVE-2026-62363 5.0 ImageMagick: Heap Buffer Over-Write in fx operation ! CVE-2026-56361 4.8 ImageMagick - Heap Buffer Overflow via Off-by-One in Morphology Processing ! CVE-2026-56363 4.8 ImageMagick - Division by Zero in Binomial Kernel Processing ! CVE-2026-56366 4.8 ImageMagick - Memory Leak in META Reader APP1JPEG Error Path ! CVE-2026-56370 4.8 ImageMagick - Out-of-bounds Access in ConnectedComponentsImage via connected-components Ar ! CVE-2026-56372 4.8 ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method ! CVE-2026-56374 4.8 ImageMagick - Heap Buffer Overflow in FTXT Encoder via format Parameter ! CVE-2026-56375 4.8 ImageMagick - Memory Leak in ASHLAR Coder Action Failure ! CVE-2026-56377 4.8 ImageMagick - Policy Bypass via Incorrect Path Validation ! CVE-2026-61465 4.8 ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass ! CVE-2026-61858 4.8 ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder ! CVE-2026-61859 4.8 ImageMagick before 7.1.2-26 Policy Bypass via script operation ! CVE-2026-66011 4.8 ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options ! CVE-2026-86423 4.8 ImageMagick before 7.1.2-30 Heap-use-after-free via GetList ! CVE-2026-86425 4.8 ImageMagick before 7.1.2-30 Heap-use-after-free via Layer ! CVE-2025-62594 4.7 ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic ! CVE-2026-55595 4.7 ImageMagick: Infinite Loop in connected-components when providing invalid arguments ! CVE-2026-62343 4.7 ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is prov ! CVE-2026-30935 4.4 ImageMagick has a heap Buffer Over-Read in BilateralBlurImage ! CVE-2025-68950 4.0 Magick's failure to limit MVG mutual references forming a loop ! CVE-2026-53464 4.0 ImageMagick: Memory Leak in wand option parser when providing invalid arguments ! CVE-2025-57807 3.8 ImageMagick BlobStream Forward-Seek Under-Allocation ! CVE-2020-25666 3.3 ImageMagick: outside the range of representable values of type int and signed integer over ! CVE-2020-25675 3.3 ImageMagick: outside the range of representable values of type 'long' and integer overflow ! CVE-2020-27751 3.3 ImageMagick: integer overflow in MagickCore/quantum-export.c ! CVE-2020-27754 3.3 ImageMagick: outside the range of representable values of type 'long' and signed integer o ! CVE-2020-27755 3.3 ImageMagick: memory leaks in ResizeMagickMemory function in ImageMagick/MagickCore/memory. ! CVE-2020-27757 3.3 ImageMagick: outside the range of representable values of type 'unsigned long long' at Mag ! CVE-2020-27758 3.3 ImageMagick: outside the range of representable values of type 'unsigned long long' at cod ! CVE-2020-27768 3.3 ImageMagick: outside the range of representable values of type 'unsigned int' at MagickCor ! CVE-2020-27769 3.3 ImageMagick: outside the range of representable values of type 'float' at MagickCore/quant ! CVE-2025-43965 2.9 ImageMagick: Incorrect Handling of Image Depth in MIFF Processing in ImageMagick ! CVE-2025-46393 2.9 ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Proc ! CVE-2026-56362 2.1 ImageMagick - Heap-buffer-overflow Read in GetPixelIndex via OpenPixelCache Metadata Desyn ! CVE-2026-61862 2.1 ImageMagick before 7.1.2-26 Information Disclosure via identify ! CVE-2026-61863 2.1 ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder ! CVE-2026-61864 2.1 ImageMagick before 7.1.2-26 Memory Leak in Log Colorspace ! CVE-2026-61865 2.1 ImageMagick before 7.1.2-26 Memory Leak in Hough Lines ! CVE-2026-61866 2.1 ImageMagick before 7.1.2-26 Memory Leak in JNG encoder ! CVE-2026-61867 2.1 ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder ! CVE-2026-61869 2.1 ImageMagick before 7.1.2-26 Memory Leak in MIFF Encoder ! CVE-2026-61870 2.1 ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder ! CVE-2025-68469 2.0 ImageMagick vulnerable to heap-buffer-overflow ! CVE-2026-61872 2.0 ImageMagick before 7.1.2-26 Memory Leak via TIFF Encoder ! CVE-2026-86424 2.0 ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race ! CVE-2026-56364 1.8 ImageMagick - Memory Leak in LoadOpenCLDeviceBenchmark() via Malformed XML ! CVE-2026-61464 1.0 ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11 ! CVE-2026-86422 1.0 ImageMagick before 7.1.2-30 Path Policy TOCTOU Symlink Race graphics/ImageMagick7 ImageMagick7-7.1.2.25_2 ! CVE-2024-41817 7.0 Arbitrary Code Execution in `AppImage` version `ImageMagick` ! CVE-2026-23952 6.5 ImageMagick has a NULL pointer dereference in MSL parser via tag before image lo ! CVE-2026-53466 6.5 ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow ! CVE-2026-61857 6.3 ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP ! CVE-2026-61860 6.3 ImageMagick before 7.1.2-26 Use-After-Free via freetype ! CVE-2026-61861 6.3 ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption ! CVE-2026-61868 6.3 ImageMagick before 7.1.2-26 Memory Leak in YUV Decoder ! CVE-2026-61871 6.3 ImageMagick before 7.1.2-26 Memory Leak in ICON decoder ! CVE-2026-86420 6.3 ImageMagick before 7.1.2-30 Denial of Service Memory Budget ! CVE-2026-86421 6.3 ImageMagick before 7.1.2-30 Memory Leak via MSL decoder ! CVE-2026-55577 5.9 ImageMagick: Heap Buffer Overflow in ImageMagick MVG decoder ! CVE-2026-55510 5.5 ImageMagick: Use-After-Free in crafted 8BIM when identifying an image ! CVE-2026-55597 5.5 ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of argum ! CVE-2026-55628 5.5 ImageMagick: Policy Bypass in concatenate operation due to missing checks ! CVE-2026-53467 5.3 ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchan ! CVE-2026-55594 5.3 ImageMagick: Stack Overflow in MVG decoder due to missing depth check. ! CVE-2026-64685 5.3 ImageMagick: Heap Buffer Over-Read in BGR decoder due to mising end-of-file check ! CVE-2026-62946 5.1 ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing ! CVE-2026-62363 5.0 ImageMagick: Heap Buffer Over-Write in fx operation ! CVE-2026-61465 4.8 ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass ! CVE-2026-61858 4.8 ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder ! CVE-2026-61859 4.8 ImageMagick before 7.1.2-26 Policy Bypass via script operation ! CVE-2026-66011 4.8 ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options ! CVE-2026-86423 4.8 ImageMagick before 7.1.2-30 Heap-use-after-free via GetList ! CVE-2026-86425 4.8 ImageMagick before 7.1.2-30 Heap-use-after-free via Layer ! CVE-2026-55595 4.7 ImageMagick: Infinite Loop in connected-components when providing invalid arguments ! CVE-2026-62343 4.7 ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is prov ! CVE-2025-57807 3.8 ImageMagick BlobStream Forward-Seek Under-Allocation ! CVE-2026-61862 2.1 ImageMagick before 7.1.2-26 Information Disclosure via identify ! CVE-2026-61863 2.1 ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder ! CVE-2026-61864 2.1 ImageMagick before 7.1.2-26 Memory Leak in Log Colorspace ! CVE-2026-61865 2.1 ImageMagick before 7.1.2-26 Memory Leak in Hough Lines ! CVE-2026-61866 2.1 ImageMagick before 7.1.2-26 Memory Leak in JNG encoder ! CVE-2026-61867 2.1 ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder ! CVE-2026-61869 2.1 ImageMagick before 7.1.2-26 Memory Leak in MIFF Encoder ! CVE-2026-61870 2.1 ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder ! CVE-2026-61872 2.0 ImageMagick before 7.1.2-26 Memory Leak via TIFF Encoder ! CVE-2026-86424 2.0 ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race ! CVE-2026-61464 1.0 ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11 ! CVE-2026-86422 1.0 ImageMagick before 7.1.2-30 Path Policy TOCTOU Symlink Race graphics/blender blender-5.0.1_2,1 ! CVE-2026-60103 6.8 Blender 3.0.0 - 5.1.2 Out-of-Bounds Read via crafted .blend SDNA block graphics/blender4 blender4-4.5.5_4 ! CVE-2026-60103 6.8 Blender 3.0.0 - 5.1.2 Out-of-Bounds Read via crafted .blend SDNA block graphics/dcmtk dcmtk-3.7.0_1 ! CVE-2026-5663 6.9 OFFIS DCMTK storescp storescp.cc executeOnEndOfStudy os command injection ! CVE-2026-10194 5.3 OFFIS DCMTK dcmqrscp dcmqrdbi.cc deleteOldestImages heap-based overflow ! CVE-2026-12805 5.3 OFFIS DCMTK ofxml.cc parseFile heap-based overflow graphics/dcraw dcraw-9.28_5 ! CVE-2018-19655 8.8 dcraw: Stack-based buffer overflow in the find_green() function ! CVE-2018-19565 7.1 dcraw: Buffer over-read in crop_masked_pixels resulting in denial of service or informatio ! CVE-2018-19566 7.1 dcraw: Heap buffer over-read in parse_tiff_ifd resulting in a denial of service or informa ! CVE-2018-19567 5.5 dcraw: A floating point exception in parse_tiff_ifd resulting in a denial of service ! CVE-2018-19568 5.5 dcraw: A floating point exception in kodak_radc_load_raw resulting in a denial of service graphics/dia dia-0.97.3_9,1 ! CVE-2026-77652 7.8 Dia: dia: heap buffer overflow in wpg colormap parser via out-of-bounds palette index ! CVE-2026-77658 7.8 Dia: dia: stack buffer overflow in bus object via unvalidated handle count in project file ! CVE-2019-19451 5.5 When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid graphics/exiftags exiftags-1.01_1 ! CVE-2024-42851 8.4 Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to ex ! CVE-2023-50671 7.8 In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 2 ! CVE-2007-6356 5.0 exiftags before 1.01 allows attackers to cause a denial of service (infinite loop) via rec graphics/freeimage freeimage-3.18.0_6 ! CVE-2024-31570 9.8 libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the Pl ! CVE-2025-70968 9.8 freeimage: FreeImage: Arbitrary code execution via Use After Free in PluginTARGA.cpp;loadR ! CVE-2023-47992 8.8 An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 ! CVE-2023-47994 8.8 An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeim ! CVE-2020-21426 7.8 Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3. ! CVE-2020-21427 7.8 Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage ! CVE-2019-12211 7.5 When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the Plu ! CVE-2019-12212 7.5 When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta. ! CVE-2019-12214 7.5 In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG ! CVE-2024-9029 7.5 Freeimage: heap buffer overflow in tiff_read_iptc_profile ! CVE-2019-12213 6.5 When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginT ! CVE-2023-47993 6.5 A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows ! CVE-2023-47995 6.5 Memory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_Allo ! CVE-2023-47996 6.5 An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allo ! CVE-2023-47997 6.5 An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 lead ! CVE-2025-65803 6.5 An integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and befo ! CVE-2021-33367 5.5 Buffer Overflow vulnerability in Freeimage v3.18.0 allows attacker to cause a denial of se ! CVE-2020-21428 3.3 Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 all graphics/gimp-app gimp-app-2.10.38_11,1 ! CVE-2025-5473 8.8 GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability ! CVE-2025-2760 7.8 GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability ! CVE-2025-2761 7.8 GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability ! CVE-2026-66758 7.8 Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted ! CVE-2026-78465 7.0 Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit ! CVE-2025-6035 6.1 Gimp: gimp integer overflow ! CVE-2026-82328 6.1 Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count ! CVE-2026-82343 6.1 Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-co ! CVE-2026-66757 5.5 Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi ! CVE-2025-8672 4.8 TCC Bypass via Inherited Permissions in Bundled Interpreter in GIMP.app ! CVE-2026-80101 4.4 Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-l graphics/gimp3-app gimp3-app-3.2.6 ! CVE-2026-66758 7.8 Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted ! CVE-2026-59091 7.3 Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file ! CVE-2026-66759 7.1 Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on cra ! CVE-2026-78465 7.0 Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit ! CVE-2026-78475 6.1 Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader ! CVE-2026-82324 6.1 Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0 ! CVE-2026-82328 6.1 Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count ! CVE-2026-82330 6.1 Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check ! CVE-2026-82343 6.1 Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-co ! CVE-2026-59089 5.5 Gimp: gimp: denial of service via integer overflow in playstation tim loader ! CVE-2026-66757 5.5 Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi ! CVE-2026-79902 5.5 Gimp: stack vla size underflow denial of service in seattle ! CVE-2026-80101 4.4 Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-l graphics/gstreamer1-plugins-aalib gstreamer1-plugins-aalib-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-cairo gstreamer1-plugins-cairo-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-gdkpixbuf gstreamer1-plugins-gdkpixbuf-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-gl gstreamer1-plugins-gl-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-jpeg gstreamer1-plugins-jpeg-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-kms gstreamer1-plugins-kms-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-libcaca gstreamer1-plugins-libcaca-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-libvisual gstreamer1-plugins-libvisual-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-opencv gstreamer1-plugins-opencv-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-openexr gstreamer1-plugins-openexr-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-openjpeg gstreamer1-plugins-openjpeg-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-png gstreamer1-plugins-png-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-rsvg gstreamer1-plugins-rsvg-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-vulkan gstreamer1-plugins-vulkan-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-webp gstreamer1-plugins-webp-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/gstreamer1-plugins-zbar gstreamer1-plugins-zbar-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p graphics/jbig2dec jbig2dec-0.20_1 ! CVE-2023-46361 6.5 Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_e graphics/jhead jhead-3.08 ! CVE-2025-44906 7.8 jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function a graphics/lcms lcms-1.19_9,1 ! CVE-2016-10165 7.1 lcms2: Out-of-bounds read in Type_MLU_Read() ! CVE-2013-4160 5.0 CMS: multiple potential flaws ! CVE-2013-4276 4.3 lcms: Stack-based buffer overflows in ColorSpace conversion calculator and TIFF compare ut ! CVE-2026-41254 4.0 Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service graphics/libbpg libbpg-0.9.8_4 ! CVE-2018-12447 8.8 The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.8 an graphics/libcaca libcaca-0.99.b20_1 ! CVE-2022-0856 6.5 libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious graphics/libfpx libfpx-1.3.1.10_1 ! CVE-2018-6876 6.5 ImageMagick: Stack-based buffer under-read in ole/oleprop.cpp graphics/libheif libheif-1.22.2_2 ! CVE-2026-62292 8.7 libheif: Out-of-bounds read in uncompressed unci tile range slicing ! CVE-2026-50142 7.5 libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing b ! CVE-2026-62291 5.3 libheif: Heap out of bounds write in libheif uncompressed encoder when writing images with ! CVE-2026-62289 4.3 libheif: Integer underflow in Fraction constructor via double clap transform application ! CVE-2026-62377 4.3 libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF graphics/librsvg2 librsvg2-2.40.23 ! CVE-2018-1000041 8.8 librsvg: Improper input validation vulnerability in rsvg-io.c graphics/linux-c7-cairo linux-c7-cairo-1.15.12_2 ! CVE-2020-35492 7.8 cairo: libreoffice slideshow aborts with stack smashing in cairo's composite_boxes ! CVE-2018-18064 6.5 cairo: Stack-based buffer overflow via parsing of crafted WebKitGTK+ document graphics/linux-c7-cairo-gobject linux-c7-cairo-gobject-1.15.12_2 ! CVE-2020-35492 7.8 cairo: libreoffice slideshow aborts with stack smashing in cairo's composite_boxes ! CVE-2018-18064 6.5 cairo: Stack-based buffer overflow via parsing of crafted WebKitGTK+ document graphics/linux-c7-gdk-pixbuf2 linux-c7-gdk-pixbuf2-2.36.12_1 ! CVE-2021-20240 8.8 gdk-pixbuf: integer wraparound in the GIF loader of gdk-pixbuf via crafted input leads to ! CVE-2021-46829 7.8 gdk-pixbuf: heap-based buffer overflow when compositing or clearing frames in GIF files graphics/linux-c7-librsvg2 linux-c7-librsvg2-2.40.20_1 ! CVE-2018-1000041 8.8 librsvg: Improper input validation vulnerability in rsvg-io.c ! CVE-2019-20446 6.5 librsvg: Resource exhaustion via crafted SVG file with nested patterns graphics/linux-c7-wayland linux-c7-wayland-1.15.0 ! CVE-2021-3782 6.6 wayland: libwayland-server wl_shm reference-count overflow graphics/linux-rl9-gdk-pixbuf2 linux-rl9-gdk-pixbuf2-2.42.6_9 ! CVE-2021-46829 7.8 gdk-pixbuf: heap-based buffer overflow when compositing or clearing frames in GIF files graphics/linux-rl9-librsvg2 linux-rl9-librsvg2-2.50.7_5 ! CVE-2023-38633 5.5 librsvg: Arbitrary file read when xinclude href has special characters graphics/openjpeg openjpeg-2.5.4_2 ! CVE-2026-6192 4.8 uclouvain openjpeg pi.c opj_pi_initialise_encode integer overflow graphics/openjpeg15 openjpeg15-1.5.2_5 ! CVE-2015-8871 9.8 openjpeg: Use-after-free in opj_j2k_write_mco function ! CVE-2017-14039 8.8 openjpeg: Heap-based buffer overflow in opj_t2_encode_packet function in lib/openjp2/t2.c ! CVE-2017-14164 8.8 openjpeg2: Heap-based buffer overflow in opj_write_bytes_LE ! CVE-2018-20847 8.8 openjpeg: integer overflow in function opj_get_encoding_parameters in openjp2/pi.c ! CVE-2018-21010 8.8 openjpeg: heap buffer overflow in color_apply_icc_profile in bin/common/color.c ! CVE-2016-7163 7.8 openjpeg: Integer overflow in opj_pi_create_decode ! CVE-2020-27823 7.8 openjpeg: heap-buffer-overflow write in opj_tcd_dc_level_shift_encode() ! CVE-2020-27844 7.8 openjpeg: heap-based buffer overflow in opj_t2_encode_packet function in openjp2/t2.c ! CVE-2021-3575 7.8 openjpeg: heap-buffer-overflow in color.c may lead to DoS or arbitrary code execution ! CVE-2016-7445 7.5 convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (N ! CVE-2018-14423 7.5 openjpeg2: Division-by-zero vulnerabilities in lib/openjp3d/pi.c ! CVE-2020-6851 7.5 openjpeg: Heap-based buffer overflow in opj_t1_clbl_decode_processor() ! CVE-2015-1239 6.5 Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as use ! CVE-2016-10504 6.5 openjpeg: Heap-based buffer over-write in in opj_mqc_byteout function of mqc.c ! CVE-2016-10505 6.5 openjpeg: NULL pointer dereference in imagetopnm function in convert.c ! CVE-2016-10506 6.5 openjpeg: Division by zero in functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_nex ! CVE-2016-10507 6.5 openjpeg: Integer overflow in bmp24toimage function in convertbmp.c ! CVE-2016-1924 6.5 openjpeg: out of bounds read in opj_tgt_reset ! CVE-2018-20845 6.5 openjpeg: division-by-zero in functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in op ! CVE-2018-20846 6.5 openjpeg: out-of-bounds read in functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_nex ! CVE-2020-15389 6.5 openjpeg: use-after-free and double-free via a mix of valid and invalid files in a directo ! CVE-2016-3182 5.5 openjpeg: Heap corruption in opj_free function ! CVE-2016-3183 5.5 openjpeg: Out-of-bounds read in sycc422_to_rgb function ! CVE-2016-4796 5.5 openjpeg: Heap buffer overflow in function color_cmyk_to_rgb in color.c ! CVE-2016-4797 5.5 openjpeg: Division-by-zero in function opj_tcd_init_tile in tcd.c ! CVE-2017-12982 5.5 openjpeg: Memory allocation failure in the opj_image_create function ! CVE-2020-27824 5.5 openjpeg: global-buffer-overflow read in opj_dwt_calc_explicit_stepsizes() ! CVE-2020-27841 5.5 openjpeg: heap-based buffer overflows in lib/openjp2/pi.c ! CVE-2020-27842 5.5 openjpeg: null pointer dereference in opj_tgt_reset function in lib/openjp2/tgt.c ! CVE-2020-27843 5.5 openjpeg: out-of-bounds read in opj_t2_encode_packet function in openjp2/t2.c ! CVE-2020-27845 5.5 openjpeg: heap-based buffer overflow in functions opj_pi_next_rlcp, opj_pi_next_rpcl and o graphics/p5-GraphViz p5-GraphViz-2.25 ! CVE-2020-18032 7.8 graphviz: off-by-one in parse_reclbl() in lib/common/shapes.c ! CVE-2014-9157 7.5 graphviz: format string vulnerability in yyerror() graphics/py-graphviz py312-graphviz-0.10.1_1 ! CVE-2008-4555 8.5 graphviz: buffer overflow in the graph parser ! CVE-2020-18032 7.8 graphviz: off-by-one in parse_reclbl() in lib/common/shapes.c ! CVE-2014-9157 7.5 graphviz: format string vulnerability in yyerror() ! CVE-2005-4803 3.6 graphviz before 2.2.1 allows local users to overwrite arbitrary files via a symlink attack graphics/sam2p sam2p-0.49.4_4,1 ! CVE-2018-12578 9.8 There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 ! CVE-2018-12601 9.8 There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that le ! CVE-2018-7551 9.8 There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fau ! CVE-2018-7552 9.8 There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segm ! CVE-2018-7553 9.8 There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p ! CVE-2018-7554 9.8 There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault i ! CVE-2018-11489 8.8 giflib: heap-based buffer overflow in DGifDecompressLine function in dgif_lib.c ! CVE-2018-11490 8.8 giflib: heap-based buffer overflow in DGifDecompressLine function in dgif_lib.c ! CVE-2018-7487 7.8 There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49. ! CVE-2020-19491 7.8 There is an invalid memory access bug in cgif.c that leads to a Segmentation fault in sam2 ! CVE-2020-19492 7.8 There is a floating point exception in ReadImage that leads to a Segmentation fault in sam ! CVE-2017-16663 5.5 In sam2p 0.49.4, there are integer overflows (with resultant heap-based buffer overflows) graphics/sdl_image sdl_image-1.2.12_14 ! CVE-2026-35444 7.1 SDL_image has a heap buffer overflow READ via unchecked colormap index in XCF loader graphics/swftools swftools-0.9.2_13 ! CVE-2024-26339 9.1 swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/sr ! CVE-2017-11096 8.8 When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer ! CVE-2017-11097 8.8 When SWFTools 0.9.2 processes a crafted file in swfc, it can lead to a NULL Pointer Derefe ! CVE-2017-11098 8.8 When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Vio ! CVE-2017-11099 8.8 When SWFTools 0.9.2 processes a crafted file in wav2swf, it can lead to a Segmentation Vio ! CVE-2017-11100 8.8 When SWFTools 0.9.2 processes a crafted file in swfextract, it can lead to a NULL Pointer ! CVE-2017-11101 8.8 When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer ! CVE-2017-8400 8.8 In SWFTools 0.9.2, an out-of-bounds write of heap data can occur in the function png_load( ! CVE-2024-25165 8.8 A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineT ! CVE-2017-16793 7.8 The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WA ! CVE-2017-16796 7.8 In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a ! CVE-2017-16797 7.8 In SWFTools 0.9.2, the png_load function in lib/png.c does not properly validate an allocl ! CVE-2017-7698 7.8 A Use After Free in the pdf2swf part of swftools 0.9.2 and earlier allows remote attackers ! CVE-2021-39558 7.8 An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in th ! CVE-2021-39561 7.8 An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in th ! CVE-2021-39564 7.8 An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the ! CVE-2021-39569 7.8 An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the ! CVE-2021-39574 7.8 An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the ! CVE-2021-39577 7.8 An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the ! CVE-2021-39579 7.8 An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the ! CVE-2021-39582 7.8 An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the ! CVE-2021-39595 7.8 An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in th ! CVE-2021-42195 7.8 An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the ! CVE-2021-42197 7.8 An issue was discovered in swftools through 20201222 through a memory leak in the swftools ! CVE-2021-42199 7.8 An issue was discovered in swftools through 20201222. A heap buffer overflow exists in the ! CVE-2021-42201 7.8 An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the ! CVE-2021-42203 7.8 An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the ! CVE-2021-42204 7.8 An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the ! CVE-2023-26991 7.8 SWFTools v0.9.2 was discovered to contain a stack-use-after-scope in the swf_ReadSWF2 func ! CVE-2024-22562 7.8 swftools 0.9.2 was discovered to contain a Stack Buffer Underflow via the function dict_fo ! CVE-2024-22911 7.8 A stack-buffer-underflow vulnerability was found in SWFTools v0.9.2, in the function parse ! CVE-2024-22912 7.8 A global-buffer-overflow was found in SWFTools v0.9.2, in the function countline at swf5co ! CVE-2024-22913 7.8 A heap-buffer-overflow was found in SWFTools v0.9.2, in the function swf5lex at lex.swf5.c ! CVE-2024-22915 7.8 A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxsw ! CVE-2024-22919 7.8 swftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the fun ! CVE-2024-22920 7.8 swftools 0.9.2 was discovered to contain a heap-use-after-free via the function bufferWrit ! CVE-2024-22955 7.8 swftools 0.9.2 was discovered to contain a stack-buffer-underflow vulnerability via the fu ! CVE-2024-22956 7.8 swftools 0.9.2 was discovered to contain a heap-use-after-free vulnerability via the funct ! CVE-2017-10976 7.5 When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffe ! CVE-2024-28458 7.5 Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to cr ! CVE-2017-8401 6.5 In SWFTools 0.9.2, an out-of-bounds read of heap data can occur in the function png_load() ! CVE-2024-26334 6.2 swftools v0.9.2 was discovered to contain a segmentation violation via the function compil ! CVE-2017-16711 5.5 The swf_DefineLosslessBitsTagToImage function in lib/modules/swfbits.c in SWFTools 0.9.2 m ! CVE-2017-16794 5.5 The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multipli ! CVE-2017-16868 5.5 In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a ! CVE-2017-16890 5.5 SWFTools 0.9.2 has a divide-by-zero error in the wav_convert2mono function in lib/wav.c be ! CVE-2021-39553 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39554 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39555 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39556 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39557 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39559 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39562 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39563 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39575 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39583 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39584 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39585 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39587 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39588 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39589 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39590 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39591 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39592 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39593 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39594 5.5 Other An issue was discovered in swftools through 20200710. A NULL pointer dereference exi ! CVE-2021-39596 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39597 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-39598 5.5 An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in ! CVE-2021-42196 5.5 An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in ! CVE-2021-42198 5.5 An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in ! CVE-2021-42200 5.5 An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in ! CVE-2021-42202 5.5 An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in ! CVE-2022-46440 5.5 ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function ! CVE-2023-27249 5.5 swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPla ! CVE-2023-29950 5.5 swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerat ! CVE-2023-37644 5.5 SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a ! CVE-2024-22914 5.5 A heap-use-after-free was found in SWFTools v0.9.2, in the function input at lex.swf5.c:26 ! CVE-2024-22957 5.5 swftools 0.9.2 was discovered to contain an Out-of-bounds Read vulnerability via the funct ! CVE-2024-26333 5.5 swftools v0.9.2 was discovered to contain a segmentation violation via the function free_l ! CVE-2024-26335 5.5 swftools v0.9.2 was discovered to contain a segmentation violation via the function state_ ! CVE-2025-6271 4.8 swftools wav2swf wav.c wav_convert2mono out-of-bounds ! CVE-2024-26337 4.3 swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font graphics/tiff tiff-4.7.2 ! CVE-2023-3618 6.5 Segmentation fault in fax3encode in libtiff/tif_fax3.c ! CVE-2023-3164 5.5 Heap-buffer-overflow in extractimagesection() graphics/xli xli-1.17.0_19 ! CVE-2001-0775 7.5 security flaw ! CVE-2005-0638 7.5 security flaw ! CVE-2005-0639 7.5 Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrar graphics/xnview xnview-1.70_3 ! CVE-2013-3941 9.8 Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) t ! CVE-2009-4001 9.3 Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary ! CVE-2012-0684 9.3 Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute ! CVE-2012-0685 9.3 Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute ! CVE-2013-2577 9.3 Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code vi ! CVE-2013-3246 7.8 Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to ! CVE-2013-3247 7.8 Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to ! CVE-2013-3937 7.8 Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to ! CVE-2013-3939 7.8 xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during process ! CVE-2021-28835 7.8 Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arb ! CVE-2011-1338 6.9 Untrusted search path vulnerability in XnView before 1.98.1 allows local users to gain pri ! CVE-2012-0276 6.8 Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause ! CVE-2012-0277 6.8 Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial ! CVE-2012-0282 6.8 Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial graphics/xpdf3 xpdf3-3.04_14 ! CVE-2022-24106 7.8 In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' f ! CVE-2022-24107 7.8 Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc. ! CVE-2019-16088 5.5 Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::c irc/atheme-services atheme-services-7.2.12_1 ! CVE-2024-27508 7.5 Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c. irc/srvx srvx-1.3.1 ! CVE-2014-5508 3.5 Multiple integer overflows in the HelpServ module (mod-helpserv.c) in srvx 1.3.1 allow rem japanese/bugzilla50 ja-bugzilla50-5.0.2 ! CVE-2016-2803 6.1 Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 thro japanese/groff ja-groff-1.18.1_19 ! CVE-2009-5078 6.5 groff: pdfroff.sh launches Ghostscript without -dSAFER ! CVE-2009-5044 3.3 groff: insecure temporary file handling in pdfroff ! CVE-2009-5079 3.3 The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts i ! CVE-2009-5080 3.3 groff: improper handling of failed attempts to create temporary directories in eqn2graph/p ! CVE-2009-5081 3.3 groff: roff2.pl and groffer.pl use easy-to-guess temporary file names japanese/nethack34 ja-nethack-3.4.3_9 ! CVE-2020-5209 5.0 NetHack command line parsing of options starting with -de and -i is subject to a buffer ov ! CVE-2020-5210 5.0 NetHack command line -w option parsing is subject to a buffer overflow ! CVE-2020-5211 5.0 NetHack AUTOCOMPLETE configuration file option is subject to a buffer overflow ! CVE-2020-5212 5.0 NetHack MENUCOLOR configuration file option is subject to a buffer overflow ! CVE-2020-5213 5.0 NetHack SYMBOL configuration file option is subject to a buffer overflow ! CVE-2020-5214 5.0 NetHack error recovery after syntax error in configuration file is subject to a buffer ove ! CVE-2020-5253 3.9 Privilege escalation in NetHack ! CVE-2020-5254 3.9 NetHack hilite_status parsing privilege escalation japanese/wordpress ja-wordpress-ja-7.1 ! CVE-2026-64638 8.9 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. japanese/xpdf ja-xpdf-jafont-4.02 ! CVE-2021-30860 7.8 KEV An integer overflow was addressed with improved input validation. This issue is fixed in S ! CVE-2020-35376 7.5 Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type ! CVE-2022-38334 5.5 XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog ! CVE-2022-48545 5.5 An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02 ! CVE-2020-25725 5.0 In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is tr ! CVE-2024-2971 2.9 Out-of-bounds array access due to negative object numbers in indirect references in Xpdf 4 ! CVE-2024-3247 2.9 Stack overflow in Xpdf 4.05 due to object loop in PDF object stream ! CVE-2024-3248 2.9 Stack overflow in Xpdf 4.05 due to object loop in attachments ! CVE-2024-3900 2.9 Out-of-bounds stack array write in Xpdf 4.05 due to missing zero check ! CVE-2024-4141 2.9 Out-of-bounds array write in Xpdf 4.05 due to incorrect bounds check ! CVE-2024-4568 2.9 Stack overflow in Xpdf 4.05 due to object loop in PDF resources ! CVE-2024-4976 2.1 Out-of-bounds array write in Xpdf 4.05 due to missing object type check ! CVE-2024-7866 2.1 Stack overflow in Xpdf 4.05 due to object loop in PDF pattern ! CVE-2024-7867 2.1 Integer overflow and divide-by-zero in Xpdf 4.05 due to bogus page box coordinates ! CVE-2024-7868 2.1 Uninitialized variable in Xpdf 4.05 due to invalid JPEG header java/bouncycastle bouncycastle-1.83_1 ! CVE-2025-14813 9.3 GOSTCTR implementation unable to process more than 255 blocks correctly ! CVE-2026-58062 9.3 Stapled OCSP response accepted without binding to the checked certificate ! CVE-2026-59638 9.3 JSSE hostname verifier CN-fallback enabled by default despite documented opt-in ! CVE-2026-59650 9.3 MTI/A0 DH agreement exponentiates unvalidated peer value ! CVE-2026-8763 9.3 Name Constraints bypass via trailing dot in rfc822Name and URI ! CVE-2026-5598 8.9 Non-constant time comparisons risk private key leakage in FrodoKEM. ! CVE-2026-12802 8.7 CMS AuthEnvelopedData fails to enforce tag-length on decryption ! CVE-2026-12803 8.7 KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) ! CVE-2026-12816 8.7 IESEngine stream-mode MAC forgery via length-dependent KDF split ! CVE-2026-12817 8.7 OpenPGP AEAD decryption skips final tag on chunk-aligned data ! CVE-2026-12852 8.7 MLS wire decoder allocates attacker-declared opaque length before bounds check ! CVE-2026-12860 8.7 RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path ! CVE-2026-13506 8.7 Lazy ASN.1 sequence forcing resets nesting-depth guard ! CVE-2026-14682 8.7 Possible OOM from unbounded up-front allocation on a definite-length read ! CVE-2026-3505 8.7 Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion. ! CVE-2026-58059 8.7 Quadratic-time escaping when stringifying X.500 distinguished names ! CVE-2026-58060 8.7 HSS public-key level count unbounded, enabling huge allocation on verify ! CVE-2026-58061 8.7 CCM-family modes write plaintext to caller buffer before tag check ! CVE-2026-59639 8.7 CMS verifySignatures returns true for SignedData with zero signers ! CVE-2026-59640 8.7 OpenPGP CFB quick-check oracle active on symmetric/session-key paths ! CVE-2026-59641 8.7 S/MIME validator trusts signer-asserted signingTime for path validation ! CVE-2026-59642 8.7 CMS AuthenticatedData content not bound to MAC when authAttrs present ! CVE-2026-59643 8.7 OpenPGP inline-signature policy failures silently ignored ! CVE-2026-59644 8.7 MLS hash-ratchet honours arbitrary 32-bit generation counter from sender ! CVE-2026-59645 8.7 OER parser recurses without depth limit on self-referential IEEE 1609.2 schema ! CVE-2026-59646 8.7 DTLS handshake reassembler allocates buffer from unchecked 24-bit length ! CVE-2026-59649 8.7 OpenPGP user-attribute subpacket length bounded only by JVM max memory ! CVE-2026-12185 7.1 BKS/UBER keystore allocates from untrusted lengths before integrity check ! CVE-2026-59651 7.1 BKS keystore accepts legacy version with 16-bit integrity MAC key ! CVE-2026-59647 6.9 CRMF/CMP password-MAC honours unbounded iteration count ! CVE-2026-59648 6.9 OpenPGP Argon2 S2K honours attacker-chosen memory and passes ! CVE-2026-59652 6.9 LDAP filter injection in legacy jdk1.4 LDAPStoreHelper ! CVE-2026-5588 6.3 PKIX draft CompositeVerifier accepts empty signature sequence as valid. ! CVE-2026-0636 5.5 LDAP Injection Vulnerability in LDAPStoreHelper.java ! CVE-2026-13586 5.3 PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) ! CVE-2026-15055 5.3 PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input ! CVE-2026-58063 5.3 BCFKS keystore load honours unbounded KDF cost from untrusted file java/intellij intellij-2020.2.3_5 ! CVE-2026-64812 10.0 Unauthorized Input Injection in IntelliJ IDEA Remote Development ! CVE-2026-64813 10.0 In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible i ! CVE-2026-59792 9.6 Path Traversal in IntelliJ IDEA Enables Code Execution ! CVE-2026-64814 8.6 In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote ! CVE-2022-28651 8.4 In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected ! CVE-2026-86502 8.4 Missing TLS and Authentication Allow Local Code Execution on JetBrains IntelliJ IDEA Remot ! CVE-2026-64815 8.1 In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Desi ! CVE-2026-49367 8.0 In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest us ! CVE-2021-25758 7.8 In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the work ! CVE-2021-29263 7.8 In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insuffic ! CVE-2022-24345 7.8 In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from ! CVE-2022-24346 7.8 In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Ov ! CVE-2026-49366 7.8 Command Injection via Filename Completion in JetBrains IntelliJ IDEA ! CVE-2026-64811 7.8 In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before gran ! CVE-2026-75056 7.8 Remote Code Execution via Markdown Export Tool in IntelliJ IDEA ! CVE-2026-86504 7.8 Missing Project Trust Confirmation Allows Host‑Level Code Execution in JetBrains IntelliJ ! CVE-2021-30006 7.5 In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure. ! CVE-2021-30504 7.5 In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource a ! CVE-2022-40978 7.5 The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search orde ! CVE-2026-41882 7.4 Arbitrary Local File Access via Built‑in Web Server in IntelliJ IDEA ! CVE-2022-29813 6.9 In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was p ! CVE-2022-29814 6.9 In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in cus ! CVE-2022-29815 6.9 In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was p ! CVE-2022-29819 6.9 In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documenta ! CVE-2025-57728 6.5 In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me gues ! CVE-2025-57729 6.5 In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to aut ! CVE-2023-51655 6.3 In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Projec ! CVE-2026-75054 6.3 Server‑side request forgery via OpenAPI preview proxy in JetBrains IntelliJ IDEA ! CVE-2022-46826 6.2 In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file ! CVE-2026-75057 6.2 Plain‑Text Logging of Git Credentials in JetBrains IntelliJ IDEA ! CVE-2022-48433 6.1 In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method us ! CVE-2024-24941 6.1 In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send a ! CVE-2022-46824 5.6 In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on m ! CVE-2022-48430 5.5 In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external s ! CVE-2026-75055 5.5 XXE Local File Disclosure in IntelliJ IDEA Hadoop ResourceManager ! CVE-2026-75058 5.5 In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings import ! CVE-2025-68269 5.4 In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted ! CVE-2026-75053 5.4 Server‑Side Request Forgery via DevKit Debug Listener in IntelliJ IDEA ! CVE-2022-46828 5.2 In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible. ! CVE-2022-48432 5.2 In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed. ! CVE-2023-39261 5.2 In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permiss ! CVE-2025-57730 5.2 In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Developmen ! CVE-2022-47896 5.0 In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks. ! CVE-2022-47895 4.7 In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP pr ! CVE-2025-57727 4.7 In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote re ! CVE-2022-48431 4.5 In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be ! CVE-2026-49382 4.5 Template Injection in IntelliJ IDEA Copyright Plugin Enables Code Execution ! CVE-2026-64810 4.3 In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notificatio ! CVE-2022-46825 4.0 In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about ! CVE-2022-29817 3.9 In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web ! CVE-2022-29818 3.9 In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were fla ! CVE-2022-37009 3.9 In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was ! CVE-2022-46827 3.9 In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to cus ! CVE-2022-37010 3.6 In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is ! CVE-2026-75052 3.6 Local Command Execution via Crafted Markdown Preview in IntelliJ IDEA ! CVE-2023-38069 3.3 In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain c ! CVE-2024-46970 3.3 In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible ! CVE-2025-32054 3.3 In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea ! CVE-2026-49383 3.3 XML External Entity Vulnerability in JetBrains IntelliJ IDEA UI Designer ! CVE-2026-86503 3.3 SSRF via Kubernetes Spec-source URL in Untrusted IntelliJ Projects ! CVE-2026-86505 3.3 Missing Project-Trust Check in JetBrains IntelliJ IDEA Leaks Project Metadata ! CVE-2022-29816 2.8 In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible ! CVE-2024-24940 2.8 In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking arch ! CVE-2026-86501 2.8 Logging of Terminal Command Input to IDE Log Leads to Information Exposure ! CVE-2022-29812 2.3 In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode direc java/netty netty-4.1.53_2 ! CVE-2026-75595 9.1 Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslCo ! CVE-2026-33871 8.7 Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass ! CVE-2026-45674 8.7 Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records ! CVE-2026-47691 8.7 Netty has Insufficient Bailiwick Validation for NS Records ! CVE-2026-48006 8.7 Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator ! CVE-2026-48059 8.7 Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memo ! CVE-2026-55851 8.7 Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbo ! CVE-2026-56745 8.7 Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaust ! CVE-2026-59901 8.7 Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang ! CVE-2026-62243 8.7 Netty 4.2.0 through 4.2.16 TLS Hostname Verification Bypass ! CVE-2026-75596 8.7 Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in defaul ! CVE-2026-56817 8.3 Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entit ! CVE-2025-55163 8.2 Netty MadeYouReset HTTP/2 DDoS Vulnerability ! CVE-2026-44249 8.1 Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking ! CVE-2021-37136 7.5 netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data ! CVE-2021-37137 7.5 netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chu ! CVE-2023-44487 7.5 KEV HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset A ! CVE-2026-33870 7.5 Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing ! CVE-2026-42579 7.5 Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder) ! CVE-2026-42583 7.5 Netty: Lz4FrameDecoder resource exhaustion ! CVE-2026-42587 7.5 Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy e ! CVE-2026-44250 7.5 Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays ! CVE-2026-44890 7.5 Netty has Unbounded Direct Memory Consumption in its RedisDecoder ! CVE-2026-44891 7.5 Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder ! CVE-2026-44893 7.5 Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length ! CVE-2026-45416 7.5 Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes ! CVE-2026-46340 7.5 Netty: SCTP reassembly nests buffers without bound ! CVE-2026-50010 7.5 Netty's wrapping plain trust manager silently disables hostname verification ! CVE-2026-50011 7.5 Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length ! CVE-2026-55831 7.5 Netty SPDY SETTINGS frame count materializes unbounded settings map ! CVE-2026-55833 7.5 Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation ! CVE-2026-56816 7.5 Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types ! CVE-2026-56819 7.5 Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is ! CVE-2026-59902 7.5 Netty: Memory Exhaustion in SctpMessageCompletionHandler ! CVE-2026-73507 7.5 Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion ! CVE-2026-56820 7.4 Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks ! CVE-2026-56821 7.4 Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator ! CVE-2026-56822 7.4 Netty: TOCTOU in OcspServerCertificateValidator ! CVE-2026-42584 7.3 Netty: HttpClientCodec response desynchronization ! CVE-2025-58057 6.9 Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack ! CVE-2026-50560 6.9 Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature ! CVE-2026-59899 6.9 Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Le ! CVE-2026-59900 6.9 Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads ! CVE-2026-42586 6.8 Netty: CRLF Injection in Netty Redis Codec Encoder ! CVE-2026-45673 6.8 Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port ! CVE-2023-34462 6.5 netty-handler SniHandler 16MB allocation ! CVE-2025-67735 6.5 Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder ! CVE-2026-42580 6.5 Netty: HTTP Request Smuggling due to incorrect chunk size parsing ! CVE-2026-42585 6.5 Netty: HTTP Request Smuggling due to malformed Transfer-Encoding ! CVE-2026-56746 6.5 Netty has a Security Control Bypass via CORS Short-Circuit Failure ! CVE-2026-59903 6.5 Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite ! CVE-2026-59920 6.5 Netty: STOMP CONNECT Frame Header Injection ! CVE-2026-59898 6.3 Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation ! CVE-2026-62380 6.3 Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection ! CVE-2021-21290 6.2 Local Information Disclosure Vulnerability in Netty on Unix-Like systems due temporary fil ! CVE-2021-21295 5.9 Possible request smuggling in HTTP/2 due missing validation ! CVE-2021-21409 5.9 Possible request smuggling in HTTP/2 due missing validation of content-length ! CVE-2026-42581 5.8 Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization ! CVE-2026-59921 5.7 Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder ! CVE-2022-24823 5.5 Local Information Disclosure Vulnerability in io.netty:netty-codec-http ! CVE-2024-47535 5.5 Denial of Service attack on windows app using Netty ! CVE-2025-25193 5.5 Denial of Service attack on windows app using Netty ! CVE-2026-59919 5.5 Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address ! CVE-2022-41881 5.3 codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS ! CVE-2024-29025 5.3 Netty HttpPostRequestDecoder can OOM ! CVE-2026-41417 5.3 Netty vulnerable to HTTP request smuggling and RTSP request injection via DefaultHttpReque ! CVE-2026-44248 5.3 Netty: Resource exhaustion in MqttDecoder ! CVE-2026-47244 5.3 Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced ! CVE-2026-48043 5.3 netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Lea ! CVE-2026-50020 5.3 Netty's HttpObjectDecoder skips arbitrary initial control characters when only initial CRL ! CVE-2026-73508 5.3 Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names ! CVE-2026-45536 4.0 Netty: Unix-socket fd receive leaks descriptors when peer sends two at once ! CVE-2026-76816 3.5 Netty: MQTT Topic Name and Client ID Validation Bypass ! CVE-2025-58056 2.9 Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions ! CVE-2026-42578 2.9 Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation lang/asn1c asn1c-0.9.28 ! CVE-2017-12966 6.5 The asn1f_lookup_symbol_impl function in asn1fix_retrieve.c in libasn1fix.a in asn1c 0.9.2 ! CVE-2020-23910 5.5 Stack-based buffer overflow vulnerability in asn1c through v0.9.28 via function genhash_ge ! CVE-2020-23911 5.5 An issue was discovered in asn1c through v0.9.28. A NULL pointer dereference exists in the lang/gnatcross-binutils-aarch64 gnatcross-binutils-aarch64-2.27_1 ! CVE-2017-12448 7.8 binutils: heap use after free in bfd_cache_close function ! CVE-2017-12449 7.8 binutils: out of bounds heap read in _bfd_vms_save_sized_string function ! CVE-2017-12450 7.8 binutils: out of bounds heap write in alpha_vms_object_p function ! CVE-2017-12451 7.8 binutils: out of bounds stack read in _bfd_xcoff_read_ar_hdr function ! CVE-2017-12452 7.8 binutils: out of bounds heap read in bfd_mach_o_i386_canonicalize_one_reloc function ! CVE-2017-12453 7.8 binutils: out of bounds heap read in __bfd_vms_slurp_eeom function ! CVE-2017-12454 7.8 binutils: Arbitrary memory read in _bfd_vms_slurp_egs function ! CVE-2017-12455 7.8 binutils: out of bounds heap read in evax_bfd_print_emh function ! CVE-2017-12456 7.8 binutils: out of bounds heap read in read_symbol_stabs_debugging_inf function ! CVE-2017-12457 7.8 binutils: NULL pointer dereference in bfd_make_section_with_flags function ! CVE-2017-12458 7.8 binutils: out of bounds heap read in nlm_swap_auxiliary_headers_in function ! CVE-2017-12459 7.8 binutils: out of bounds heap write in bfd_mach_o_read_symtab_strtab function ! CVE-2018-1000876 7.8 binutils: integer overflow leads to heap-based buffer overflow in objdump ! CVE-2018-19931 7.8 binutils: Heap-based buffer overflow in bfd_elf32_swap_phdr_in function resulting in a den ! CVE-2021-37322 7.8 binutils: use-after-free in c++filt in cplus-dem.c ! CVE-2021-45078 7.8 binutils: out-of-bounds write in stab_xcoff_builtin_type() in stabs.c ! CVE-2022-44840 7.8 binutils: heap-based buffer overflow in find_section_in_set() in readelf.c ! CVE-2022-45703 7.8 binutils: heap-based buffer overflow in display_debug_section() in readelf.c ! CVE-2022-47673 7.8 binutils: out-of-bounds read in parse_module() in bfd/vms-alpha.c via addr2line ! CVE-2022-47695 7.8 binutils: uninitialized field in bfd_mach_o_get_synthetic_symtab() in match-o.c ! CVE-2022-47696 7.8 binutils: segmentation fault in compare_symbols() in objdump.c ! CVE-2026-6846 7.8 Binutils: binutils: arbitrary code execution via malformed xcoff object file processing ! CVE-2020-35342 7.5 binutils: uninitialized heap memory in tic4x_print_cond() in opcodes/tic4x-dis.c ! CVE-2021-46174 7.5 binutils: heap-based buffer overflow in bfd_getl32() in libbfd.c via objdump ! CVE-2021-20197 6.3 binutils: Race window allows users to own arbitrary files ! CVE-2023-25584 6.3 Out of bounds read in parse_module function in bfd/vms-alpha.c ! CVE-2025-0840 6.3 GNU Binutils objdump.c disassemble_bytes stack-based overflow ! CVE-2025-69647 6.2 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data ! CVE-2025-69648 6.2 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists ! CVE-2025-69652 6.2 binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug inf ! CVE-2020-35494 6.1 binutils: usage of unitialized heap in tic4x_print_cond function in opcodes/tic4x-dis.c ! CVE-2018-19932 5.5 binutils: Integer overflow due to the IS_CONTAINED_BY_LMA macro resulting in a denial of s ! CVE-2018-20671 5.5 binutils: Integer overflow in load_specific_debug_section function ! CVE-2019-1010204 5.5 binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gol ! CVE-2020-19724 5.5 binutils: memory leak in get_data() in nm.c ! CVE-2020-21490 5.5 binutils: memory leak in get_field() in microblaze-dis.c ! CVE-2020-35493 5.5 binutils: heap-based buffer overflow in bfd_pef_parse_function_stubs function in bfd/pef.c ! CVE-2020-35495 5.5 binutils: NULL pointer dereference in bfd_pef_parse_symbols function in bfd/pef.c ! CVE-2020-35496 5.5 binutils: NULL pointer dereference in bfd_pef_scan_start_address function in bfd/pef.c ! CVE-2020-35507 5.5 binutils: NULL pointer dereference in bfd_pef_parse_function_stubs function in bfd/pef.c ! CVE-2022-38533 5.5 binutils: heap-based buffer overflow in bfd_getl32() when called by strip_main() in objcop ! CVE-2022-48063 5.5 binutils: excessive memory consumption in load_separate_debug_files() in dwarf.c ! CVE-2022-48064 5.5 binutils: excessive memory consumption in _bfd_dwarf2_find_nearest_line_with_alt() in dwar ! CVE-2022-48065 5.5 binutils: memory leak in find_abstract_instance() in dwarf2.c ! CVE-2025-69649 5.5 binutils: NULL pointer dereference in readelf via crafted ELF binary ! CVE-2025-69644 5.0 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug inform ! CVE-2025-5244 4.8 GNU Binutils ld elflink.c elf_gc_sweep memory corruption ! CVE-2025-5245 4.8 GNU Binutils objdump debug.c debug_type_samep memory corruption ! CVE-2023-25585 4.7 Field `file_table` of `struct module *module` is uninitialized ! CVE-2023-25586 4.7 Local variable `ch_type` in function `bfd_init_section_decompress_status` can be uninitial ! CVE-2023-25588 4.7 Field `the_bfd` of `asymbol` is uninitialized in function `bfd_mach_o_get_synthetic_symtab lang/gnatdroid-binutils gnatdroid-binutils-2.27_1 ! CVE-2017-12448 7.8 binutils: heap use after free in bfd_cache_close function ! CVE-2017-12449 7.8 binutils: out of bounds heap read in _bfd_vms_save_sized_string function ! CVE-2017-12450 7.8 binutils: out of bounds heap write in alpha_vms_object_p function ! CVE-2017-12451 7.8 binutils: out of bounds stack read in _bfd_xcoff_read_ar_hdr function ! CVE-2017-12452 7.8 binutils: out of bounds heap read in bfd_mach_o_i386_canonicalize_one_reloc function ! CVE-2017-12453 7.8 binutils: out of bounds heap read in __bfd_vms_slurp_eeom function ! CVE-2017-12454 7.8 binutils: Arbitrary memory read in _bfd_vms_slurp_egs function ! CVE-2017-12455 7.8 binutils: out of bounds heap read in evax_bfd_print_emh function ! CVE-2017-12456 7.8 binutils: out of bounds heap read in read_symbol_stabs_debugging_inf function ! CVE-2017-12457 7.8 binutils: NULL pointer dereference in bfd_make_section_with_flags function ! CVE-2017-12458 7.8 binutils: out of bounds heap read in nlm_swap_auxiliary_headers_in function ! CVE-2017-12459 7.8 binutils: out of bounds heap write in bfd_mach_o_read_symtab_strtab function ! CVE-2018-1000876 7.8 binutils: integer overflow leads to heap-based buffer overflow in objdump ! CVE-2018-19931 7.8 binutils: Heap-based buffer overflow in bfd_elf32_swap_phdr_in function resulting in a den ! CVE-2021-37322 7.8 binutils: use-after-free in c++filt in cplus-dem.c ! CVE-2021-45078 7.8 binutils: out-of-bounds write in stab_xcoff_builtin_type() in stabs.c ! CVE-2022-44840 7.8 binutils: heap-based buffer overflow in find_section_in_set() in readelf.c ! CVE-2022-45703 7.8 binutils: heap-based buffer overflow in display_debug_section() in readelf.c ! CVE-2022-47673 7.8 binutils: out-of-bounds read in parse_module() in bfd/vms-alpha.c via addr2line ! CVE-2022-47695 7.8 binutils: uninitialized field in bfd_mach_o_get_synthetic_symtab() in match-o.c ! CVE-2022-47696 7.8 binutils: segmentation fault in compare_symbols() in objdump.c ! CVE-2026-6846 7.8 Binutils: binutils: arbitrary code execution via malformed xcoff object file processing ! CVE-2020-35342 7.5 binutils: uninitialized heap memory in tic4x_print_cond() in opcodes/tic4x-dis.c ! CVE-2021-46174 7.5 binutils: heap-based buffer overflow in bfd_getl32() in libbfd.c via objdump ! CVE-2021-20197 6.3 binutils: Race window allows users to own arbitrary files ! CVE-2023-25584 6.3 Out of bounds read in parse_module function in bfd/vms-alpha.c ! CVE-2025-0840 6.3 GNU Binutils objdump.c disassemble_bytes stack-based overflow ! CVE-2025-69647 6.2 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data ! CVE-2025-69648 6.2 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists ! CVE-2025-69652 6.2 binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug inf ! CVE-2020-35494 6.1 binutils: usage of unitialized heap in tic4x_print_cond function in opcodes/tic4x-dis.c ! CVE-2018-19932 5.5 binutils: Integer overflow due to the IS_CONTAINED_BY_LMA macro resulting in a denial of s ! CVE-2018-20671 5.5 binutils: Integer overflow in load_specific_debug_section function ! CVE-2019-1010204 5.5 binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gol ! CVE-2020-19724 5.5 binutils: memory leak in get_data() in nm.c ! CVE-2020-21490 5.5 binutils: memory leak in get_field() in microblaze-dis.c ! CVE-2020-35493 5.5 binutils: heap-based buffer overflow in bfd_pef_parse_function_stubs function in bfd/pef.c ! CVE-2020-35495 5.5 binutils: NULL pointer dereference in bfd_pef_parse_symbols function in bfd/pef.c ! CVE-2020-35496 5.5 binutils: NULL pointer dereference in bfd_pef_scan_start_address function in bfd/pef.c ! CVE-2020-35507 5.5 binutils: NULL pointer dereference in bfd_pef_parse_function_stubs function in bfd/pef.c ! CVE-2022-38533 5.5 binutils: heap-based buffer overflow in bfd_getl32() when called by strip_main() in objcop ! CVE-2022-48063 5.5 binutils: excessive memory consumption in load_separate_debug_files() in dwarf.c ! CVE-2022-48064 5.5 binutils: excessive memory consumption in _bfd_dwarf2_find_nearest_line_with_alt() in dwar ! CVE-2022-48065 5.5 binutils: memory leak in find_abstract_instance() in dwarf2.c ! CVE-2025-69649 5.5 binutils: NULL pointer dereference in readelf via crafted ELF binary ! CVE-2025-69644 5.0 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug inform ! CVE-2025-5244 4.8 GNU Binutils ld elflink.c elf_gc_sweep memory corruption ! CVE-2025-5245 4.8 GNU Binutils objdump debug.c debug_type_samep memory corruption ! CVE-2023-25585 4.7 Field `file_table` of `struct module *module` is uninitialized ! CVE-2023-25586 4.7 Local variable `ch_type` in function `bfd_init_section_decompress_status` can be uninitial ! CVE-2023-25588 4.7 Field `the_bfd` of `asymbol` is uninitialized in function `bfd_mach_o_get_synthetic_symtab lang/gnatdroid-binutils-x86 gnatdroid-binutils-x86-2.27_1 ! CVE-2017-12448 7.8 binutils: heap use after free in bfd_cache_close function ! CVE-2017-12449 7.8 binutils: out of bounds heap read in _bfd_vms_save_sized_string function ! CVE-2017-12450 7.8 binutils: out of bounds heap write in alpha_vms_object_p function ! CVE-2017-12451 7.8 binutils: out of bounds stack read in _bfd_xcoff_read_ar_hdr function ! CVE-2017-12452 7.8 binutils: out of bounds heap read in bfd_mach_o_i386_canonicalize_one_reloc function ! CVE-2017-12453 7.8 binutils: out of bounds heap read in __bfd_vms_slurp_eeom function ! CVE-2017-12454 7.8 binutils: Arbitrary memory read in _bfd_vms_slurp_egs function ! CVE-2017-12455 7.8 binutils: out of bounds heap read in evax_bfd_print_emh function ! CVE-2017-12456 7.8 binutils: out of bounds heap read in read_symbol_stabs_debugging_inf function ! CVE-2017-12457 7.8 binutils: NULL pointer dereference in bfd_make_section_with_flags function ! CVE-2017-12458 7.8 binutils: out of bounds heap read in nlm_swap_auxiliary_headers_in function ! CVE-2017-12459 7.8 binutils: out of bounds heap write in bfd_mach_o_read_symtab_strtab function ! CVE-2018-1000876 7.8 binutils: integer overflow leads to heap-based buffer overflow in objdump ! CVE-2018-19931 7.8 binutils: Heap-based buffer overflow in bfd_elf32_swap_phdr_in function resulting in a den ! CVE-2021-37322 7.8 binutils: use-after-free in c++filt in cplus-dem.c ! CVE-2021-45078 7.8 binutils: out-of-bounds write in stab_xcoff_builtin_type() in stabs.c ! CVE-2022-44840 7.8 binutils: heap-based buffer overflow in find_section_in_set() in readelf.c ! CVE-2022-45703 7.8 binutils: heap-based buffer overflow in display_debug_section() in readelf.c ! CVE-2022-47673 7.8 binutils: out-of-bounds read in parse_module() in bfd/vms-alpha.c via addr2line ! CVE-2022-47695 7.8 binutils: uninitialized field in bfd_mach_o_get_synthetic_symtab() in match-o.c ! CVE-2022-47696 7.8 binutils: segmentation fault in compare_symbols() in objdump.c ! CVE-2026-6846 7.8 Binutils: binutils: arbitrary code execution via malformed xcoff object file processing ! CVE-2020-35342 7.5 binutils: uninitialized heap memory in tic4x_print_cond() in opcodes/tic4x-dis.c ! CVE-2021-46174 7.5 binutils: heap-based buffer overflow in bfd_getl32() in libbfd.c via objdump ! CVE-2021-20197 6.3 binutils: Race window allows users to own arbitrary files ! CVE-2023-25584 6.3 Out of bounds read in parse_module function in bfd/vms-alpha.c ! CVE-2025-0840 6.3 GNU Binutils objdump.c disassemble_bytes stack-based overflow ! CVE-2025-69647 6.2 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data ! CVE-2025-69648 6.2 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists ! CVE-2025-69652 6.2 binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug inf ! CVE-2020-35494 6.1 binutils: usage of unitialized heap in tic4x_print_cond function in opcodes/tic4x-dis.c ! CVE-2018-19932 5.5 binutils: Integer overflow due to the IS_CONTAINED_BY_LMA macro resulting in a denial of s ! CVE-2018-20671 5.5 binutils: Integer overflow in load_specific_debug_section function ! CVE-2019-1010204 5.5 binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gol ! CVE-2020-19724 5.5 binutils: memory leak in get_data() in nm.c ! CVE-2020-21490 5.5 binutils: memory leak in get_field() in microblaze-dis.c ! CVE-2020-35493 5.5 binutils: heap-based buffer overflow in bfd_pef_parse_function_stubs function in bfd/pef.c ! CVE-2020-35495 5.5 binutils: NULL pointer dereference in bfd_pef_parse_symbols function in bfd/pef.c ! CVE-2020-35496 5.5 binutils: NULL pointer dereference in bfd_pef_scan_start_address function in bfd/pef.c ! CVE-2020-35507 5.5 binutils: NULL pointer dereference in bfd_pef_parse_function_stubs function in bfd/pef.c ! CVE-2022-38533 5.5 binutils: heap-based buffer overflow in bfd_getl32() when called by strip_main() in objcop ! CVE-2022-48063 5.5 binutils: excessive memory consumption in load_separate_debug_files() in dwarf.c ! CVE-2022-48064 5.5 binutils: excessive memory consumption in _bfd_dwarf2_find_nearest_line_with_alt() in dwar ! CVE-2022-48065 5.5 binutils: memory leak in find_abstract_instance() in dwarf2.c ! CVE-2025-69649 5.5 binutils: NULL pointer dereference in readelf via crafted ELF binary ! CVE-2025-69644 5.0 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug inform ! CVE-2025-5244 4.8 GNU Binutils ld elflink.c elf_gc_sweep memory corruption ! CVE-2025-5245 4.8 GNU Binutils objdump debug.c debug_type_samep memory corruption ! CVE-2023-25585 4.7 Field `file_table` of `struct module *module` is uninitialized ! CVE-2023-25586 4.7 Local variable `ch_type` in function `bfd_init_section_decompress_status` can be uninitial ! CVE-2023-25588 4.7 Field `the_bfd` of `asymbol` is uninitialized in function `bfd_mach_o_get_synthetic_symtab lang/go125 go125-1.25.14_1 ! CVE-2024-24786 7.5 Infinite loop in JSON unmarshaling in google.golang.org/protobuf ! CVE-2024-24787 6.4 Arbitrary code execution during build on Darwin in cmd/go lang/go126 go126-1.26.8 ! CVE-2024-24786 7.5 Infinite loop in JSON unmarshaling in google.golang.org/protobuf ! CVE-2024-24787 6.4 Arbitrary code execution during build on Darwin in cmd/go lang/go127 go127-1.27.1 ! CVE-2024-24786 7.5 Infinite loop in JSON unmarshaling in google.golang.org/protobuf ! CVE-2024-24787 6.4 Arbitrary code execution during build on Darwin in cmd/go lang/guile1 guile1-1.8.8_2 ! CVE-2016-8605 5.3 guile: Thread-unsafe umask modification lang/hermes hermes-javascript-engine-0.13.0_1 ! CVE-2020-1914 9.8 A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes p ! CVE-2023-23556 9.8 An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f56 ! CVE-2023-23557 9.8 An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894 ! CVE-2020-1915 7.5 An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb ! CVE-2023-24832 7.5 A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27fdd8b01f103 ! CVE-2023-24833 7.5 A use-after-free in BigIntPrimitive addition in Hermes prior to commit a6dcafe6ded8e61658b lang/linux-rl9-python3 linux-rl9-python39-3.9.25 ! CVE-2026-15308 8.7 Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup d ! CVE-2026-4519 7.0 webbrowser.open() allows leading dashes in URLs ! CVE-2025-12084 6.3 Quadratic complexity in node ID cache clearing ! CVE-2025-12781 6.3 base64.b64decode() always accepts "+/" characters, despite setting altchars ! CVE-2025-13836 6.3 Excessive read buffering DoS in http.client ! CVE-2026-7210 6.3 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protectio ! CVE-2026-3644 6.0 Incomplete control character validation in http.cookies ! CVE-2026-4224 6.0 Stack overflow parsing XML with deeply nested DTD content models ! CVE-2026-0864 4.1 Configuration Injection via Carriage Return (\r) in write() method ! CVE-2025-13837 2.1 Out-of-memory when loading Plist ! CVE-2026-6019 2.1 BaseCookie.js_output() does not neutralize embedded characters ! CVE-2025-13462 2.0 tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling lang/lua51 lua51-5.1.5_10 ! CVE-2021-43519 5.5 lua: stack overflow in lua_resume of ldo.c allows a DoS via a crafted script file ! CVE-2014-5461 5.0 lua: overflow flaw in vararg functions lang/lua52 lua52-5.2.4_1 ! CVE-2021-43519 5.5 lua: stack overflow in lua_resume of ldo.c allows a DoS via a crafted script file lang/lua53 lua53-5.3.6_1 ! CVE-2020-15945 5.5 lua: segmentation fault in changedline in ldebug.c lang/mujs mujs-1.3.9 ! CVE-2016-10141 9.8 An integer overflow vulnerability was observed in the regemit function in regexp.c in Arti ! CVE-2016-7504 9.8 A use-after-free vulnerability was observed in Rp_toString function of Artifex Software, I ! CVE-2017-5627 7.8 An issue was discovered in Artifex Software, Inc. MuJS before 4006739a28367c708dea19aeb19b ! CVE-2017-5628 7.8 An issue was discovered in Artifex Software, Inc. MuJS before 8f62ea10a0af68e56d5c00720523 ! CVE-2016-7506 7.5 An out-of-bounds read vulnerability was observed in Sp_replace_regexp function of Artifex ! CVE-2016-9017 7.5 Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context ! CVE-2016-9108 7.5 Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS bef ! CVE-2016-9136 7.5 Artifex Software, Inc. MuJS before a0ceaf5050faf419401fe1b83acfa950ec8a8a89 allows context ! CVE-2016-9294 7.5 Artifex Software, Inc. MuJS before 5008105780c0b0182ea6eda83ad5598f225be3ee allows context lang/perl5.40 perl5.40-5.40.5 ! CVE-2025-40909 5.9 Perl threads have a working directory race condition where file operations may target unin ! CVE-2026-19487 5.3 Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results lang/picoc picoc-2.1_2 ! CVE-2019-16277 7.8 PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called lang/python27 python27-2.7.18_5 ! CVE-2007-4559 9.8 python: tarfile module directory traversal ! CVE-2022-48565 9.8 python: XML External Entity in XML processing plistlib module ! CVE-2026-15308 8.7 Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup d ! CVE-2022-0391 7.5 python: urllib.parse does not sanitize URLs containing ASCII newline and tabs ! CVE-2022-45061 7.5 python: CPU denial of service via inefficient IDNA decoder ! CVE-2022-48560 7.5 python: use after free in heappushpop() of heapq module ! CVE-2023-24329 7.5 python: urllib.parse url blocklisting bypass ! CVE-2024-6232 7.5 Regular-expression DoS when parsing TarFile headers ! CVE-2024-7592 7.5 Quadratic complexity parsing cookies with backslashes ! CVE-2026-4519 7.0 webbrowser.open() allows leading dashes in URLs ! CVE-2021-3733 6.5 python: urllib: Regular expression DoS in AbstractBasicAuthHandler ! CVE-2022-48564 6.5 python: DoS when processing malformed Apple Property List files in binary format ! CVE-2025-12084 6.3 Quadratic complexity in node ID cache clearing ! CVE-2025-12781 6.3 base64.b64decode() always accepts "+/" characters, despite setting altchars ! CVE-2025-13836 6.3 Excessive read buffering DoS in http.client ! CVE-2026-7210 6.3 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protectio ! CVE-2026-3644 6.0 Incomplete control character validation in http.cookies ! CVE-2026-4224 6.0 Stack overflow parsing XML with deeply nested DTD content models ! CVE-2021-23336 5.9 Web Cache Poisoning ! CVE-2022-48566 5.9 python: constant-time-defeating optimisations issue in the compare_digest function in Lib/ ! CVE-2023-27043 5.3 python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address par ! CVE-2023-40217 5.3 python: TLS handshake bypass ! CVE-2024-9287 5.3 Virtual environment (venv) activation scripts don't quote paths ! CVE-2026-0864 4.1 Configuration Injection via Carriage Return (\r) in write() method ! CVE-2025-13837 2.1 Out-of-memory when loading Plist ! CVE-2026-6019 2.1 BaseCookie.js_output() does not neutralize embedded characters ! CVE-2025-13462 2.0 tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling ! CVE-2026-4360 2.0 Tarfile.extract() doesn't fully respect filter parameter ! CVE-2025-6075 1.8 Quadratic complexity in os.path.expandvars() with user-controlled template lang/python310 python310-3.10.21 ! CVE-2026-4519 7.0 webbrowser.open() allows leading dashes in URLs ! CVE-2025-12084 6.3 Quadratic complexity in node ID cache clearing ! CVE-2025-12781 6.3 base64.b64decode() always accepts "+/" characters, despite setting altchars ! CVE-2026-7210 6.3 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protectio ! CVE-2026-3644 6.0 Incomplete control character validation in http.cookies ! CVE-2025-13837 2.1 Out-of-memory when loading Plist ! CVE-2026-6019 2.1 BaseCookie.js_output() does not neutralize embedded characters ! CVE-2025-13462 2.0 tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling lang/python311 python311-3.11.16 ! CVE-2026-4519 7.0 webbrowser.open() allows leading dashes in URLs ! CVE-2025-12084 6.3 Quadratic complexity in node ID cache clearing ! CVE-2025-12781 6.3 base64.b64decode() always accepts "+/" characters, despite setting altchars ! CVE-2026-7210 6.3 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protectio ! CVE-2026-3644 6.0 Incomplete control character validation in http.cookies ! CVE-2025-13837 2.1 Out-of-memory when loading Plist ! CVE-2026-6019 2.1 BaseCookie.js_output() does not neutralize embedded characters ! CVE-2025-13462 2.0 tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling lang/python312 python312-3.12.14 ! CVE-2026-4519 7.0 webbrowser.open() allows leading dashes in URLs ! CVE-2025-12084 6.3 Quadratic complexity in node ID cache clearing ! CVE-2025-12781 6.3 base64.b64decode() always accepts "+/" characters, despite setting altchars ! CVE-2026-7210 6.3 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protectio ! CVE-2026-3644 6.0 Incomplete control character validation in http.cookies ! CVE-2025-13837 2.1 Out-of-memory when loading Plist ! CVE-2026-6019 2.1 BaseCookie.js_output() does not neutralize embedded characters ! CVE-2025-13462 2.0 tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling lang/quickjs-ng quickjs-ng-0.16.2 ! CVE-2020-22876 7.5 Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause de ! CVE-2023-48183 7.5 QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an ! CVE-2025-46687 5.6 quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading ! CVE-2025-46688 5.6 quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, ! CVE-2023-48184 3.9 QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect lang/v8 v8-10.4.132.20_4 ! CVE-2024-1939 8.8 Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to ! CVE-2026-85046 8.8 KEV Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to lang/v8-beta v8-beta-10.4.132.20_4 ! CVE-2024-1939 8.8 Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to ! CVE-2026-85046 8.8 KEV Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to mail/dovecot dovecot-2.3.21.1_3 ! CVE-2022-30550 8.8 dovecot: Privilege escalation when similar master and non-master passdbs are used ! CVE-2026-24031 7.7 dovecot: Dovecot: Authentication bypass and user enumeration due to cleared auth_username_ ! CVE-2025-59032 7.5 dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE ! CVE-2026-27858 7.5 dovecot: denial of service via crafted message before authentication ! CVE-2026-27851 7.4 When safe filter is used with variable expansion, all following pipelines on the same stri ! CVE-2026-27856 7.4 dovecot: Doveadm: Full access via timing oracle attack in credential verification ! CVE-2026-27855 6.8 dovecot: Dovecot: Replay attack allows unauthorized login via observed One-Time Password ( ! CVE-2026-33603 6.8 dovecot: Dovecot: Information disclosure via SCRAM TLS channel binding bypass ! CVE-2025-59028 5.3 dovecot: Dovecot: Denial of Service via invalid SASL data ! CVE-2026-0394 5.3 dovecot: Dovecot: Information disclosure and authentication bypass via path traversal ! CVE-2026-27859 5.3 dovecot: Dovecot: Denial of Service via excessive RFC 2231 MIME parameters ! CVE-2026-40016 5.3 dovecot: Dovecot: Denial of Service due to Sieve script CPU limit bypass ! CVE-2025-59031 4.3 dovecot: Dovecot: Information disclosure via specially crafted OOXML documents ! CVE-2026-27857 4.3 dovecot: denial of service via specially crafted NOOP command ! CVE-2026-42006 4.3 An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix ! CVE-2026-27860 3.7 dovecot: Dovecot: Authentication bypass and information disclosure via LDAP filter injecti ! CVE-2026-40020 3.1 dovecot: dovecot: Denial of Service via IMAP SETACL command injection mail/heirloom-mailx heirloom-mailx-12.4_11 ! CVE-2004-2771 7.5 mailx: command execution flaw mail/libspf2 libspf2-1.2.11_2 ! CVE-2021-20314 9.8 Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros mail/mailman mailman-2.1.39_4 ! CVE-2021-34337 6.3 mailman: password checking timing attack in administrative REST API mail/mailman-exim4 mailman-exim4-2.1.39_4 ! CVE-2021-34337 6.3 mailman: password checking timing attack in administrative REST API mail/mailman-postfix mailman-postfix-2.1.39_4 ! CVE-2021-34337 6.3 mailman: password checking timing attack in administrative REST API mail/mutt mutt-2.4.2 ! CVE-2024-49393 6.5 Mutt: neomutt: to and cc email header fields are not protected by cryptographic signing ! CVE-2024-49394 5.3 Mutt: neomutt: in-reply-to email header field it not protected by cryptograpic signing ! CVE-2024-49395 5.3 Mutt: neomutt: bcc email header field is indirectly leaked by cryptographic info block mail/nextcloud-mail nextcloud-mail-php84-5.11.5 ! CVE-2024-52508 8.2 Nextcloud Mail auto configurator can be tricked into sending account information to wrong mail/opendkim opendkim-2.10.3_23 ! CVE-2020-35766 7.8 The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privil ! CVE-2022-48521 5.3 An issue was discovered in OpenDKIM through 2.10.3, and 2.11.x through 2.11.0-Beta2. It fa mail/opendmarc opendmarc-1.4.2_4 ! CVE-2024-25768 7.5 OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendma mail/phpmailer phpmailer-5.2.28_1 ! CVE-2021-3603 8.1 Inclusion of Functionality from Untrusted Control Sphere in PHPMailer/PHPMailer ! CVE-2020-13625 7.5 PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment mail/procmail procmail-3.22_11 ! CVE-2017-16844 9.8 procmail: Heap-based buffer overflow in loadbuf function in formisc.c ! CVE-2014-3618 7.5 procmail: Heap-overflow in procmail's formail utility when processing specially-crafted em mail/qmail netqmail-1.06_7 ! CVE-2020-3811 7.5 qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulne ! CVE-2020-3812 5.5 qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. mail/roundcube-classic roundcube-classic-php84-1.6.0.4 ! CVE-2025-49113 9.9 KEV roundcubemail: Remote Code Execution in Roundcube via Unvalidated _from Parameter ! CVE-2024-37385 9.8 Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection ! CVE-2024-42008 9.3 A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through ! CVE-2024-42009 9.3 KEV A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 al ! CVE-2026-74997 8.8 Remote Code Execution in Roundcube MarkAsJunk Plugin via Crafted Placeholder Values ! CVE-2026-48842 8.1 Pre-Authentication SQL Injection in Roundcube's virtuser_query Plugin ! CVE-2026-48844 7.5 LDAP Autovalues Code Injection in Roundcube Webmail ! CVE-2025-68460 7.2 roundcubemail: Roundcube Webmail: Information Disclosure via HTML Style Sanitizer ! CVE-2025-68461 7.2 KEV roundcubemail: Roundcube Webmail: Cross-Site Scripting (XSS) vulnerability via crafted SVG ! CVE-2026-48848 7.2 CSS Injection via SVG in Roundcube Webmail ! CVE-2026-54433 7.2 Stored XSS via crafted plain-text email in Roundcube Webmail ! CVE-2026-62643 7.2 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sh ! CVE-2026-74998 7.2 Unvalidated CSS Proxy Response Causing XSS and Information Disclosure in Roundcube Webmail ! CVE-2026-75002 7.1 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-c ! CVE-2026-48846 6.5 In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking ! CVE-2026-62644 6.4 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roun ! CVE-2026-75010 6.4 Roundcube Webmail Password Plugin Modoboa Driver Token Leakage ! CVE-2023-43770 6.1 KEV Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/pl ! CVE-2023-47272 6.1 Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Conte ! CVE-2023-5631 6.1 KEV Stored XSS vulnerability in Roundcube ! CVE-2024-37383 6.1 KEV roundcubemail: allows XSS via SVG animate attributes ! CVE-2024-37384 6.1 Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from use ! CVE-2026-35539 6.1 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because ! CVE-2026-75000 5.8 SVG Animate Attribute Sanitization Leading to Remote Image Blocking Bypass in Roundcube We ! CVE-2026-75003 5.8 SVG FuncIRI URL Evades Remote Image Blocking in Roundcube Webmail ! CVE-2026-75006 5.8 Insufficient CSS Sanitization in Roundcube Webmail Enables SSRF and Information Disclosure ! CVE-2026-35540 5.4 Roundcube Webmail CSS Sanitization Issue Allows SSRF and Information Disclosure ! CVE-2026-74999 5.4 Stored XSS in Roundcube Add to Address Book ! CVE-2026-75007 5.4 LDAP Search Filter Injection in Roundcube Webmail ! CVE-2026-35542 5.3 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image bl ! CVE-2026-35543 5.3 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image bl ! CVE-2026-35544 5.3 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascad ! CVE-2026-35545 5.3 SVG Bypass of Remote Image Blocking in Roundcube Webmail ! CVE-2026-26079 4.7 roundcubemail: Roundcube Webmail: Cascading Style Sheets (CSS) injection via mishandled co ! CVE-2026-54432 4.7 Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting ! CVE-2026-48849 4.4 Stored XSS via Unvalidated Subject Field in Draft Restoration for Roundcube Webmail ! CVE-2026-25916 4.3 Bypass of Block Remote Images in Roundcube via SVG feImage ! CVE-2026-62641 4.3 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to ! CVE-2026-62642 4.3 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered ! CVE-2026-75004 4.3 Improper Rule Name Quoting Allows managesieve Disabled Actions Bypass in Roundcube Webmail ! CVE-2026-35541 4.2 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password ! CVE-2026-35537 3.7 Roundcube Webmail Unsafe Deserialization Enables Unauthenticated File Write via Session Da ! CVE-2026-48847 3.7 Pre-authentication Arbitrary File Deletion via Session Poisoning in Roundcube Webmail ! CVE-2026-35538 3.1 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SE mail/roundcube-larry roundcube-larry-php84-1.6.1.3 ! CVE-2025-49113 9.9 KEV roundcubemail: Remote Code Execution in Roundcube via Unvalidated _from Parameter ! CVE-2024-37385 9.8 Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection ! CVE-2024-42008 9.3 A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through ! CVE-2024-42009 9.3 KEV A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 al ! CVE-2026-74997 8.8 Remote Code Execution in Roundcube MarkAsJunk Plugin via Crafted Placeholder Values ! CVE-2026-48842 8.1 Pre-Authentication SQL Injection in Roundcube's virtuser_query Plugin ! CVE-2026-48844 7.5 LDAP Autovalues Code Injection in Roundcube Webmail ! CVE-2025-68460 7.2 roundcubemail: Roundcube Webmail: Information Disclosure via HTML Style Sanitizer ! CVE-2025-68461 7.2 KEV roundcubemail: Roundcube Webmail: Cross-Site Scripting (XSS) vulnerability via crafted SVG ! CVE-2026-48848 7.2 CSS Injection via SVG in Roundcube Webmail ! CVE-2026-54433 7.2 Stored XSS via crafted plain-text email in Roundcube Webmail ! CVE-2026-62643 7.2 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sh ! CVE-2026-74998 7.2 Unvalidated CSS Proxy Response Causing XSS and Information Disclosure in Roundcube Webmail ! CVE-2026-75002 7.1 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-c ! CVE-2026-48846 6.5 In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking ! CVE-2026-62644 6.4 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roun ! CVE-2026-75010 6.4 Roundcube Webmail Password Plugin Modoboa Driver Token Leakage ! CVE-2023-43770 6.1 KEV Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/pl ! CVE-2023-47272 6.1 Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Conte ! CVE-2023-5631 6.1 KEV Stored XSS vulnerability in Roundcube ! CVE-2024-37383 6.1 KEV roundcubemail: allows XSS via SVG animate attributes ! CVE-2024-37384 6.1 Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from use ! CVE-2026-35539 6.1 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because ! CVE-2026-75000 5.8 SVG Animate Attribute Sanitization Leading to Remote Image Blocking Bypass in Roundcube We ! CVE-2026-75003 5.8 SVG FuncIRI URL Evades Remote Image Blocking in Roundcube Webmail ! CVE-2026-75006 5.8 Insufficient CSS Sanitization in Roundcube Webmail Enables SSRF and Information Disclosure ! CVE-2026-35540 5.4 Roundcube Webmail CSS Sanitization Issue Allows SSRF and Information Disclosure ! CVE-2026-74999 5.4 Stored XSS in Roundcube Add to Address Book ! CVE-2026-75007 5.4 LDAP Search Filter Injection in Roundcube Webmail ! CVE-2026-35542 5.3 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image bl ! CVE-2026-35543 5.3 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image bl ! CVE-2026-35544 5.3 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascad ! CVE-2026-35545 5.3 SVG Bypass of Remote Image Blocking in Roundcube Webmail ! CVE-2026-26079 4.7 roundcubemail: Roundcube Webmail: Cascading Style Sheets (CSS) injection via mishandled co ! CVE-2026-54432 4.7 Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting ! CVE-2026-48849 4.4 Stored XSS via Unvalidated Subject Field in Draft Restoration for Roundcube Webmail ! CVE-2026-25916 4.3 Bypass of Block Remote Images in Roundcube via SVG feImage ! CVE-2026-62641 4.3 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to ! CVE-2026-62642 4.3 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered ! CVE-2026-75004 4.3 Improper Rule Name Quoting Allows managesieve Disabled Actions Bypass in Roundcube Webmail ! CVE-2026-35541 4.2 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password ! CVE-2026-35537 3.7 Roundcube Webmail Unsafe Deserialization Enables Unauthenticated File Write via Session Da ! CVE-2026-48847 3.7 Pre-authentication Arbitrary File Deletion via Session Poisoning in Roundcube Webmail ! CVE-2026-35538 3.1 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SE mail/sylpheed sylpheed-3.7.0_9 ! CVE-2021-37746 6.1 textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed throug mail/sympa sympa-6.2.78 ! CVE-2018-1000671 6.1 sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Ope math/btor2tools btor2tools-g20320816 ! CVE-2019-7559 5.5 In btor2parser/btor2parser.c in Boolector Btor2Tools before 2019-01-15, opening a speciall math/gnuplot-tex-extras gnuplot-tex-extras-5.2.8_1 ! CVE-2025-31176 6.2 Gnuplot: gnuplot segmentation fault on plot3d_points ! CVE-2025-31178 6.2 Gnuplot: gnuplot segmentation fault on getannotatestring ! CVE-2025-31179 6.2 Gnuplot: gnuplot segmentation fault on xstrftime ! CVE-2025-31180 6.2 Gnuplot: gnuplot segmentation fault on canvas_text ! CVE-2025-31181 6.2 Gnuplot: gnuplot segmentation fault on x11_graphics ! CVE-2025-31177 5.5 Gnuplot: gnuplot heap-buffer overflow on utf8_copy_one math/libxls libxls-1.6.3 ! CVE-2026-26824 6.5 libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the O ! CVE-2026-26825 5.3 Use‑of‑Uninitialized Memory in libxls 1.6.3 During XLS Parsing math/py-PuLP py312-PuLP-3.3.2 ! CVE-2024-7143 8.3 Pulpcore: rbac permissions incorrectly assigned in tasks that create objects misc/amanda-client amanda-client-3.5.1_1,1 ! CVE-2022-37703 3.3 amanda: information leak (discovery of directory existence) misc/amanda-server amanda-server-3.5.1_1,1 ! CVE-2022-37703 3.3 amanda: information leak (discovery of directory existence) misc/concourse concourse-8.2.4_4 ! CVE-2018-1227 7.5 Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified imp multimedia/Bento4 Bento4-1.6.0_3 ! CVE-2021-32265 8.8 An issue was discovered in Bento4 through v1.6.0-637. A global-buffer-overflow exists in t ! CVE-2020-23330 7.5 An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in th ! CVE-2020-23333 7.5 A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in ! CVE-2020-23334 7.5 A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom co ! CVE-2025-0751 6.9 Axiomatic Bento4 mp42aac ReadBits heap-based overflow ! CVE-2025-0753 6.9 Axiomatic Bento4 mp42aac ReadPartial heap-based overflow ! CVE-2021-35306 6.5 An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in ! CVE-2021-35307 6.5 An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in ! CVE-2022-40737 6.5 An issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the func ! CVE-2022-40738 6.5 An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in ! CVE-2022-4584 6.3 Axiomatic Bento4 mp42aac heap-based overflow ! CVE-2025-0870 6.3 Axiomatic Bento4 Ap4DataBuffer.h GetData heap-based overflow ! CVE-2025-8537 6.3 Axiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resources ! CVE-2020-23912 5.5 An issue was discovered in Bento4 through v1.6.0-637. A NULL pointer dereference exists in ! CVE-2022-29017 5.5 Bento4 v1.6.0.0 was discovered to contain a segmentation fault via the component /x86_64/m ! CVE-2022-40774 5.5 An issue was discovered in Bento4 through 1.6.0-639. There is a NULL pointer dereference i ! CVE-2022-40775 5.5 An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in ! CVE-2022-40884 5.5 Bento4 1.6.0 has memory leaks via the mp4fragment. ! CVE-2022-41841 5.5 An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in ! CVE-2022-3809 4.3 Axiomatic Bento4 mp4tag Mp4Tag.cpp ParseCommandLine denial of service ! CVE-2022-3810 4.3 Axiomatic Bento4 mp42hevc Mp42Hevc.cpp AP4_File denial of service multimedia/assimp assimp-6.0.5 ! CVE-2026-14610 4.8 Open Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile heap-based overflow multimedia/ffmpeg ffmpeg-9.0.1,1 ! CVE-2025-25468 6.5 FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the comp ! CVE-2025-25469 6.5 FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the comp multimedia/ffmpeg3 ffmpeg3-3.0.2_1 ! CVE-2016-10190 9.8 Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0 ! CVE-2016-10191 9.8 Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before ! CVE-2016-10192 9.8 Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1. ! CVE-2016-6164 9.8 Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8 ! CVE-2017-7859 9.8 FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow ! CVE-2018-1999010 9.8 FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of arr ! CVE-2019-12730 9.8 aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does no ! CVE-2019-17539 9.8 In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereferenc ! CVE-2017-14767 8.8 The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3. ! CVE-2017-15672 8.8 The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earl ! CVE-2017-9990 8.8 Stack-based buffer overflow in the color_string_to_rgba function in libavcodec/xpmdec.c in ! CVE-2017-9992 8.8 Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg befor ! CVE-2018-1999011 8.8 FFmpeg before commit 2b46ebdbff1d8dec7a3d8ea280a612b91a582869 contains a Buffer Overflow v ! CVE-2018-9841 8.8 The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote at ! CVE-2019-15942 8.8 ffmpeg: conditional jump or move depends on uninitialised value ! CVE-2026-8461 8.8 Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder ! CVE-2026-64830 8.7 FFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle Demuxer ! CVE-2026-64834 8.7 FFmpeg 0.6.3 - 8.1.2 Infinite Loop DoS via RTP/ASF Demuxer ! CVE-2026-66039 8.7 FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File ! CVE-2026-66040 8.7 FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder ! CVE-2026-65703 8.5 FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder ! CVE-2026-65706 8.5 FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing ! CVE-2026-70628 8.5 FFmpeg 0.5 < 9.0 DVB Subtitle Parser Heap Buffer Overflow via WTV File ! CVE-2022-48434 8.1 libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leav ! CVE-2016-6671 7.8 The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows remote attack ! CVE-2016-7450 7.8 The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable t ! CVE-2016-7502 7.8 The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable ! CVE-2017-11399 7.8 Integer overflow in the ape_decode_frame function in libavcodec/apedec.c in FFmpeg 2.4 thr ! CVE-2017-11719 7.8 The dnxhd_decode_header function in libavcodec/dnxhddec.c in FFmpeg 3.0 through 3.3.2 allo ! CVE-2017-9991 7.8 Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec.c in FFmp ! CVE-2017-9994 7.8 libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x b ! CVE-2017-9996 7.8 The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x b ! CVE-2026-66036 7.7 FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter ! CVE-2016-6920 7.5 Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg befo ! CVE-2017-9993 7.5 FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3 ! CVE-2021-38291 7.5 FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an ass ! CVE-2022-3109 7.5 An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c ! CVE-2023-6603 7.5 Ffmpeg: null pointer dereference in ffmpeg hls parsing ! CVE-2024-31578 7.5 FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_c ! CVE-2026-30997 7.5 FFmpeg: FFmpeg: Denial of Service via out-of-bounds read ! CVE-2026-30998 7.5 FFmpeg: FFmpeg: Denial of Service vulnerability in zmqsend.c via crafted input ! CVE-2026-30999 7.5 FFmpeg: FFmpeg: Denial of Service via heap buffer overflow in av_bprint_finalize() ! CVE-2026-65704 7.3 FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder ! CVE-2023-6605 7.2 Ffmpeg: dash playlist ssrf vulnerability in ffmpeg ! CVE-2025-9951 7.2 Remote code execution via Heap Buffer Overflow in FFmpeg JPEG2000 ! CVE-2026-64833 7.1 FFmpeg 0.7.1 - 8.1.2 Out-of-Bounds Read via S/PDIF Muxer spdifenc.c ! CVE-2026-66037 7.1 FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu() ! CVE-2026-66038 7.1 FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c ! CVE-2024-7055 6.9 FFmpeg pnmdec.c pnm_decode_frame heap-based overflow ! CVE-2026-70629 6.8 FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder ! CVE-2026-70630 6.8 FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder ! CVE-2026-70631 6.8 FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder ! CVE-2017-15186 6.5 Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a d ! CVE-2017-9608 6.5 The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers t ! CVE-2018-10001 6.5 The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote ! CVE-2018-14394 6.5 libavformat/movenc.c in FFmpeg before 4.0.2 allows attackers to cause a denial of service ! CVE-2018-1999012 6.5 FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite ! CVE-2018-1999013 6.5 FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vu ! CVE-2018-1999014 6.5 FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array acc ! CVE-2018-1999015 6.5 FFmpeg before commit 5aba5b89d0b1d73164d3b81764828bb8b20ff32a contains an out of array rea ! CVE-2018-6392 6.5 The filter_slice function in libavfilter/vf_transpose.c in FFmpeg through 3.4.1 allows rem ! CVE-2018-6621 6.5 The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote a ! CVE-2018-6912 6.5 The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote ! CVE-2018-7557 6.5 The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows rem ! CVE-2018-7751 6.5 The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote atta ! CVE-2025-25468 6.5 FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the comp ! CVE-2025-25469 6.5 FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the comp ! CVE-2024-36617 6.2 FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder. ! CVE-2016-6881 5.5 The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote atta ! CVE-2016-7122 5.5 The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable t ! CVE-2016-7555 5.5 The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable ! CVE-2016-7562 5.5 The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote ! CVE-2016-7785 5.5 The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote at ! CVE-2016-7905 5.5 The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote at ! CVE-2016-8595 5.5 The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote att ! CVE-2016-9561 5.5 The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows r ! CVE-2021-3566 5.5 Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned ! CVE-2022-1475 5.5 An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0 ! CVE-2022-3341 5.3 A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() functi ! CVE-2023-6602 5.3 Ffmpeg: improper handling of input format in tty demuxer of ffmpeg ! CVE-2023-6604 5.3 Ffmpeg: hls xbin demuxer dos amplification in ffmpeg ! CVE-2025-1594 5.3 FFmpeg AAC Encoder aacenc_tns.c ff_aac_search_for_tns stack-based overflow ! CVE-2025-7700 5.3 Ffmpeg: null pointer dereference in ffmpeg als decoder (libavcodec/alsdec.c) ! CVE-2025-1373 4.8 FFmpeg MOV Parser mov.c mov_read_trak null pointer dereference ! CVE-2023-6601 4.7 Ffmpeg: hls unsafe file extension bypass in ffmpeg multimedia/ffmpeg4 ffmpeg4-4.4.7_1 ! CVE-2026-8461 8.8 Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder ! CVE-2026-64830 8.7 FFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle Demuxer ! CVE-2026-64832 8.7 FFmpeg 4.4 - 8.1.2 Double-Free in NVDEC Hardware Decoder via nvdec.c ! CVE-2026-64834 8.7 FFmpeg 0.6.3 - 8.1.2 Infinite Loop DoS via RTP/ASF Demuxer ! CVE-2026-64835 8.7 FFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio Decoder ! CVE-2026-66039 8.7 FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File ! CVE-2026-66040 8.7 FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder ! CVE-2026-65703 8.5 FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder ! CVE-2026-65706 8.5 FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing ! CVE-2026-70628 8.5 FFmpeg 0.5 < 9.0 DVB Subtitle Parser Heap Buffer Overflow via WTV File ! CVE-2026-70632 8.5 FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing ! CVE-2022-48434 8.1 libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leav ! CVE-2026-66036 7.7 FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter ! CVE-2022-3109 7.5 An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c ! CVE-2023-6603 7.5 Ffmpeg: null pointer dereference in ffmpeg hls parsing ! CVE-2024-31578 7.5 FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_c ! CVE-2026-30997 7.5 FFmpeg: FFmpeg: Denial of Service via out-of-bounds read ! CVE-2026-30998 7.5 FFmpeg: FFmpeg: Denial of Service vulnerability in zmqsend.c via crafted input ! CVE-2026-30999 7.5 FFmpeg: FFmpeg: Denial of Service via heap buffer overflow in av_bprint_finalize() ! CVE-2026-65704 7.3 FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder ! CVE-2026-65705 7.3 FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame() ! CVE-2023-6605 7.2 Ffmpeg: dash playlist ssrf vulnerability in ffmpeg ! CVE-2025-9951 7.2 Remote code execution via Heap Buffer Overflow in FFmpeg JPEG2000 ! CVE-2026-64833 7.1 FFmpeg 0.7.1 - 8.1.2 Out-of-Bounds Read via S/PDIF Muxer spdifenc.c ! CVE-2026-66037 7.1 FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu() ! CVE-2026-66038 7.1 FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c ! CVE-2026-70629 6.8 FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder ! CVE-2026-70630 6.8 FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder ! CVE-2026-70631 6.8 FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder ! CVE-2025-25468 6.5 FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the comp ! CVE-2025-25469 6.5 FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the comp ! CVE-2022-3341 5.3 A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() functi ! CVE-2023-6602 5.3 Ffmpeg: improper handling of input format in tty demuxer of ffmpeg ! CVE-2023-6604 5.3 Ffmpeg: hls xbin demuxer dos amplification in ffmpeg ! CVE-2025-10256 5.3 Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c) ! CVE-2025-1594 5.3 FFmpeg AAC Encoder aacenc_tns.c ff_aac_search_for_tns stack-based overflow ! CVE-2025-7700 5.3 Ffmpeg: null pointer dereference in ffmpeg als decoder (libavcodec/alsdec.c) ! CVE-2026-40962 4.9 FFmpeg: FFmpeg: Integer overflow and out-of-bounds write via CENC subsample data ! CVE-2025-1373 4.8 FFmpeg MOV Parser mov.c mov_read_trak null pointer dereference ! CVE-2023-6601 4.7 Ffmpeg: hls unsafe file extension bypass in ffmpeg multimedia/ffmpeg6 ffmpeg6-6.1.6_1 ! CVE-2023-49502 8.8 Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to ex ! CVE-2026-8461 8.8 Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder ! CVE-2026-64830 8.7 FFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle Demuxer ! CVE-2026-64832 8.7 FFmpeg 4.4 - 8.1.2 Double-Free in NVDEC Hardware Decoder via nvdec.c ! CVE-2026-64834 8.7 FFmpeg 0.6.3 - 8.1.2 Infinite Loop DoS via RTP/ASF Demuxer ! CVE-2026-64835 8.7 FFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio Decoder ! CVE-2026-66039 8.7 FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File ! CVE-2026-66040 8.7 FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder ! CVE-2026-65703 8.5 FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder ! CVE-2026-65706 8.5 FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing ! CVE-2026-70628 8.5 FFmpeg 0.5 < 9.0 DVB Subtitle Parser Heap Buffer Overflow via WTV File ! CVE-2026-70632 8.5 FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing ! CVE-2023-50009 8.0 FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 ! CVE-2023-50008 7.8 FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, ! CVE-2023-50010 7.8 FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, ! CVE-2024-31582 7.8 FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the ! CVE-2026-66036 7.7 FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter ! CVE-2024-31578 7.5 FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_c ! CVE-2026-30997 7.5 FFmpeg: FFmpeg: Denial of Service via out-of-bounds read ! CVE-2026-30998 7.5 FFmpeg: FFmpeg: Denial of Service vulnerability in zmqsend.c via crafted input ! CVE-2026-30999 7.5 FFmpeg: FFmpeg: Denial of Service via heap buffer overflow in av_bprint_finalize() ! CVE-2026-65704 7.3 FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder ! CVE-2026-65705 7.3 FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame() ! CVE-2025-9951 7.2 Remote code execution via Heap Buffer Overflow in FFmpeg JPEG2000 ! CVE-2026-64833 7.1 FFmpeg 0.7.1 - 8.1.2 Out-of-Bounds Read via S/PDIF Muxer spdifenc.c ! CVE-2026-66037 7.1 FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu() ! CVE-2026-66038 7.1 FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c ! CVE-2026-70629 6.8 FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder ! CVE-2026-70630 6.8 FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder ! CVE-2026-70631 6.8 FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder ! CVE-2025-25468 6.5 FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the comp ! CVE-2025-25469 6.5 FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the comp ! CVE-2025-10256 5.3 Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c) ! CVE-2025-1594 5.3 FFmpeg AAC Encoder aacenc_tns.c ff_aac_search_for_tns stack-based overflow ! CVE-2025-7700 5.3 Ffmpeg: null pointer dereference in ffmpeg als decoder (libavcodec/alsdec.c) ! CVE-2026-40962 4.9 FFmpeg: FFmpeg: Integer overflow and out-of-bounds write via CENC subsample data ! CVE-2025-1373 4.8 FFmpeg MOV Parser mov.c mov_read_trak null pointer dereference ! CVE-2023-50007 4.0 FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative s ! CVE-2025-12343 3.3 Ffmpeg: double-free vulnerability in ffmpeg tensorflow dnn backend multimedia/gstreamer1-plugins gstreamer1-plugins-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-aom gstreamer1-plugins-aom-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-assrender gstreamer1-plugins-assrender-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-bad gstreamer1-plugins-bad-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-dash gstreamer1-plugins-dash-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-dts gstreamer1-plugins-dts-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-dv gstreamer1-plugins-dv-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-dvdread gstreamer1-plugins-dvdread-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-good gstreamer1-plugins-good-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-hls gstreamer1-plugins-hls-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-libde265 gstreamer1-plugins-libde265-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-mpeg2dec gstreamer1-plugins-mpeg2dec-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-mpeg2enc gstreamer1-plugins-mpeg2enc-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-mplex gstreamer1-plugins-mplex-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-msdk gstreamer1-plugins-msdk-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-openh264 gstreamer1-plugins-openh264-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-resindvd gstreamer1-plugins-resindvd-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-smoothstreaming gstreamer1-plugins-smoothstreaming-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-svt-av1 gstreamer1-plugins-svtav1-1.28.6,1 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-theora gstreamer1-plugins-theora-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-ttml gstreamer1-plugins-ttml-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-ugly gstreamer1-plugins-ugly-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-v4l2 gstreamer1-plugins-v4l2-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-vpx gstreamer1-plugins-vpx-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-webrtc gstreamer1-plugins-webrtc-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-x264 gstreamer1-plugins-x264-1.28.6_1 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/gstreamer1-plugins-x265 gstreamer1-plugins-x265-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/lms lms-3.80.0 ! CVE-2018-1000535 7.5 lms version <= LMS_011123 contains a Local File Disclosure vulnerability in File reading f multimedia/mp4v2 mp4v2-2.1.3_1 ! CVE-2023-33718 8.8 mp4v2 v2.1.3 was discovered to contain a memory leak via MP4File::ReadString() at mp4file_ ! CVE-2023-33717 5.5 mp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBy multimedia/plexmediaserver plexmediaserver-1.43.3.10896 ! CVE-2020-5742 8.8 Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to e multimedia/plexmediaserver-plexpass plexmediaserver-plexpass-1.43.3.10896 ! CVE-2020-5742 8.8 Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to e multimedia/py-gstreamer1 py312-gstreamer1-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p multimedia/tautulli tautulli-2.16.0_2 ! CVE-2026-43986 9.9 Tautulli vulnerable to unauthenticated SSRF in /image/ via attacker-seeded image has ! CVE-2026-41065 8.9 Tautulli Vulnerable to Unauthenticated/Authenticated Remote Code Execution via Newsletter ! CVE-2026-43984 8.9 Tautulli has stored XSS in logFile via guest-controlled log_js_errors input ! CVE-2026-43985 8.8 Taultulli has CSRF in /configUpdate via missing anti-CSRF and method restriction that allo ! CVE-2026-31831 8.7 Tautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint ! CVE-2026-28505 7.5 Tautulli: RCE via eval() sandbox bypass using lambda nested scope to escape co_names white ! CVE-2026-32275 7.4 Tautulli: Unsanitized JSONP callback parameter allows cross-origin script injection and AP ! CVE-2026-40605 5.7 Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API ! CVE-2026-31799 4.9 Tautulli: SQL Injection in get_home_stats API endpoint via unsanitised filter parameters ! CVE-2026-31804 4.0 Tautulli: Unauthenticated pms_image_proxy endpoint proxies arbitrary HTTP requests through multimedia/xine xine-0.99.14_5 ! CVE-2008-5237 10.0 Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allo ! CVE-2008-5235 9.3 xine-lib: various flaws (CVE-2008-5234 CVE-2008-5235 CVE-2008-5236 CVE-2008-5237 CVE-2008- ! CVE-2008-5236 9.3 Multiple heap-based buffer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier vers ! CVE-2008-5238 7.1 Integer overflow in the real_parse_mdpr function in demux_real.c in xine-lib 1.1.12, and o multimedia/zoneminder zoneminder-php84-1.38.3 ! CVE-2026-72556 8.8 ZoneMinder ZoneMinder - Remote Code Execution net-im/nextcloud-talk nextcloud-talk-php84-24.0.5 ! CVE-2018-3781 5.4 A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2. net-im/profanity profanity-0.18.2 ! CVE-2022-40769 7.5 profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers net-im/zoom zoom-video-conferencing-client-5.3.465578.0920_1 ! CVE-2022-28755 9.6 Improper URL parsing in Zoom Clients ! CVE-2023-39213 9.6 Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VD ! CVE-2023-39216 9.6 Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an un ! CVE-2024-24691 9.6 Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Win ! CVE-2023-36534 9.3 Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticat ! CVE-2023-39211 8.8 Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Window ! CVE-2023-49647 8.8 Zoom Desktop Client for Windows - Improper Access Control ! CVE-2023-28597 8.3 Improper trust boundary implementation for SMB in Zoom Clients ! CVE-2023-28601 8.3 Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations wit ! CVE-2023-34116 8.2 Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may ! CVE-2023-36541 8.0 Insufficient verification of data authenticity in Zoom Desktop Client for Windows before 5 ! CVE-2023-39214 7.6 Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenti ! CVE-2023-28598 7.5 Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a vic ! CVE-2023-34114 7.4 Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before ! CVE-2023-36540 7.3 Untrusted search path in the installer for Zoom Desktop Client for Windows before 5.14.5 m ! CVE-2023-43586 7.3 Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom S ! CVE-2024-24697 7.2 Zoom Clients - Untrusted Search Path ! CVE-2023-36535 7.1 Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a ! CVE-2023-39215 7.1 Improper authentication in Zoom clients may allow an authenticated user to conduct a denia ! CVE-2023-43585 7.1 Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5. ! CVE-2023-22880 6.8 Information Disclosure in Zoom for Windows Clients ! CVE-2024-24695 6.8 Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wi ! CVE-2024-24696 6.8 Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Win ! CVE-2023-22881 6.5 Denial of Service in Zoom Clients ! CVE-2023-22882 6.5 Denial of Service in Zoom Clients ! CVE-2023-39208 6.5 Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allo ! CVE-2024-24699 6.5 Zoom Clients - Business Logic Error ! CVE-2025-49463 6.5 Zoom Clients for iOS - Insufficient Control Flow Management ! CVE-2025-49464 6.5 Zoom Clients for Windows- Classic Buffer Overflow ! CVE-2023-49646 6.4 Improper authentication in some Zoom clients before version 5.16.5 may allow an authentica ! CVE-2022-36928 6.1 Path Traversal in Zoom for Android Clients ! CVE-2023-39218 6.1 Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a ! CVE-2023-36532 5.9 Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable ! CVE-2023-39209 5.9 Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an au ! CVE-2024-24694 5.9 Zoom Desktop Client for Windows - Improper Privilege Management ! CVE-2023-43582 5.5 Improper authorization in some Zoom clients may allow an authorized user to conduct an esc ! CVE-2024-27247 5.5 Zoom Desktop Client for macOS - Improper Privilege Management ! CVE-2024-24690 5.4 Zoom Clients - Improper Input Validation ! CVE-2023-28600 5.2 Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A ! CVE-2023-39199 4.9 Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged use ! CVE-2023-43583 4.9 Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs f ! CVE-2024-24698 4.9 Zoom Clients - Improper Authentication ! CVE-2021-28133 4.3 Zoom through 5.5.4 sometimes allows attackers to read private information on a participant ! CVE-2023-28599 4.3 Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user c ! CVE-2023-39203 4.3 Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows an ! CVE-2023-39204 4.3 Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial ! CVE-2023-39205 4.3 Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated us ! CVE-2023-34121 4.1 Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting ! CVE-2024-27242 4.1 Zoom Desktop Client for Linux - Cross Site Scripting ! CVE-2023-39206 3.7 Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial ! CVE-2023-43588 3.5 Insufficient control flow management in some Zoom clients may allow an authenticated user ! CVE-2025-49462 3.5 Zoom Clients - Cross-site Scripting ! CVE-2023-28602 2.8 Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic net-mgmt/cacti cacti-php84-1.2.31 ! CVE-2026-71287 8.8 Cacti sanitize_sql_column() Regex Allowlist Permits SQL Time-Delay Functions Leading to Bl net-mgmt/libsmi libsmi-0.4.8_3 ! CVE-2010-2891 7.5 libsmi: buffer overflow in smiGetNode can lead to arbitrary code execution net-mgmt/lldpd lldpd-1.0.21 ! CVE-2026-46433 6.5 lldpd: Heap OOB Read in VLAN Decapsulation memmove net-mgmt/nagios nagios-3.5.1_12 ! CVE-2008-4796 10.0 snoopy: command execution via shell metacharacters ! CVE-2008-7313 9.8 snoopy: incomplete fixes for command execution flaws ! CVE-2014-5009 9.8 snoopy: incomplete fixes for command execution flaws ! CVE-2016-9565 9.8 nagios: Command injection via curl in MagpieRSS ! CVE-2016-10089 7.8 nagios: Privilege escalation due to incomplete fix for CVE-2016-8641 ! CVE-2016-9566 7.8 nagios: Privilege escalation issue ! CVE-2013-7205 6.4 nagios: denial of service due to off-by-one flaw in process_cgivars() ! CVE-2013-4214 6.3 core: html/rss-newsfeed.php insecure temporary file usage ! CVE-2017-12847 6.3 nagios: Incorrect permissions for PID file ! CVE-2013-7108 5.5 nagios: denial of service due to off-by-one flaw in process_cgivars() ! CVE-2018-13441 5.5 nagios: NULL pointer dereference in qh_help in base/query-handler.c ! CVE-2014-1878 5.0 nagios: possible buffer overflows in cmd.cgi net-mgmt/nagvis nagvis-1.9.36 ! CVE-2024-47093 8.8 Fix various XSS issues and potential RCE ! CVE-2025-39665 6.9 Livestatus Injection in dynmaps ! CVE-2023-46287 6.1 XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/ ! CVE-2024-38866 5.3 Livestatus Injection in dynmaps ! CVE-2024-47090 5.1 XSS via WYSIWYG editor net-mgmt/netbox netbox-4.6.10 ! CVE-2026-86175 7.1 NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs ! CVE-2026-86176 5.3 NetBox through 4.7.0 Information Disclosure via REST and GraphQL APIs net-mgmt/omada5 omada5-5.15.24.19_3 ! CVE-2025-9290 6.0 Authentication Weakness on Omada Controllers, Gateways and Access Points ! CVE-2025-9289 5.7 Cross-Site Scripting (XSS) on Omada Controllers net-mgmt/phpipam phpipam-1.6.0 ! CVE-2026-67602 9.3 phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache ! CVE-2026-75105 8.7 phpIPAM Temporary Subnet Share Information Disclosure via Address Parameter ! CVE-2024-10718 7.5 Cookie without Secure attribute in phpipam/phpipam ! CVE-2024-41353 7.1 phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.ph ! CVE-2024-41354 7.1 phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php ! CVE-2024-41357 7.1 phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edi ! CVE-2024-41355 6.5 phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.ph ! CVE-2023-24657 6.1 phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerabilit ! CVE-2024-10720 6.1 Stored Cross-site Scripting (XSS) in phpipam/phpipam ! CVE-2024-10727 6.1 Cross-Site Scripting (XSS) in phpipam/phpipam ! CVE-2024-41358 6.1 phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import ! CVE-2024-10719 5.4 Stored Cross-site Scripting (XSS) in phpipam/phpipam ! CVE-2024-10721 5.4 Store XSS in phpipam/phpipam ! CVE-2024-10722 5.4 Stored Cross-site Scripting (XSS) in phpipam/phpipam ! CVE-2024-10723 5.4 Stored XSS in phpipam/phpipam ! CVE-2024-10724 5.4 Stored XSS in IPV6 Section in phpipam/phpipam ! CVE-2024-10725 5.4 Stored Cross-site Scripting (XSS) in phpipam/phpipam ! CVE-2024-55093 5.4 phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the inst ! CVE-2024-0787 5.3 Improper Restriction of Excessive Authentication Attempts in phpipam/phpipam ! CVE-2024-41356 4.7 phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones ! CVE-2025-60912 3.3 phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database ! CVE-2026-12194 2.3 PHPIPAM Authenticated LFI net-mgmt/prometheus1 prometheus1-1.8.2_48 ! CVE-2026-42151 7.5 Prometheus Azure AD remote write OAuth client secret exposed via config API ! CVE-2026-42154 7.5 Prometheus: remote read endpoint allows denial of service via crafted snappy payload ! CVE-2019-3826 6.1 prometheus: Stored DOM cross-site scripting (XSS) attack via crafted URL net-mgmt/prometheus2 prometheus-2.55.1_18 ! CVE-2026-42151 7.5 Prometheus Azure AD remote write OAuth client secret exposed via config API ! CVE-2026-42154 7.5 Prometheus: remote read endpoint allows denial of service via crafted snappy payload ! CVE-2026-44903 5.1 Prometheus: Stored XSS via crafted histogram bucket label values in the heatmap display of net-mgmt/tcpreplay tcpreplay-4.6.1 ! CVE-2023-4256 5.5 Tcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.c net-mgmt/zabbix6-frontend zabbix6-frontend-php84-6.0.48 ! CVE-2023-30958 4.7 DOM XSS in Developer mode dashboard via redirect GET parameter net-mgmt/zabbix6-server zabbix6-server-6.0.48 ! CVE-2024-22120 9.1 Time Based SQL Injection in Zabbix Server Audit Log net/avahi-app avahi-app-0.8_6 ! CVE-2021-26720 7.8 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root vi ! CVE-2025-68468 6.5 Avahi has a reachable assertion in lookup_multicast_callback ! CVE-2025-68471 6.5 Avahi has a reachable assertion in lookup_start ! CVE-2026-24401 6.5 Avahi has Uncontrolled Recursion in lookup_handle_cname function ! CVE-2023-38469 6.2 Reachable assertion in avahi_dns_packet_append_record ! CVE-2023-38470 6.2 Reachable assertion in avahi_escape_label ! CVE-2023-38471 6.2 Reachable assertion in dbus_set_host_name ! CVE-2023-38472 6.2 Reachable assertion in avahi_rdata_parse ! CVE-2023-38473 6.2 Reachable assertion in avahi_alternative_host_name ! CVE-2021-3468 5.5 avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket ! CVE-2025-59529 5.5 simple protocol server ignores accepts unlimited connections and logs failures without lim ! CVE-2025-68276 5.5 Avahi has a reachable assertion in avahi_wide_area_scan_cache ! CVE-2026-34933 5.5 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flag net/avahi-autoipd avahi-autoipd-0.8_2 ! CVE-2021-26720 7.8 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root vi ! CVE-2025-68468 6.5 Avahi has a reachable assertion in lookup_multicast_callback ! CVE-2025-68471 6.5 Avahi has a reachable assertion in lookup_start ! CVE-2026-24401 6.5 Avahi has Uncontrolled Recursion in lookup_handle_cname function ! CVE-2023-38469 6.2 Reachable assertion in avahi_dns_packet_append_record ! CVE-2023-38470 6.2 Reachable assertion in avahi_escape_label ! CVE-2023-38471 6.2 Reachable assertion in dbus_set_host_name ! CVE-2023-38472 6.2 Reachable assertion in avahi_rdata_parse ! CVE-2023-38473 6.2 Reachable assertion in avahi_alternative_host_name ! CVE-2021-3468 5.5 avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket ! CVE-2025-59529 5.5 simple protocol server ignores accepts unlimited connections and logs failures without lim ! CVE-2025-68276 5.5 Avahi has a reachable assertion in avahi_wide_area_scan_cache ! CVE-2026-34933 5.5 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flag net/avahi-gtk avahi-gtk-0.8_2 ! CVE-2021-26720 7.8 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root vi ! CVE-2025-68468 6.5 Avahi has a reachable assertion in lookup_multicast_callback ! CVE-2025-68471 6.5 Avahi has a reachable assertion in lookup_start ! CVE-2026-24401 6.5 Avahi has Uncontrolled Recursion in lookup_handle_cname function ! CVE-2023-38469 6.2 Reachable assertion in avahi_dns_packet_append_record ! CVE-2023-38470 6.2 Reachable assertion in avahi_escape_label ! CVE-2023-38471 6.2 Reachable assertion in dbus_set_host_name ! CVE-2023-38472 6.2 Reachable assertion in avahi_rdata_parse ! CVE-2023-38473 6.2 Reachable assertion in avahi_alternative_host_name ! CVE-2021-3468 5.5 avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket ! CVE-2025-59529 5.5 simple protocol server ignores accepts unlimited connections and logs failures without lim ! CVE-2025-68276 5.5 Avahi has a reachable assertion in avahi_wide_area_scan_cache ! CVE-2026-34933 5.5 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flag net/avahi-gtk3 avahi-gtk3-0.8_2 ! CVE-2021-26720 7.8 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root vi ! CVE-2025-68468 6.5 Avahi has a reachable assertion in lookup_multicast_callback ! CVE-2025-68471 6.5 Avahi has a reachable assertion in lookup_start ! CVE-2026-24401 6.5 Avahi has Uncontrolled Recursion in lookup_handle_cname function ! CVE-2023-38469 6.2 Reachable assertion in avahi_dns_packet_append_record ! CVE-2023-38470 6.2 Reachable assertion in avahi_escape_label ! CVE-2023-38471 6.2 Reachable assertion in dbus_set_host_name ! CVE-2023-38472 6.2 Reachable assertion in avahi_rdata_parse ! CVE-2023-38473 6.2 Reachable assertion in avahi_alternative_host_name ! CVE-2021-3468 5.5 avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket ! CVE-2025-59529 5.5 simple protocol server ignores accepts unlimited connections and logs failures without lim ! CVE-2025-68276 5.5 Avahi has a reachable assertion in avahi_wide_area_scan_cache ! CVE-2026-34933 5.5 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flag net/avahi-libdns avahi-libdns-0.8_2 ! CVE-2021-26720 7.8 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root vi ! CVE-2025-68468 6.5 Avahi has a reachable assertion in lookup_multicast_callback ! CVE-2025-68471 6.5 Avahi has a reachable assertion in lookup_start ! CVE-2026-24401 6.5 Avahi has Uncontrolled Recursion in lookup_handle_cname function ! CVE-2023-38469 6.2 Reachable assertion in avahi_dns_packet_append_record ! CVE-2023-38470 6.2 Reachable assertion in avahi_escape_label ! CVE-2023-38471 6.2 Reachable assertion in dbus_set_host_name ! CVE-2023-38472 6.2 Reachable assertion in avahi_rdata_parse ! CVE-2023-38473 6.2 Reachable assertion in avahi_alternative_host_name ! CVE-2021-3468 5.5 avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket ! CVE-2025-59529 5.5 simple protocol server ignores accepts unlimited connections and logs failures without lim ! CVE-2025-68276 5.5 Avahi has a reachable assertion in avahi_wide_area_scan_cache ! CVE-2026-34933 5.5 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flag net/avahi-qt5 avahi-qt5-0.8_2 ! CVE-2021-26720 7.8 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root vi ! CVE-2025-68468 6.5 Avahi has a reachable assertion in lookup_multicast_callback ! CVE-2025-68471 6.5 Avahi has a reachable assertion in lookup_start ! CVE-2026-24401 6.5 Avahi has Uncontrolled Recursion in lookup_handle_cname function ! CVE-2023-38469 6.2 Reachable assertion in avahi_dns_packet_append_record ! CVE-2023-38470 6.2 Reachable assertion in avahi_escape_label ! CVE-2023-38471 6.2 Reachable assertion in dbus_set_host_name ! CVE-2023-38472 6.2 Reachable assertion in avahi_rdata_parse ! CVE-2023-38473 6.2 Reachable assertion in avahi_alternative_host_name ! CVE-2021-3468 5.5 avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket ! CVE-2025-59529 5.5 simple protocol server ignores accepts unlimited connections and logs failures without lim ! CVE-2025-68276 5.5 Avahi has a reachable assertion in avahi_wide_area_scan_cache ! CVE-2026-34933 5.5 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flag net/avahi-sharp avahi-sharp-0.8_2 ! CVE-2021-26720 7.8 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root vi ! CVE-2025-68468 6.5 Avahi has a reachable assertion in lookup_multicast_callback ! CVE-2025-68471 6.5 Avahi has a reachable assertion in lookup_start ! CVE-2026-24401 6.5 Avahi has Uncontrolled Recursion in lookup_handle_cname function ! CVE-2023-38469 6.2 Reachable assertion in avahi_dns_packet_append_record ! CVE-2023-38470 6.2 Reachable assertion in avahi_escape_label ! CVE-2023-38471 6.2 Reachable assertion in dbus_set_host_name ! CVE-2023-38472 6.2 Reachable assertion in avahi_rdata_parse ! CVE-2023-38473 6.2 Reachable assertion in avahi_alternative_host_name ! CVE-2021-3468 5.5 avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket ! CVE-2025-59529 5.5 simple protocol server ignores accepts unlimited connections and logs failures without lim ! CVE-2025-68276 5.5 Avahi has a reachable assertion in avahi_wide_area_scan_cache ! CVE-2026-34933 5.5 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flag net/corosync2 corosync2-2.4.6_2 ! CVE-2025-30472 9.0 corosync: Stack buffer overflow from 'orf_token_endian_convert' net/csync2 csync2-2.0_4 ! CVE-2019-15522 9.8 An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neg ! CVE-2019-15523 5.3 An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the net/delegate delegate-9.9.13_3 ! CVE-2015-7556 7.8 DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setui net/echoping echoping-6.0.2_13 ! CVE-2010-5111 6.8 Multiple buffer overflows in readline.c in Echoping 6.0.2 allow remote attackers to cause net/freeipa-server freeipa-server-4.13.4 ! CVE-2017-12169 7.5 ipa: Password hash disclosure via 'System: Read Stage Users' permission ! CVE-2019-14826 4.4 ipa: Session not terminated after logout net/freerdp freerdp-2.11.8_1 ! CVE-2024-32658 9.8 FreeRDP ExtractRunLengthRegular* out of bound read ! CVE-2024-32659 9.8 freerdp_image_copy out of bound read ! CVE-2026-67305 9.4 FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr ! CVE-2026-31806 9.3 FreeRDP has a Heap Buffer Overflow in nsc_process_message() via Unchecked SURFACE_BITS_COM ! CVE-2026-64620 9.3 FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common ! CVE-2026-64621 9.3 FreeRDP before 3.28.0 Double-Free via selectedmonitors ! CVE-2026-66402 9.3 FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass ! CVE-2026-67289 9.3 FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection ! CVE-2026-67292 9.3 FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure ! CVE-2026-67293 9.3 FreeRDP before 3.29.0 Improper Certificate Hostname Validation ! CVE-2026-67294 9.3 FreeRDP before 3.29.0 TLS Certificate EKU Bypass ! CVE-2026-26955 8.8 FreeRDP has Out-of-bounds Write ! CVE-2026-26965 8.8 FreeRDP has Out-of-bounds Write ! CVE-2026-44420 8.8 FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_ ! CVE-2026-44421 8.8 FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypass ! CVE-2026-24677 8.7 FreeRDP has a heap-buffer-overflow in ecam_encoder_compress_h264 ! CVE-2026-24678 8.7 FreeRDP has a Heap-use-after-free in cam_v4l_stream_capture_thread ! CVE-2026-24679 8.7 FreeRDP has a heap-buffer-overflow in urb_select_interface ! CVE-2026-24680 8.7 FreeRDP has a heap-use-after-free in update_pointer_new(SDL) ! CVE-2026-24681 8.7 FreeRDP has a heap-use-after-free in urb_bulk_transfer_cb ! CVE-2026-24682 8.7 FreeRDP has a Heap-buffer-overflow in audio_formats_free ! CVE-2026-24683 8.7 FreeRDP has a heap-use-after-free in ainput_send_input_event ! CVE-2026-24684 8.7 FreeRDP has a Heap-use-after-free in play_thread ! CVE-2026-55191 8.7 FreeRDP: Heap-buffer-overflow write in AVC444 YUV buffer allocation ! CVE-2026-55193 8.7 FreeRDP: Heap-buffer-overflow write in TS Gateway RPC fragment receive due to uncapped bin ! CVE-2026-55194 8.7 FreeRDPHeap-buffer-overflow write in TS Gateway RPC RESPONSE reassembly due to alloc_hint ! CVE-2026-67288 8.7 FreeRDP before 3.29.0 Denial of Service via smartcard cache ! CVE-2026-67290 8.7 FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF ! CVE-2026-67291 8.7 FreeRDP before 3.29.0 Heap Out-of-Bounds Read via GLYPH_FRAGMENT_ADD ! CVE-2026-67296 8.7 FreeRDP before 3.29.0 Denial of Service via RDPEI PDU ! CVE-2026-67297 8.7 FreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP response ! CVE-2026-67298 8.7 FreeRDP 3.28.0 Heap Buffer Overflow via RAIL orderLength Underflow ! CVE-2026-67299 8.7 FreeRDP before 3.29.0 Use-After-Free via WindowIcon async message ! CVE-2026-67300 8.7 FreeRDP before 3.29.0 Use-After-Free via async message proxy ! CVE-2026-67301 8.7 FreeRDP before 3.29.0 Out-of-bounds Read via Polygon async message-proxy ! CVE-2026-67304 8.7 FreeRDP before 3.29.0 NULL Dereference via smartcard cleanup ! CVE-2026-68579 8.7 FreeRDP before 3.30.0 Heap Overflow via CliprdrStream_Read ! CVE-2026-40033 8.6 FreeRDP - Heap-buffer-overflow in gdi_CacheToSurface via rectangle validation bypass ! CVE-2026-57156 8.6 FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsing ! CVE-2026-64624 8.5 FreeRDP RDP File Parser Remote Code Execution via CLI Options ! CVE-2026-56297 8.3 FreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel Callback ! CVE-2026-73241 8.3 FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accept ! CVE-2026-73242 8.3 FreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decrypt ! CVE-2026-23530 7.7 FreeRDP has heap-buffer-overflow in planar_decompress_plane_rle ! CVE-2026-23531 7.7 FreeRDP has heap-buffer-overflow in clear_decompress ! CVE-2026-23532 7.7 FreeRDP has heap-buffer-overflow in gdi_SurfaceToSurface ! CVE-2026-23533 7.7 FreeRDP has heap-buffer-overflow in clear_decompress_residual_data ! CVE-2026-23534 7.7 FreeRDP has heap-buffer-overflow in clear_decompress_bands_data ! CVE-2026-23883 7.7 Heap-use-after-free in update_pointer_new ! CVE-2026-23884 7.7 Heap-use-after-free in gdi_set_bounds ! CVE-2026-24491 7.7 FreeRDP has a heap-use-after-free in video_timer ! CVE-2026-24675 7.7 FreeRDP has a Heap-use-after-free in urb_select_interface ! CVE-2026-24676 7.7 FreeRDP has a heap-use-after-free in audio_format_compatible ! CVE-2026-45700 7.7 Heap-buffer-overflow write in planar bitmap decoder ! CVE-2026-63633 7.7 FreeRDP: Heap buffer overflow in Opus audio decode (`freerdp_dsp_decode_opus` resizes the ! CVE-2026-68580 7.7 FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel ! CVE-2024-32660 7.5 FreeRDP zgfx_decompress out of memory vulnerability ! CVE-2024-32661 7.5 FreeRDP rdp_write_logon_info_v1 NULL access ! CVE-2024-32662 7.5 FreeRDP rdp_redirection_read_base64_wchar out of bound read ! CVE-2026-33984 7.5 FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write ! CVE-2026-33986 7.5 FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write ! CVE-2026-44422 7.5 FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion ! CVE-2026-55827 7.5 FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode ! CVE-2026-55192 7.2 FreeRDP: Out-of-bounds read in H.264 YUV-to-RGB conversion due to decoder/surface dimensio ! CVE-2026-33982 7.1 FreeRDP: Persistent Cache Allocator Mismatch - Heap OOB Read ! CVE-2026-33987 7.1 FreeRDP: Persistent Cache bmpSize Desync - Heap OOB Write ! CVE-2026-63652 7.1 FreeRDP: Double-free of `client_formats` in the rdpsnd server channel on a malformed Clien ! CVE-2026-22851 6.9 FreeRDP RDPGFX ResetGraphics race leads to use-after-free in SDL client (sdl->primary) ! CVE-2026-23948 6.9 FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2() ! CVE-2026-33977 6.9 FreeRDP: DoS via WINPR_ASSERT in IMA ADPCM audio decoder (dsp.c:331) ! CVE-2026-22852 6.8 FreeRDP has a heap-buffer-overflow in audin_process_formats ! CVE-2026-22853 6.8 FreeRDP has a heap-buffer-overflow in ndr_read_uint8Array ! CVE-2026-22854 6.8 FreeRDP has a heap-buffer-overflow in drive_process_irp_read ! CVE-2026-22856 6.8 FreeRDP has a heap-use-after-free in create_irp_thread ! CVE-2026-22857 6.8 FreeRDP has a heap-use-after-free in irp_thread_func ! CVE-2025-68118 6.6 Potential Heap Out-of-Bounds Read in freerdp_certificate_data_hash_ via Unsafe _snprintf U ! CVE-2026-31883 6.5 FreeRDP has a `size_t` underflow in ADPCM decoder leads to heap-buffer-overflow write ! CVE-2026-31884 6.5 FreeRDP has a division-by-zero in ADPCM decoders when `nBlockAlign` is 0 ! CVE-2026-31885 6.5 FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bo ! CVE-2026-33983 6.5 FreeRDP: Progressive Codec Quant BYTE Underflow - UB + CPU DoS ! CVE-2026-57157 6.5 Out-of-bounds read in the camera device enumerator server (rdpecam) via unterminated Devic ! CVE-2026-63117 6.5 FreeRDP: Denial of service through ADPCM frame size calculation ! CVE-2026-55648 6.1 FreeRDP: Integer Overflow in `freerdp_image_copy_from_icon_data` Bypasses Bounds Check ! CVE-2026-33952 6.0 FreeRDP: DoS via WINPR_ASSERT in rts_read_auth_verifier_no_checks ! CVE-2026-33985 5.9 FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read ! CVE-2026-22855 5.6 FreeRDP has a heap-buffer-overflow in smartcard_unpack_set_attrib_call ! CVE-2026-22858 5.6 FreeRDP has a global-buffer-overflow in crypto_base64_decode ! CVE-2026-22859 5.6 FreeRDP has a heap-buffer-overflow in urb_select_configuration ! CVE-2026-23732 5.5 FreeRDP has heap-buffer-overflow in Glyph_Alloc ! CVE-2026-25942 5.5 FreeRDP has global-buffer-overflow in xf_rail_server_execute_result ! CVE-2026-25952 5.5 FreeRDP has heap-use-after-free in xf_SetWindowMinMaxInfo ! CVE-2026-25953 5.5 FreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (freed appWindow) ! CVE-2026-25954 5.5 FreeRDP has heap-use-after-free in xf_rail_server_local_move_size ! CVE-2026-25955 5.5 FreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (stale XImage) ! CVE-2026-25959 5.5 FreeRDP has heap-use-after-free in xf_cliprdr_provide_data_ ! CVE-2026-25997 5.5 FreeRDP has heap-use-after-free in xf_clipboard_format_equal ! CVE-2026-26271 5.5 Buffer Overread in FreeRDP Icon Processing ! CVE-2026-26986 5.5 FreeRDP has heap-use-after-free in rail_window_free ! CVE-2026-27950 5.5 FreeRDP heap-use-after-free in update_pointer_new(SDL): Fix Applied in the Wrong File ! CVE-2026-55564 5.4 FreeRDP: Out-of-bounds read in glyph_cache_get via crafted glyph fragments ! CVE-2026-27951 5.3 FreeRDP has possible Integer overflow in Stream_EnsureCapacity ! CVE-2026-29774 5.3 FreeRDP has a heap-buffer-overflow in avc420_yuv_to_rgb via OOB regionRects ! CVE-2026-29775 5.3 FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId ! CVE-2026-33995 5.3 FreeRDP: Possible double free in kerberos_AcceptSecurityContext ! CVE-2026-67295 5.3 FreeRDP before 3.29.0 Path Traversal via drive redirection ! CVE-2026-67302 5.3 FreeRDP rdpecam StartStreamsRequest divide-by-zero denial of service ! CVE-2026-67303 5.3 FreeRDP before 3.29.0 Denial of Service via serial DeviceControl ! CVE-2026-67306 5.3 FreeRDP before 3.29.0 Out-of-Bounds Read via Planar RLE ! CVE-2026-27015 5.0 FreeRDP: Smartcard NDR Alignment Padding Triggers Reachable WINPR_ASSERT Abort (Client DoS ! CVE-2026-40254 4.2 FreeRDP: contains_dotdot() off-by-one allows drive channel path traversal via terminal .. ! CVE-2026-29776 3.1 FreeRDP has an Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's C ! CVE-2026-66401 2.4 FreeRDP before 3.29.0 Out-of-Bounds Read via UVC H.264 ! CVE-2026-31897 0.0 FreeRDP has an out-of-bounds read in `freerdp_bitmap_decompress_planar` net/gstreamer1-plugins-sctp gstreamer1-plugins-sctp-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p net/gstreamer1-plugins-srtp gstreamer1-plugins-srtp-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p net/haproxy-devel haproxy-devel-3.3.d10 ! CVE-2026-55203 9.0 HAProxy - Integer Overflow in FCGI Demux Record Length Field ! CVE-2026-55204 8.7 HAProxy - NULL Pointer Dereference in hpack_dht_insert Function ! CVE-2026-33555 4.0 haproxy: HAProxy: Request smuggling via HTTP/3 parser desynchronization net/haproxy26 haproxy26-2.6.33 ! CVE-2026-55203 9.0 HAProxy - Integer Overflow in FCGI Demux Record Length Field ! CVE-2026-55204 8.7 HAProxy - NULL Pointer Dereference in hpack_dht_insert Function ! CVE-2023-45539 8.2 haproxy: untrimmed URI fragments may lead to exposure of confidential data on static serve ! CVE-2025-32464 6.8 haproxy: Buffer Overflow via Improper Back-Reference Replacement Length Check ! CVE-2026-33555 4.0 haproxy: HAProxy: Request smuggling via HTTP/3 parser desynchronization net/haproxy28 haproxy28-2.8.28 ! CVE-2026-55203 9.0 HAProxy - Integer Overflow in FCGI Demux Record Length Field ! CVE-2026-55204 8.7 HAProxy - NULL Pointer Dereference in hpack_dht_insert Function ! CVE-2025-32464 6.8 haproxy: Buffer Overflow via Improper Back-Reference Replacement Length Check ! CVE-2026-33555 4.0 haproxy: HAProxy: Request smuggling via HTTP/3 parser desynchronization net/haproxy30 haproxy30-3.0.27 ! CVE-2026-55203 9.0 HAProxy - Integer Overflow in FCGI Demux Record Length Field ! CVE-2026-55204 8.7 HAProxy - NULL Pointer Dereference in hpack_dht_insert Function ! CVE-2025-32464 6.8 haproxy: Buffer Overflow via Improper Back-Reference Replacement Length Check ! CVE-2026-33555 4.0 haproxy: HAProxy: Request smuggling via HTTP/3 parser desynchronization net/haproxy32 haproxy32-3.2.23 ! CVE-2026-55203 9.0 HAProxy - Integer Overflow in FCGI Demux Record Length Field ! CVE-2026-55204 8.7 HAProxy - NULL Pointer Dereference in hpack_dht_insert Function ! CVE-2026-33555 4.0 haproxy: HAProxy: Request smuggling via HTTP/3 parser desynchronization net/haproxy33 haproxy33-3.3.14 ! CVE-2026-55203 9.0 HAProxy - Integer Overflow in FCGI Demux Record Length Field ! CVE-2026-55204 8.7 HAProxy - NULL Pointer Dereference in hpack_dht_insert Function net/hostapd210 hostapd210-2.10_10 ! CVE-2022-37660 6.5 hostapd: Public Key Exchange (PKEX) Reuse Vulnerability in hostapd ! CVE-2026-58374 6.5 hostapd: hostapd: Denial of Service via malformed Wi-Fi 7 Multi-Link Operation association ! CVE-2025-24912 3.7 hostapd: RADIUS Packet Processing Flaw in hostapd net/hostapd29 hostapd29-2.9_5 ! CVE-2022-23303 9.8 wpa_supplicant: SAE side channel attacks as a result of cache access patterns ! CVE-2022-23304 9.8 wpa_supplicant: EAP-pwd side-channel attacks as a result of cache access patterns ! CVE-2019-16275 6.5 wpa_supplicant: AP mode PMF disconnection protection bypass ! CVE-2022-37660 6.5 hostapd: Public Key Exchange (PKEX) Reuse Vulnerability in hostapd ! CVE-2026-58374 6.5 hostapd: hostapd: Denial of Service via malformed Wi-Fi 7 Multi-Link Operation association ! CVE-2021-30004 4.3 wpa_supplicant: mishandled AlgorithmIdentifier parameters may lead to forging attacks ! CVE-2025-24912 3.7 hostapd: RADIUS Packet Processing Flaw in hostapd net/kafka kafka-4.3.0 ! CVE-2026-41115 4.3 Apache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE API net/kube-apiserver kube-apiserver-1.27.2_32 ! CVE-2023-30513 7.5 jenkins: Improper masking of credentials in multiple plugins ! CVE-2020-2307 4.3 jenkins-2-plugins/kubernetes: Jenkins controller environment variables are accessible in K ! CVE-2020-2308 4.3 jenkins-2-plugins/kubernetes: Missing permission check in Kubernetes Plugin allows listing ! CVE-2020-2309 4.3 jenkins-2-plugins/kubernetes: Missing permission check in Kubernetes Plugin allows enumera net/kube-controller-manager kube-controller-manager-1.27.2_32 ! CVE-2023-30513 7.5 jenkins: Improper masking of credentials in multiple plugins ! CVE-2020-2307 4.3 jenkins-2-plugins/kubernetes: Jenkins controller environment variables are accessible in K ! CVE-2020-2308 4.3 jenkins-2-plugins/kubernetes: Missing permission check in Kubernetes Plugin allows listing ! CVE-2020-2309 4.3 jenkins-2-plugins/kubernetes: Missing permission check in Kubernetes Plugin allows enumera net/kube-scheduler kube-scheduler-1.27.2_32 ! CVE-2023-30513 7.5 jenkins: Improper masking of credentials in multiple plugins ! CVE-2020-2307 4.3 jenkins-2-plugins/kubernetes: Jenkins controller environment variables are accessible in K ! CVE-2020-2308 4.3 jenkins-2-plugins/kubernetes: Missing permission check in Kubernetes Plugin allows listing ! CVE-2020-2309 4.3 jenkins-2-plugins/kubernetes: Missing permission check in Kubernetes Plugin allows enumera net/l2tpd l2tpd-0.69_12 ! CVE-2004-0649 10.0 Buffer overflow in write_packet in control.c for l2tpd may allow remote attackers to execu net/libgrss libgrss-0.7.0_3 ! CVE-2016-20011 7.5 libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds net/libvncserver libvncserver-0.9.15 ! CVE-2026-32853 6.9 LibVNCServer UltraZip Encoding Heap Out-of-bounds Read ! CVE-2026-32854 6.3 LibVNCServer httpd proxy NULL Pointer Dereference net/libzapojit libzapojit-0.0.3_3 ! CVE-2021-39360 5.9 libzapojit: missing TLS certificate verification net/linux-c7-avahi-libs linux-c7-avahi-libs-0.6.31_4 ! CVE-2017-6519 9.1 avahi: Multicast DNS responds to unicast queries outside of local network ! CVE-2021-26720 7.8 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root vi ! CVE-2025-68468 6.5 Avahi has a reachable assertion in lookup_multicast_callback ! CVE-2025-68471 6.5 Avahi has a reachable assertion in lookup_start ! CVE-2026-24401 6.5 Avahi has Uncontrolled Recursion in lookup_handle_cname function ! CVE-2023-38469 6.2 Reachable assertion in avahi_dns_packet_append_record ! CVE-2023-38470 6.2 Reachable assertion in avahi_escape_label ! CVE-2023-38471 6.2 Reachable assertion in dbus_set_host_name ! CVE-2023-38472 6.2 Reachable assertion in avahi_rdata_parse ! CVE-2023-38473 6.2 Reachable assertion in avahi_alternative_host_name ! CVE-2021-3468 5.5 avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket ! CVE-2025-59529 5.5 simple protocol server ignores accepts unlimited connections and logs failures without lim ! CVE-2025-68276 5.5 Avahi has a reachable assertion in avahi_wide_area_scan_cache ! CVE-2026-34933 5.5 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flag net/linux-c7-openldap linux-c7-openldap-2.4.44_3 ! CVE-2022-29155 9.8 openldap: OpenLDAP SQL injection ! CVE-2015-3276 7.5 openldap: incorrect multi-keyword mode cipherstring parsing ! CVE-2017-17740 7.5 openldap: contrib/slapd-modules/nops/nops.c attempts to free stack buffer allowing remote ! CVE-2019-13565 7.5 openldap: ACL restrictions bypass due to sasl_ssf value being set permanently ! CVE-2020-12243 7.5 openldap: denial of service via nested boolean expressions in LDAP search filters ! CVE-2020-25692 7.5 openldap: NULL pointer dereference for unauthenticated packet in slapd ! CVE-2020-25709 7.5 openldap: assertion failure in Certificate List syntax validation ! CVE-2020-25710 7.5 openldap: assertion failure in CSN normalization with invalid input ! CVE-2020-36221 7.5 openldap: Integer underflow in serialNumberAndIssuerCheck in schema_init.c ! CVE-2020-36222 7.5 openldap: Assertion failure in slapd in the saslAuthzTo validation ! CVE-2020-36223 7.5 openldap: Out-of-bounds read in Values Return Filter ! CVE-2020-36224 7.5 openldap: Invalid pointer free in the saslAuthzTo processing ! CVE-2020-36225 7.5 openldap: Double free in the saslAuthzTo processing ! CVE-2020-36226 7.5 openldap: Denial of service via length miscalculation in slap_parse_user ! CVE-2020-36227 7.5 openldap: Infinite loop in slapd with the cancel_extop Cancel operation ! CVE-2020-36228 7.5 openldap: Integer underflow in issuerAndThisUpdateCheck in schema_init.c ! CVE-2020-36229 7.5 openldap: Type confusion in ad_keystring in ad.c ! CVE-2020-36230 7.5 openldap: Assertion failure in ber_next_element in decode.c ! CVE-2021-27212 7.5 openldap: Assertion failure in slapd in the issuerAndThisUpdateCheck function ! CVE-2017-9287 6.5 openldap: Double free vulnerability in servers/slapd/back-mdb/search.c ! CVE-2019-13057 4.9 openldap: Information disclosure issue in slapd component ! CVE-2017-14159 4.7 openldap: Privilege escalation via PID file manipulation ! CVE-2020-15719 4.2 openldap: Certificate validation incorrectly matches name against CN-ID net/linux-rl9-avahi-libs linux-rl9-avahi-libs-0.8_8 ! CVE-2021-26720 7.8 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root vi ! CVE-2025-68468 6.5 Avahi has a reachable assertion in lookup_multicast_callback ! CVE-2025-68471 6.5 Avahi has a reachable assertion in lookup_start ! CVE-2026-24401 6.5 Avahi has Uncontrolled Recursion in lookup_handle_cname function ! CVE-2023-38469 6.2 Reachable assertion in avahi_dns_packet_append_record ! CVE-2023-38470 6.2 Reachable assertion in avahi_escape_label ! CVE-2023-38471 6.2 Reachable assertion in dbus_set_host_name ! CVE-2023-38472 6.2 Reachable assertion in avahi_rdata_parse ! CVE-2023-38473 6.2 Reachable assertion in avahi_alternative_host_name ! CVE-2021-3468 5.5 avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket ! CVE-2025-59529 5.5 simple protocol server ignores accepts unlimited connections and logs failures without lim ! CVE-2025-68276 5.5 Avahi has a reachable assertion in avahi_wide_area_scan_cache ! CVE-2026-34933 5.5 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flag net/miniupnpd miniupnpd-2.3.9_1,1 ! CVE-2026-5720 7.1 miniupnpd Integer Underflow SOAPAction Header Parsing net/ntopng ntopng-6.6.d20260829,1 ! CVE-2026-86090 7.1 ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient ! CVE-2026-86091 7.1 ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler net/openslp openslp-2.0.0_1 ! CVE-2016-7567 9.8 openslp: memory corruption due to possible overflow in SLPFoldWhiteSpace in common/slp_com ! CVE-2019-5544 9.8 KEV openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remot ! CVE-2016-4912 7.5 openslp: null pointer dereference in _xrealloc() function net/openvswitch openvswitch-2.17.12 ! CVE-2023-3966 7.5 Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet ! CVE-2023-5366 7.1 Openvswitch don't match packets on nd_target field net/pjsip pjsip-2.14.1 ! CVE-2026-42225 8.2 GnuTLS backend silently skips certificate chain verification when verify_peer is false ! CVE-2026-41416 8.1 PJSIP: Asymmetric ptime integer overflow in Media Stream ! CVE-2026-34235 6.9 PJSIP: Heap OOB read in VPX unpacketizer ! CVE-2026-41415 6.7 PJSIP: SIP Multipart CID URI Length Underflow net/proftpd-mod_ldap proftpd-mod_ldap-1.3.8c_6 ! CVE-2026-63090 8.7 ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly ! CVE-2026-35025 8.6 ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR ! CVE-2026-42167 8.1 mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a u ! CVE-2026-44331 8.1 SQL Injection via Reverse DNS Lookup in ProFTPD ! CVE-2026-53994 7.7 ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation ! CVE-2026-63091 7.1 ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser net/py-avahi py312-avahi-0.8_5 ! CVE-2021-26720 7.8 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root vi ! CVE-2025-68468 6.5 Avahi has a reachable assertion in lookup_multicast_callback ! CVE-2025-68471 6.5 Avahi has a reachable assertion in lookup_start ! CVE-2026-24401 6.5 Avahi has Uncontrolled Recursion in lookup_handle_cname function ! CVE-2023-38469 6.2 Reachable assertion in avahi_dns_packet_append_record ! CVE-2023-38470 6.2 Reachable assertion in avahi_escape_label ! CVE-2023-38471 6.2 Reachable assertion in dbus_set_host_name ! CVE-2023-38472 6.2 Reachable assertion in avahi_rdata_parse ! CVE-2023-38473 6.2 Reachable assertion in avahi_alternative_host_name ! CVE-2021-3468 5.5 avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket ! CVE-2025-59529 5.5 simple protocol server ignores accepts unlimited connections and logs failures without lim ! CVE-2025-68276 5.5 Avahi has a reachable assertion in avahi_wide_area_scan_cache ! CVE-2026-34933 5.5 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flag net/py-eventlet py312-eventlet-0.41.2 ! CVE-2023-29483 7.0 dnspython: denial of service in stub resolver net/py-zeroconf py312-zeroconf-0.132.2 ! CVE-2026-47180 6.5 Zeroconf: Unbounded recursion in DNS compression-pointer decoder allows LAN-local denial o ! CVE-2026-47183 6.5 Zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame local ! CVE-2026-47184 6.5 Zeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via multicast floo ! CVE-2026-48045 6.5 Zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-sourc ! CVE-2026-48487 5.3 Zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption net/quagga quagga-1.2.4_13 ! CVE-2021-44038 7.8 quagga: unsafe chown/chmod operations may lead to privileges escalation net/repeater repeater-0.17 ! CVE-2016-5673 7.5 UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, whi net/rubygem-grpc rubygem-grpc-1.76.0_6 ! CVE-2026-33186 9.1 gRPC-Go has an authorization bypass via missing leading slash in :path net/rubygem-tweetstream rubygem-tweetstream-2.6.1_1 ! CVE-2020-24393 5.9 TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS net/samba422 samba422-4.22.11_1 ! CVE-2026-2340 6.5 Samba: vfs_worm does not block directory modification net/samba423 samba423-4.23.11_2 ! CVE-2026-2340 6.5 Samba: vfs_worm does not block directory modification net/samba424 samba424-4.24.6_2 ! CVE-2026-2340 6.5 Samba: vfs_worm does not block directory modification net/tcpflow tcpflow-1.6.1_1 ! CVE-2026-25061 5.5 tcpflow has TIM Element OOB Write in wifipcap net/tightvnc tightvnc-1.3.10_10 ! CVE-2019-15678 9.8 TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, wh ! CVE-2019-15679 9.8 TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection func ! CVE-2019-8287 9.8 TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro funct ! CVE-2021-42785 9.8 Buffer Overflow in tvnviewer.exe via Crafted Packet in TightVNC Viewer 2.8.59 ! CVE-2024-42049 9.1 TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pip ! CVE-2023-27830 9.0 TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating syst ! CVE-2019-15680 7.5 TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, net/traefik traefik-3.7.11_1 ! CVE-2026-88877 9.3 Traefik v3.7.0 Authentication Bypass via from-to-www-redirect ! CVE-2026-88007 9.1 Traefik HTTP/3 Backend NTLM Connection Reuse ! CVE-2026-88009 8.8 Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing ! CVE-2026-85594 7.0 Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware ! CVE-2026-88004 7.0 Traefik entrypoint header-name sanitization bypassed via request trailers ! CVE-2026-88008 7.0 Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') ! CVE-2026-88878 6.9 Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass ! CVE-2026-88011 5.3 Traefik: ForwardAuth identity spoofing via dot-form header alias ! CVE-2026-88012 5.3 Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body upload ! CVE-2026-88879 5.3 Traefik before v2.11.56 Identity Spoofing via Header Alias net/vde vde-1.5.7_1 ! CVE-2017-16638 9.8 The Gentoo net-misc/vde package before version 2.3.2-r4 may allow members of the "qemu" gr ports-mgmt/packagekit-qt PackageKit-Qt-1.1.4 ! CVE-2026-41651 8.8 PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package insta ! CVE-2018-1106 5.5 PackageKit: authentication bypass allows to install signed packages without administrator print/cups-filters cups-filters-1.28.17_14 ! CVE-2023-24805 8.8 Command injection in cups-filters print/fontforge fontforge-20230101_2 ! CVE-2024-25082 6.5 fontforge: command injection via crafted archives or compressed files ! CVE-2024-25081 4.2 fontforge: command injection via crafted filenames print/foomatic-filters foomatic-filters-4.0.17_13 ! CVE-2015-8327 7.5 cups-filters: foomatic-rip did not consider the back tick as an illegal shell escape chara ! CVE-2015-8560 7.3 cups-filters: foomatic-rip did not consider semicolon as illegal shell escape character print/linux-c7-freetype linux-c7-freetype-2.8_3 ! CVE-2022-27404 9.8 FreeType: Buffer overflow in sfnt_init_face ! CVE-2020-15999 9.6 KEV freetype: Heap-based buffer overflow due to integer truncation in Load_SBit_Png ! CVE-2025-27363 8.1 KEV freetype: OOB write when attempting to parse font subglyph structures related to TrueType ! CVE-2022-27405 7.5 FreeType: Segmentation violation via FNT_Size_Request ! CVE-2022-27406 7.5 Freetype: Segmentation violation via FT_Request_Size ! CVE-2018-6942 6.5 freetype: NULL pointer dereference in the Ins_GETVARIATION() function print/linux-c7-harfbuzz linux-c7-harfbuzz-1.7.5 ! CVE-2023-25193 7.5 harfbuzz: allows attackers to trigger O(n^2) growth via consecutive marks ! CVE-2026-22693 5.3 Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS print/linux-rl9-cups-libs linux-rl9-cups-libs-2.3.3_11 ! CVE-2024-47850 7.5 cups-browsed: cups-filters: cups-browsed vulnerable to DDoS amplification attack print/linux-rl9-freetype linux-rl9-freetype-2.10.4_3 ! CVE-2022-27404 9.8 FreeType: Buffer overflow in sfnt_init_face ! CVE-2025-27363 8.1 KEV freetype: OOB write when attempting to parse font subglyph structures related to TrueType ! CVE-2022-27405 7.5 FreeType: Segmentation violation via FNT_Size_Request ! CVE-2022-27406 7.5 Freetype: Segmentation violation via FT_Request_Size print/linux-rl9-harfbuzz linux-rl9-harfbuzz-2.7.4_2 ! CVE-2023-25193 7.5 harfbuzz: allows attackers to trigger O(n^2) growth via consecutive marks ! CVE-2026-22693 5.3 Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS print/pdfbox pdfbox-3.0.7 ! CVE-2026-23907 5.3 Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code ! CVE-2026-33929 4.3 Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code print/pstotext pstotext-1.9_8 ! CVE-2005-2536 7.5 pstotext before 1.8g does not properly use the "-dSAFER" option when calling Ghostscript t ! CVE-2006-5869 5.1 pstotext before 1.9 allows user-assisted attackers to execute arbitrary commands via shell russian/wordpress ru-wordpress-ru_RU-7.1 ! CVE-2026-64638 8.9 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. science/hdf5-110 hdf5-110-1.10.11 ! CVE-2024-29157 9.8 hdf5: multiple CVEs ! CVE-2024-29159 9.8 hdf5: multiple CVEs ! CVE-2024-29164 9.8 hdf5: multiple CVEs ! CVE-2024-32608 9.8 hdf5: multiple CVEs ! CVE-2024-32611 9.8 hdf5: multiple CVEs ! CVE-2024-32615 9.8 hdf5: multiple CVEs ! CVE-2024-32621 9.8 hdf5: multiple CVEs ! CVE-2024-32622 9.1 hdf5: multiple CVEs ! CVE-2024-29161 8.8 hdf5: multiple CVEs ! CVE-2024-32605 8.8 hdf5: multiple CVEs ! CVE-2024-32614 8.8 hdf5: multiple CVEs ! CVE-2024-32617 8.8 hdf5: multiple CVEs ! CVE-2024-32623 8.8 hdf5: multiple CVEs ! CVE-2024-33873 8.8 hdf5: multiple CVEs ! CVE-2024-33877 8.8 hdf5: multiple CVEs ! CVE-2026-19024 8.2 HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message ! CVE-2026-26200 7.8 HDF5 Affected by H5T__conv_struct_opt Heap Buffer Overflow ! CVE-2026-34734 7.8 HDF5: H5T__conv_struct Use After Free ! CVE-2024-32609 7.5 hdf5: multiple CVEs ! CVE-2024-29158 7.4 hdf5: multiple CVEs ! CVE-2024-29160 7.4 hdf5: multiple CVEs ! CVE-2024-29162 7.4 hdf5: multiple CVEs ! CVE-2024-29163 7.4 hdf5: multiple CVEs ! CVE-2024-29165 7.4 hdf5: multiple CVEs ! CVE-2024-32612 7.4 hdf5: multiple CVEs ! CVE-2024-32613 7.4 hdf5: multiple CVEs ! CVE-2024-32616 7.4 hdf5: multiple CVEs ! CVE-2024-32618 7.4 hdf5: multiple CVEs ! CVE-2024-32619 7.4 hdf5: multiple CVEs ! CVE-2024-32620 7.4 hdf5: multiple CVEs ! CVE-2024-32624 7.4 hdf5: multiple CVEs ! CVE-2026-19027 6.9 HDF5 out-of-bounds heap read in N-Bit filter decompression ! CVE-2026-19023 6.8 HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datas ! CVE-2026-19025 6.8 HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank ! CVE-2026-19026 6.8 Nbit filter NULL/short parameter-array dereference ! CVE-2026-19028 6.8 HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read ! CVE-2026-26197 5.9 Array full size, element count, and element size are not checked to make sure they match i ! CVE-2026-26199 5.9 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero ! CVE-2024-29166 5.7 hdf5: multiple CVEs ! CVE-2024-32606 5.7 hdf5: multiple CVEs ! CVE-2024-32607 5.7 hdf5: multiple CVEs ! CVE-2024-32610 5.7 hdf5: multiple CVEs ! CVE-2024-33875 5.7 hdf5: multiple CVEs ! CVE-2024-33876 5.7 hdf5: multiple CVEs ! CVE-2020-10809 5.5 hdf5: Heap-based buffer overflow in function Decompress() in decompress.c ! CVE-2020-10810 5.5 hdf5: Null pointer dereference in function H5AC_unpin_entry() in H5AC.c ! CVE-2020-10811 5.5 hdf5: Heap-based buffer over-read in function H5O__layout_decode() in H5Olayout.c ! CVE-2020-10812 5.5 hdf5: Null pointer dereference in function H5F_get_nrefs() in H5Fquery.c ! CVE-2026-17572 5.5 HDF5 SOHM List Index Heap Buffer Overflow ! CVE-2026-29043 5.5 HDF5 H5T__ref_mem_setnull Heap Buffer Overflow ! CVE-2026-17574 5.2 NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag ! CVE-2025-2912 4.8 HDF5 H5Omessage.c H5O_msg_flush heap-based overflow ! CVE-2025-2913 4.8 HDF5 H5FL.c H5FL__blk_gc_list use after free ! CVE-2025-2914 4.8 HDF5 H5FScache.c H5FS__sinfo_Srialize_Sct_cb heap-based overflow ! CVE-2025-2915 4.8 HDF5 H5Faccum.c H5F__accum_free heap-based overflow ! CVE-2025-2923 4.8 HDF5 H5Fint.c H5F_addr_encode_len heap-based overflow ! CVE-2025-2924 4.8 HDF5 H5HLcache.c H5HL__fl_deserialize heap-based overflow ! CVE-2025-2925 4.8 HDF5 H5MM.c H5MM_realloc double free ! CVE-2025-2926 4.8 HDF5 H5Ocache.c H5O__cache_chk_serialize null pointer dereference ! CVE-2025-6269 4.8 HDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflow ! CVE-2025-6270 4.8 HDF5 H5FSsection.c H5FS__sect_find_node heap-based overflow ! CVE-2025-6516 4.8 HDF5 H5Fint.c H5F_addr_decode_len heap-based overflow ! CVE-2026-17573 4.0 Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field science/hdf5-18 hdf5-18-1.8.23 ! CVE-2024-29157 9.8 hdf5: multiple CVEs ! CVE-2024-29159 9.8 hdf5: multiple CVEs ! CVE-2024-29164 9.8 hdf5: multiple CVEs ! CVE-2024-32608 9.8 hdf5: multiple CVEs ! CVE-2024-32611 9.8 hdf5: multiple CVEs ! CVE-2024-32615 9.8 hdf5: multiple CVEs ! CVE-2024-32621 9.8 hdf5: multiple CVEs ! CVE-2024-32622 9.1 hdf5: multiple CVEs ! CVE-2024-29161 8.8 hdf5: multiple CVEs ! CVE-2024-32605 8.8 hdf5: multiple CVEs ! CVE-2024-32614 8.8 hdf5: multiple CVEs ! CVE-2024-32617 8.8 hdf5: multiple CVEs ! CVE-2024-32623 8.8 hdf5: multiple CVEs ! CVE-2024-33873 8.8 hdf5: multiple CVEs ! CVE-2024-33877 8.8 hdf5: multiple CVEs ! CVE-2026-19024 8.2 HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message ! CVE-2026-26200 7.8 HDF5 Affected by H5T__conv_struct_opt Heap Buffer Overflow ! CVE-2026-34734 7.8 HDF5: H5T__conv_struct Use After Free ! CVE-2024-32609 7.5 hdf5: multiple CVEs ! CVE-2024-29158 7.4 hdf5: multiple CVEs ! CVE-2024-29160 7.4 hdf5: multiple CVEs ! CVE-2024-29162 7.4 hdf5: multiple CVEs ! CVE-2024-29163 7.4 hdf5: multiple CVEs ! CVE-2024-29165 7.4 hdf5: multiple CVEs ! CVE-2024-32612 7.4 hdf5: multiple CVEs ! CVE-2024-32613 7.4 hdf5: multiple CVEs ! CVE-2024-32616 7.4 hdf5: multiple CVEs ! CVE-2024-32618 7.4 hdf5: multiple CVEs ! CVE-2024-32619 7.4 hdf5: multiple CVEs ! CVE-2024-32620 7.4 hdf5: multiple CVEs ! CVE-2024-32624 7.4 hdf5: multiple CVEs ! CVE-2026-19027 6.9 HDF5 out-of-bounds heap read in N-Bit filter decompression ! CVE-2026-19023 6.8 HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datas ! CVE-2026-19025 6.8 HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank ! CVE-2026-19026 6.8 Nbit filter NULL/short parameter-array dereference ! CVE-2026-19028 6.8 HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read ! CVE-2017-17506 6.5 hdf5: Out-of-bounds read in the H5Opline_pline_decode function ! CVE-2018-17233 6.5 hdf5: SIGFPE signal in H5D__create_chunk_file_map_hyper() of H5Dchunk.c ! CVE-2018-17234 6.5 hdf5: Memory leak in the H5O__chunk_deserialize() function in H5Ocache.c ! CVE-2018-17237 6.5 hdf5: SIGFPE signal in H5D__chunk_set_info_real() of H5Dchunk.c ! CVE-2018-17432 6.5 hdf5: NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c ! CVE-2018-17433 6.5 hdf5: heap-based buffer overflow in ReadGifImageDesc() in gifread.c ! CVE-2018-17434 6.5 hdf5: SIGFPE signal in apply_filters() in h5repack_filters.c ! CVE-2018-17435 6.5 hdf5: buffer over-read in H5O_attr_decode() in H5Oattr.c ! CVE-2018-17436 6.5 hdf5: invalid write access in ReadCode() in decompress.c ! CVE-2018-17437 6.5 hdf5: memory leak in H5O_dtype_decode_helper() in H5Odtype.c ! CVE-2018-17438 6.5 hdf5: SIGFPE signal in function H5D__select_io() of H5Dselect.c ! CVE-2019-8396 6.5 hdf5: buffer overflow in function H5O__layout_encode in H5Olayout.c ! CVE-2026-26197 5.9 Array full size, element count, and element size are not checked to make sure they match i ! CVE-2026-26199 5.9 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero ! CVE-2024-29166 5.7 hdf5: multiple CVEs ! CVE-2024-32606 5.7 hdf5: multiple CVEs ! CVE-2024-32607 5.7 hdf5: multiple CVEs ! CVE-2024-32610 5.7 hdf5: multiple CVEs ! CVE-2024-33875 5.7 hdf5: multiple CVEs ! CVE-2024-33876 5.7 hdf5: multiple CVEs ! CVE-2020-10809 5.5 hdf5: Heap-based buffer overflow in function Decompress() in decompress.c ! CVE-2020-10810 5.5 hdf5: Null pointer dereference in function H5AC_unpin_entry() in H5AC.c ! CVE-2020-10811 5.5 hdf5: Heap-based buffer over-read in function H5O__layout_decode() in H5Olayout.c ! CVE-2020-10812 5.5 hdf5: Null pointer dereference in function H5F_get_nrefs() in H5Fquery.c ! CVE-2026-17572 5.5 HDF5 SOHM List Index Heap Buffer Overflow ! CVE-2026-29043 5.5 HDF5 H5T__ref_mem_setnull Heap Buffer Overflow ! CVE-2026-17574 5.2 NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag ! CVE-2025-2912 4.8 HDF5 H5Omessage.c H5O_msg_flush heap-based overflow ! CVE-2025-2913 4.8 HDF5 H5FL.c H5FL__blk_gc_list use after free ! CVE-2025-2914 4.8 HDF5 H5FScache.c H5FS__sinfo_Srialize_Sct_cb heap-based overflow ! CVE-2025-2915 4.8 HDF5 H5Faccum.c H5F__accum_free heap-based overflow ! CVE-2025-2923 4.8 HDF5 H5Fint.c H5F_addr_encode_len heap-based overflow ! CVE-2025-2924 4.8 HDF5 H5HLcache.c H5HL__fl_deserialize heap-based overflow ! CVE-2025-2925 4.8 HDF5 H5MM.c H5MM_realloc double free ! CVE-2025-2926 4.8 HDF5 H5Ocache.c H5O__cache_chk_serialize null pointer dereference ! CVE-2025-6269 4.8 HDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflow ! CVE-2025-6270 4.8 HDF5 H5FSsection.c H5FS__sect_find_node heap-based overflow ! CVE-2025-6516 4.8 HDF5 H5Fint.c H5F_addr_decode_len heap-based overflow ! CVE-2026-17573 4.0 Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field science/hdf5-21 hdf5-21-2.1.1 ! CVE-2026-19024 8.2 HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message ! CVE-2026-19027 6.9 HDF5 out-of-bounds heap read in N-Bit filter decompression ! CVE-2026-19023 6.8 HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datas ! CVE-2026-19025 6.8 HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank ! CVE-2026-19026 6.8 Nbit filter NULL/short parameter-array dereference ! CVE-2026-19028 6.8 HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read ! CVE-2026-17572 5.5 HDF5 SOHM List Index Heap Buffer Overflow ! CVE-2026-17574 5.2 NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag ! CVE-2026-17573 4.0 Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field security/boringssl boringssl-0.20260813.0_2 ! CVE-2018-12440 4.7 netty-tcnative-boringssl-static: memory-cache side-channel attack on DSA signatures security/clamav-lts clamav-lts-1.4.4_5,1 ! CVE-2026-20213 7.5 ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability ! CVE-2026-20214 7.5 ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability ! CVE-2026-20215 7.5 ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability ! CVE-2026-20216 7.5 ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability ! CVE-2026-20217 7.5 ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability ! CVE-2026-20243 7.5 ClamAV ALZ Archive Processing Denial of Service Vulnerability ! CVE-2026-20244 7.5 ClamAV DMG File Processing Denial of Service Vulnerability security/gnupg1 gnupg1-1.4.23_5 ! CVE-2026-24882 8.4 GnuPG: GnuPG: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution ! CVE-2025-68973 7.8 In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable ! CVE-2018-12020 7.5 gnupg2: Improper sanitization of filenames allows for the display of fake status messages ! CVE-2019-13050 7.5 GnuPG: interaction between the sks-keyserver code and GnuPG allows for a Certificate Spamm ! CVE-2019-14855 7.5 gnupg2: OpenPGP Key Certification Forgeries with SHA-1 ! CVE-2022-34903 6.5 gpg: Signature spoofing via status line injection ! CVE-2025-68972 5.9 gnupg: GnuPG: Signature bypass via form feed character in signed messages ! CVE-2015-1606 5.5 gnupg2: invalid memory read using a garbled keyring ! CVE-2011-2207 5.3 dirmngr: Improper dealing with blocking system calls, when verifying a certificate ! CVE-2006-3082 5.0 security flaw ! CVE-2026-57062 2.9 GnuPG: Incorrect cryptographic message parsing ! CVE-2025-30258 2.7 gnupg: verification DoS due to a malicious subkey in the keyring security/gstreamer1-plugins-dtls gstreamer1-plugins-dtls-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p security/heimdal heimdal-7.8.0_9 ! CVE-2022-45142 7.5 samba: fix introduced a logic inversion security/ipsec-tools ipsec-tools-0.8.2_13 ! CVE-2015-4047 7.8 ipsec-tools: NULL pointer dereference in racoon/gssapi.c ! CVE-2016-10396 7.5 ipsec-tools: Parsing and storing ISAKMP fragments in malicious order can exhaust resources security/keepass keepass-2.56 ! CVE-2026-86776 4.6 KeePass 2.35 through 2.61.1 Memory Exhaustion via KDBX Header Field Size security/libotr3 libotr3-3.2.1_5 ! CVE-2016-2851 9.8 Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attac security/libp11 libp11-0.4.20 ! CVE-2021-34193 7.5 opensc: Stack overflow vulnerability in OpenSC smart card middleware ! CVE-2018-16391 6.8 opensc: Buffer overflows handling responses from Muscle Cards in card-muscle.c:muscle_list ! CVE-2018-16392 6.8 opensc: Buffer overflows handling responses from TCOS Cards in card-tcos.c:tcos_select_fil ! CVE-2018-16393 6.8 opensc: Buffer overflows handling responses from Gemsafe V1 Smartcards in pkcs15-gemsafeV1 ! CVE-2019-20792 6.8 opensc: Double free in coolkey_free_private_data in libopensc/card-coolkey.c ! CVE-2018-16418 6.6 opensc: Buffer overflow handling string concatention in tools/util.c:util_acl_to_str() ! CVE-2018-16419 6.6 opensc: Buffer overflow handling responses from Cryptoflex cards in cryptoflex-tool.c:read ! CVE-2018-16420 6.6 opensc: Buffer overflows handling responses from ePass 2003 Cards in card-epass2003.c:decr ! CVE-2018-16421 6.6 opensc: Buffer overflows handling responses from CAC Cards in card-cac.c:cac_get_serial_nr ! CVE-2018-16422 6.6 opensc: Buffer overflow handling responses from esteid cards in pkcs15-esteid.c:sc_pkcs15e ! CVE-2018-16423 6.6 opensc: Double free handling responses from smartcards in libopensc/sc.c:sc_file_set_sec_a ! CVE-2018-16424 6.6 opensc: Double free handling responses from smartcards in tools/egk-tool.c:read_file() ! CVE-2018-16425 6.6 opensc: Double free handling responses from HSM Cards in pkcs15-sc-hsm.c:sc_pkcs15emu_sc_h ! CVE-2019-15945 6.4 opensc: Out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1. ! CVE-2019-15946 6.4 opensc: Out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/as ! CVE-2023-5992 5.6 Opensc: side-channel leaks while stripping encryption pkcs#1 padding ! CVE-2019-19479 5.5 opensc: Incorrect read operation during parsing of a SETCOS file attribute ! CVE-2020-26570 5.5 opensc: heap-based buffer overflow in sc_oberthur_read_file ! CVE-2020-26571 5.5 opensc: stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init ! CVE-2020-26572 5.5 opensc: stack-based buffer overflow in tcos_decipher ! CVE-2023-40661 5.4 Opensc: multiple memory issues with pkcs15-init (enrollment tool) ! CVE-2021-42778 5.3 opensc: Heap double free in sc_pkcs15_free_tokeninfo ! CVE-2021-42779 5.3 opensc: Heap use after free in sc_file_valid ! CVE-2021-42780 5.3 opensc: Use after return in insert_pin function ! CVE-2021-42781 5.3 opensc: Heap buffer overflow in pkcs15-oberthur.c ! CVE-2021-42782 5.3 opensc: Stack buffer overflow issues in various places ! CVE-2018-16426 4.3 opensc: Infinite recusrion handling responses from IAS-ECC cards in card-iasecc.c:iasecc_s ! CVE-2018-16427 4.3 opensc: Out of bounds reads handling responses from smartcards ! CVE-2024-45619 4.3 Libopensc: incorrect handling length of buffers or files in libopensc ! CVE-2024-45615 3.9 Libopensc: pkcs15init: usage of uninitialized values in libopensc and pkcs15init ! CVE-2024-45616 3.9 Libopensc: uninitialized values after incorrect check or usage of apdu response values in ! CVE-2024-45617 3.9 Libopensc: uninitialized values after incorrect or missing checking return values of funct ! CVE-2024-45618 3.9 Libopensc: uninitialized values after incorrect or missing checking return values of funct ! CVE-2024-45620 3.9 Libopensc: incorrect handling of the length of buffers or files in pkcs15init ! CVE-2025-66037 3.9 OpenSC: Out of Bounds vulnerability ! CVE-2025-66038 3.9 OpenSC: `sc_compacttlv_find_tag` can return out-of-bounds pointers ! CVE-2025-49010 3.8 OpenSC: Stack-buffer-overflow WRITE in GET RESPONSE ! CVE-2025-66215 3.8 OpenSC: Stack-buffer-overflow WRITE in card-oberthur ! CVE-2026-40510 1.0 OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c ! CVE-2026-40528 1.0 OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c security/libreswan libreswan-4.12_3 ! CVE-2026-50721 8.1 IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload ! CVE-2026-50722 8.1 IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload ! CVE-2026-12413 7.5 IKEv2 Denial of Service via malformed fragmentation ! CVE-2026-14957 7.5 FIPS mode assertion failure via malicious CERT payload ! CVE-2024-3652 6.5 IKEv1 default AH/ESP responder can cause libreswan to abort and restart security/libssh libssh-0.12.2 ! CVE-2023-3603 3.1 Processing sftp server read may cause null dereference security/libssh2 libssh2-1.11.1_1,3 ! CVE-2026-55200 9.2 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c ! CVE-2026-66032 8.7 libssh2 Double-Free Heap Corruption via sftp_open() ! CVE-2026-66033 8.7 libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation ! CVE-2025-15661 8.3 libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c ! CVE-2026-58050 8.3 libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation ! CVE-2026-58051 8.3 libssh2 - Free of Uninitialized Pointer in publickey List Cleanup ! CVE-2026-55199 8.2 libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler ! CVE-2026-66034 7.7 libssh2 Heap Out-of-Bounds Read via publickey subsystem ! CVE-2026-66035 7.7 libssh2 Heap Buffer Overflow via ETM Cipher Negotiation ! CVE-2026-7598 6.9 libssh2 userauth.c userauth_password integer overflow security/libtomcrypt libtomcrypt-1.18.2_1 ! CVE-2019-17362 9.1 libtomcrypt: out-of-bounds read in the der_decode_utf8_string function in der_decode_utf8_ security/linux-c7-gnutls linux-c7-gnutls-3.3.29 ! CVE-2014-3468 7.5 libtasn1: asn1_get_bit_der() can return negative bit length ! CVE-2016-7444 7.5 gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3) ! CVE-2017-7507 7.5 gnutls: Crash upon receiving well-formed status_request extension ! CVE-2017-7869 7.5 gnutls: Out-of-bounds write related to the cdk_pkt_read function (GNUTLS-SA-2017-3) ! CVE-2020-24659 7.5 gnutls: Heap buffer overflow in handshake with no_renegotiation alert sent ! CVE-2022-2509 7.5 gnutls: Double free during gnutls_pkcs7_verify ! CVE-2026-33845 7.5 Gnutls: gnutls: denial of service via dtls zero-length fragment ! CVE-2021-4209 6.5 GnuTLS: Null pointer dereference in MD_UPDATE ! CVE-2025-32988 6.5 Gnutls: vulnerability in gnutls othername san export ! CVE-2026-3833 6.5 Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison ! CVE-2018-10844 5.9 gnutls: HMAC-SHA-256 vulnerable to Lucky thirteen attack due to not enough dummy function ! CVE-2018-10845 5.9 gnutls: HMAC-SHA-384 vulnerable to Lucky thirteen attack due to use of wrong constant ! CVE-2023-5981 5.9 Gnutls: timing side-channel in the rsa-psk authentication ! CVE-2018-10846 5.6 gnutls: "Just in Time" PRIME + PROBE cache-based side channel attack can lead to plaintext ! CVE-2018-16868 5.6 gnutls: Bleichenbacher-like side channel leakage in PKCS#1 v1.5 verification and padding o ! CVE-2014-3467 5.0 libtasn1: multiple boundary check issues ! CVE-2014-3469 5.0 libtasn1: asn1_read_value_type() NULL pointer dereference ! CVE-2026-3832 3.7 Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via craft security/linux-c7-libgcrypt linux-c7-libgcrypt-1.5.3_4 ! CVE-2017-0379 7.5 libgcrypt: Missing input validation for X25519 curve ! CVE-2018-6829 7.5 libgcrypt: ElGamal implementation doesn't have semantic security due to incorrectly encode ! CVE-2021-33560 7.5 libgcrypt: mishandles ElGamal encryption because it lacks exponent blinding to address a s ! CVE-2017-7526 6.1 libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery ! CVE-2015-0837 5.9 libgcrypt: last-level cache side-channel attack ! CVE-2017-9526 5.9 libgcrypt: Possible timing attack on EdDSA session key ! CVE-2021-40528 5.9 libgcrypt: ElGamal implementation allows plaintext recovery ! CVE-2016-6313 5.3 libgcrypt: PRNG output is predictable ! CVE-2018-0495 4.7 ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries ! CVE-2014-3591 4.2 libgcrypt: use ciphertext blinding for Elgamal decryption (new side-channel attack) ! CVE-2014-5270 2.1 libgcrypt: ELGAMAL side-channel attack ! CVE-2015-7511 2.0 libgcrypt: side-channel attack on ECDH with Weierstrass curves security/linux-c7-libssh2 linux-c7-libssh2-1.8.0_2 ! CVE-2026-55200 9.2 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c ! CVE-2019-3859 9.1 libssh2: Unchecked use of _libssh2_packet_require and _libssh2_packet_requirev resulting i ! CVE-2019-3855 8.8 libssh2: Integer overflow in transport read resulting in out of bounds write ! CVE-2019-3856 8.8 libssh2: Integer overflow in keyboard interactive handling resulting in out of bounds writ ! CVE-2019-3857 8.8 libssh2: Integer overflow in SSH packet processing channel resulting in out of bounds writ ! CVE-2026-66032 8.7 libssh2 Double-Free Heap Corruption via sftp_open() ! CVE-2026-66033 8.7 libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation ! CVE-2025-15661 8.3 libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c ! CVE-2026-58050 8.3 libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation ! CVE-2026-58051 8.3 libssh2 - Free of Uninitialized Pointer in publickey List Cleanup ! CVE-2026-55199 8.2 libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler ! CVE-2019-13115 8.1 libssh2: integer overflow in kex_method_diffie_hellman_group_exchange_sha256_key_exchange ! CVE-2019-17498 8.1 libssh2: integer overflow in SSH_MSG_DISCONNECT logic in packet.c ! CVE-2026-66034 7.7 libssh2 Heap Out-of-Bounds Read via publickey subsystem ! CVE-2026-66035 7.7 libssh2 Heap Buffer Overflow via ETM Cipher Negotiation ! CVE-2019-3863 7.5 libssh2: Integer overflow in user authenticate keyboard interactive allows out-of-bounds w ! CVE-2019-3862 7.3 libssh2: Out-of-bounds memory comparison with specially crafted message channel request ! CVE-2026-7598 6.9 libssh2 userauth.c userauth_password integer overflow ! CVE-2023-48795 5.9 ssh: Prefix truncation attack on Binary Packet Protocol (BPP) ! CVE-2019-3858 5.0 libssh2: Zero-byte allocation with a specially crafted SFTP packed leading to an out-of-bo ! CVE-2019-3860 5.0 libssh2: Out-of-bounds reads with specially crafted SFTP packets ! CVE-2019-3861 5.0 libssh2: Out-of-bounds reads with specially crafted SSH packets security/linux-c7-libtasn1 linux-c7-libtasn1-4.10 ! CVE-2021-46848 9.1 libtasn1: Out-of-bound access in ETYPE_OK ! CVE-2017-6891 8.8 libtasn1: Stack-based buffer overflow in asn1_find_node() ! CVE-2017-10790 7.5 libtasn1: NULL pointer dereference in the _asn1_check_identifier function ! CVE-2018-6003 7.5 libtasn1: Stack exhaustion due to indefinite recursion during BER decoding ! CVE-2025-13151 7.5 CVE-2025-13151 security/linux-c7-nettle linux-c7-nettle-2.7.1_1 ! CVE-2015-8803 9.8 nettle: secp256 calculation bug ! CVE-2015-8804 9.8 nettle: miscalculations on secp384 curve ! CVE-2015-8805 9.8 nettle: secp256 calculation bug ! CVE-2021-20305 8.1 nettle: Out of bounds memory access in signature verification ! CVE-2016-6489 7.5 nettle: RSA/DSA code is vulnerable to cache-timing related attacks ! CVE-2021-3580 7.5 nettle: Remote crash in RSA decryption via manipulated ciphertext ! CVE-2018-16869 5.7 nettle: Leaky data conversion exposing a manager oracle security/linux-c7-openssl-devel linux-c7-openssl-devel-1.0.2k_2 ! CVE-2022-1292 9.8 The c_rehash script allows command injection ! CVE-2022-2068 9.8 The c_rehash script allows command injection ! CVE-2024-5535 9.1 SSL_select_next_proto buffer overread ! CVE-2026-45447 8.8 Heap Use-After-Free in the PKCS7_verify() Function ! CVE-2026-7383 8.1 Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion ! CVE-2018-0732 7.5 Client DoS due to large DH parameter ! CVE-2021-23840 7.5 Integer overflow in CipherUpdate ! CVE-2022-0778 7.5 Infinite loop in BN_mod_sqrt() reachable when parsing certificates ! CVE-2023-0215 7.5 Use-after-free following BIO_new_NDEF ! CVE-2023-0464 7.5 Excessive Resource Usage Verifying X.509 Policy Constraints ! CVE-2025-69421 7.5 NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function ! CVE-2025-9230 7.5 Out-of-bounds read & write in RFC 3211 KEK Unwrap ! CVE-2026-28388 7.5 NULL Pointer Dereference When Processing a Delta CRL ! CVE-2026-28389 7.5 Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo ! CVE-2026-28390 7.5 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo ! CVE-2026-34180 7.5 Heap Buffer Over-read in ASN.1 Content Parsing ! CVE-2026-54874 7.5 Excessive Memory Use Buffering DTLS Records for a Future Epoch ! CVE-2026-9076 7.5 Out-of-Bounds Read in CMS Password-Based Decryption ! CVE-2021-3712 7.4 Read buffer overruns processing ASN.1 strings ! CVE-2023-0286 7.4 X.400 address type confusion in X.509 GeneralName ! CVE-2017-3736 6.5 openssl: bn_sqrx8x_internal carry bug on x86_64 ! CVE-2018-0739 6.5 Constructed ASN.1 types with a recursive definition could exceed the stack ! CVE-2023-2650 6.5 Possible DoS translating ASN.1 object identifiers ! CVE-2017-3737 5.9 openssl: Read/write after SSL object in error state ! CVE-2017-3738 5.9 openssl: rsaz_1024_mul_avx2 overflow bug on x86_64 ! CVE-2018-0734 5.9 Timing attack against DSA ! CVE-2018-0737 5.9 Cache timing vulnerability in RSA Key Generation ! CVE-2019-1559 5.9 0-byte record padding oracle ! CVE-2020-1971 5.9 EDIPARTYNAME NULL pointer dereference ! CVE-2021-23841 5.9 Null pointer deref in X509_issuer_and_serial_hash() ! CVE-2021-4160 5.9 BN_mod_exp may produce incorrect results on MIPS ! CVE-2022-4304 5.9 Timing Oracle in RSA Decryption ! CVE-2026-42766 5.9 Possible NULL Dereference in Password-Based CMS Decryption ! CVE-2024-0727 5.5 PKCS12 Decoding crashes ! CVE-2017-3735 5.3 openssl: Malformed X.509 IPAdressFamily could cause OOB read ! CVE-2019-1551 5.3 rsaz_512_sqr overflow bug on x86_64 ! CVE-2023-0465 5.3 Invalid certificate policies in leaf certificates are silently ignored ! CVE-2023-0466 5.3 Certificate policy check not enabled ! CVE-2023-3446 5.3 Excessive time spent checking DH keys and parameters ! CVE-2023-3817 5.3 Excessive time spent checking DH q parameter value ! CVE-2023-5678 5.3 Excessive time spent in DH check / generation with large Q parameter value ! CVE-2026-22796 5.3 ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function ! CVE-2018-5407 4.7 openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) ! CVE-2019-1547 4.7 ECDSA remote timing attack ! CVE-2025-68160 4.7 Heap out-of-bounds write in BIO_f_linebuffer on short writes ! CVE-2024-9143 4.3 Low-level invalid GF(2^m) parameters lead to OOB memory access ! CVE-2024-13176 4.1 Timing side-channel in ECDSA signature computation ! CVE-2019-1563 3.7 Padding Oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey ! CVE-2020-1968 3.7 Raccoon attack ! CVE-2019-1552 3.3 Windows builds with insecure path defaults security/linux-c7-trousers linux-c7-trousers-0.3.14_1 ! CVE-2020-24330 7.8 trousers: fails to drop the root gid privilege when no longer needed ! CVE-2020-24331 7.8 trousers: tss user still has read and write access to the /etc/tcsd.conf file if tcsd is s security/linux-rl9-gnupg linux-rl9-gnupg2-2.3.3_3 ! CVE-2022-3515 9.8 libksba: integer overflow may lead to remote code execution ! CVE-2026-24882 8.4 GnuPG: GnuPG: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution ! CVE-2025-68973 7.8 In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable ! CVE-2022-34903 6.5 gpg: Signature spoofing via status line injection ! CVE-2025-68972 5.9 gnupg: GnuPG: Signature bypass via form feed character in signed messages ! CVE-2026-57062 2.9 GnuPG: Incorrect cryptographic message parsing ! CVE-2025-30258 2.7 gnupg: verification DoS due to a malicious subkey in the keyring security/linux-rl9-gnutls linux-rl9-gnutls-3.8.10 ! CVE-2026-33845 7.5 Gnutls: gnutls: denial of service via dtls zero-length fragment ! CVE-2026-3833 6.5 Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison ! CVE-2026-3832 3.7 Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via craft security/linux-rl9-libgcrypt linux-rl9-libgcrypt-1.10.0_2 ! CVE-2026-41989 6.7 Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext security/linux-rl9-libksba linux-rl9-libksba-1.5.1 ! CVE-2022-3515 9.8 libksba: integer overflow may lead to remote code execution ! CVE-2022-47629 9.8 libksba: integer overflow to code execution security/linux-rl9-libssh linux-rl9-libssh-0.10.4_2 ! CVE-2026-0966 8.2 Libssh: libssh: denial of service via zero-length input in ssh_get_hexa() ! CVE-2025-5987 8.1 Libssh: invalid return code for chacha20 poly1305 with openssl backend ! CVE-2025-14821 7.8 Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on ! CVE-2026-3731 6.9 libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds ! CVE-2023-1667 6.5 libssh: NULL pointer dereference during rekeying with algorithm guessing ! CVE-2023-2283 6.5 libssh: authorization bypass in pki_verify_data_signature ! CVE-2025-5351 6.5 Libssh: double free vulnerability in libssh key export functions ! CVE-2026-0964 6.3 Libssh: improper sanitation of paths received from scp servers ! CVE-2023-48795 5.9 ssh: Prefix truncation attack on Binary Packet Protocol (BPP) ! CVE-2026-59847 5.9 Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification ! CVE-2026-0967 5.5 Libssh: libssh: denial of service via inefficient regular expression processing ! CVE-2025-5318 5.4 Libssh: out-of-bounds read in sftp_handle() ! CVE-2025-5372 5.0 Libssh: incorrect return code handling in ssh_kdf() in libssh ! CVE-2023-6004 4.8 Libssh: proxycommand/proxyjump features allow injection of malicious code through hostname ! CVE-2025-8114 4.7 Libssh: null pointer dereference in libssh kex session id calculation ! CVE-2023-6918 3.7 Libssh: missing checks for return values for digests ! CVE-2026-0965 3.3 Libssh: libssh: denial of service via improper configuration file handling ! CVE-2023-3603 3.1 Processing sftp server read may cause null dereference ! CVE-2026-0968 3.1 Libssh: libssh: denial of service due to malformed sftp message security/linux-rl9-libtasn1 linux-rl9-libtasn1-4.16.0_2 ! CVE-2021-46848 9.1 libtasn1: Out-of-bound access in ETYPE_OK ! CVE-2025-13151 7.5 CVE-2025-13151 security/makepasswd makepasswd-1.10_8 ! CVE-2010-2247 7.5 makepasswd 1.10 default settings generate insecure passwords security/nikto nikto-2.1.6_1,1 ! CVE-2018-11652 9.8 CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject a security/olm olm-3.2.13 ! CVE-2024-45191 5.3 An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnera ! CVE-2024-45193 4.3 An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature mallea security/openssl-unsafe openssl-unsafe-1.0.2.20170706 ! CVE-2022-1292 9.8 The c_rehash script allows command injection ! CVE-2022-2068 9.8 The c_rehash script allows command injection ! CVE-2024-5535 9.1 SSL_select_next_proto buffer overread ! CVE-2026-45447 8.8 Heap Use-After-Free in the PKCS7_verify() Function ! CVE-2026-7383 8.1 Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion ! CVE-2018-0732 7.5 Client DoS due to large DH parameter ! CVE-2021-23840 7.5 Integer overflow in CipherUpdate ! CVE-2022-0778 7.5 Infinite loop in BN_mod_sqrt() reachable when parsing certificates ! CVE-2023-0215 7.5 Use-after-free following BIO_new_NDEF ! CVE-2023-0464 7.5 Excessive Resource Usage Verifying X.509 Policy Constraints ! CVE-2025-69421 7.5 NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function ! CVE-2025-9230 7.5 Out-of-bounds read & write in RFC 3211 KEK Unwrap ! CVE-2026-28388 7.5 NULL Pointer Dereference When Processing a Delta CRL ! CVE-2026-28389 7.5 Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo ! CVE-2026-28390 7.5 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo ! CVE-2026-34180 7.5 Heap Buffer Over-read in ASN.1 Content Parsing ! CVE-2026-54874 7.5 Excessive Memory Use Buffering DTLS Records for a Future Epoch ! CVE-2026-9076 7.5 Out-of-Bounds Read in CMS Password-Based Decryption ! CVE-2021-3712 7.4 Read buffer overruns processing ASN.1 strings ! CVE-2023-0286 7.4 X.400 address type confusion in X.509 GeneralName ! CVE-2017-3736 6.5 openssl: bn_sqrx8x_internal carry bug on x86_64 ! CVE-2018-0739 6.5 Constructed ASN.1 types with a recursive definition could exceed the stack ! CVE-2023-2650 6.5 Possible DoS translating ASN.1 object identifiers ! CVE-2017-3737 5.9 openssl: Read/write after SSL object in error state ! CVE-2017-3738 5.9 openssl: rsaz_1024_mul_avx2 overflow bug on x86_64 ! CVE-2018-0734 5.9 Timing attack against DSA ! CVE-2018-0737 5.9 Cache timing vulnerability in RSA Key Generation ! CVE-2019-1559 5.9 0-byte record padding oracle ! CVE-2020-1971 5.9 EDIPARTYNAME NULL pointer dereference ! CVE-2021-23841 5.9 Null pointer deref in X509_issuer_and_serial_hash() ! CVE-2021-4160 5.9 BN_mod_exp may produce incorrect results on MIPS ! CVE-2022-4304 5.9 Timing Oracle in RSA Decryption ! CVE-2026-42766 5.9 Possible NULL Dereference in Password-Based CMS Decryption ! CVE-2024-0727 5.5 PKCS12 Decoding crashes ! CVE-2017-3735 5.3 openssl: Malformed X.509 IPAdressFamily could cause OOB read ! CVE-2019-1551 5.3 rsaz_512_sqr overflow bug on x86_64 ! CVE-2023-0465 5.3 Invalid certificate policies in leaf certificates are silently ignored ! CVE-2023-0466 5.3 Certificate policy check not enabled ! CVE-2023-3446 5.3 Excessive time spent checking DH keys and parameters ! CVE-2023-3817 5.3 Excessive time spent checking DH q parameter value ! CVE-2023-5678 5.3 Excessive time spent in DH check / generation with large Q parameter value ! CVE-2026-22796 5.3 ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function ! CVE-2018-5407 4.7 openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) ! CVE-2019-1547 4.7 ECDSA remote timing attack ! CVE-2025-68160 4.7 Heap out-of-bounds write in BIO_f_linebuffer on short writes ! CVE-2024-9143 4.3 Low-level invalid GF(2^m) parameters lead to OOB memory access ! CVE-2024-13176 4.1 Timing side-channel in ECDSA signature computation ! CVE-2019-1563 3.7 Padding Oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey ! CVE-2020-1968 3.7 Raccoon attack ! CVE-2019-1552 3.3 Windows builds with insecure path defaults security/openvpn openvpn-2.7.7 ! CVE-2026-11604 5.6 Heap Buffer Overflow in OpenVPN ovpn-dco-win Leading to System Crash security/openvpn-devel openvpn-devel-g20260907,2 ! CVE-2017-12166 9.8 OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow v ! CVE-2024-27903 9.8 OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any direct ! CVE-2024-5594 9.1 OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker cont ! CVE-2026-84732 8.7 openvpn: OpenVPN: Remote Denial of Service via crafted ACK packets ! CVE-2024-27459 7.8 The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causi ! CVE-2017-7508 7.5 openvpn: Multiple security issues fixed in OpenVPN 2.4.3 and 2.3.17 ! CVE-2020-15078 7.5 OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and ! CVE-2020-20813 7.5 Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of ! CVE-2024-24974 7.5 The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be ! CVE-2017-7520 7.4 openvpn: Multiple security issues fixed in OpenVPN 2.4.3 and 2.3.17 ! CVE-2017-7479 6.5 OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when ! CVE-2017-7522 6.5 openvpn: Multiple security issues fixed in OpenVPN 2.4.3 and 2.3.17 ! CVE-2016-6329 5.9 OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain ! CVE-2017-7521 5.9 openvpn: Multiple security issues fixed in OpenVPN 2.4.3 and 2.3.17 ! CVE-2013-2061 2.6 The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP security/py-cryptography-legacy py312-cryptography-legacy-3.4.8_3,1 ! CVE-2026-26007 8.2 cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves ! CVE-2023-50782 7.5 Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomple ! CVE-2023-49083 5.9 cryptography vulnerable to NULL-dereference when loading PKCS7 certificates ! CVE-2023-23931 4.8 Cipher.update_into can corrupt memory in pyca cryptography ! CVE-2026-34073 1.7 cryptography has incomplete DNS name constraint enforcement on peer names security/py-m2crypto py312-m2crypto-0.49.0 ! CVE-2023-50781 7.5 M2crypto: bleichenbacher timing attacks in the rsa decryption api - incomplete fix for cve security/py-tlslite py312-tlslite-0.4.9_2 ! CVE-2015-3220 7.5 The tlslite library before 0.4.9 for Python allows remote attackers to trigger a denial of security/rubygem-omniauth1 rubygem-omniauth1-1.9.2_1 ! CVE-2015-9284 8.8 rubygem-omniauth: request phase of the OmniAuth Ruby gem is vulnerable to Cross-Site Reque security/strongswan strongswan-6.0.7_1 ! CVE-2026-78130 7.5 NULL Pointer Dereference in strongSwan X.509 Attribute Certificate Parser ! CVE-2026-78132 7.5 Infinite Loop in StrongSwan X.509 Attribute Certificate Parser ! CVE-2026-78133 7.5 Use-After-Free in strongSwan IKEv2 Rekeying Collision Handling ! CVE-2026-78134 7.1 Imprecise Access Control in eap-ttls/eap-peap Plugins of strongSwan ! CVE-2026-78123 5.9 Expired Pointer Dereference in strongSwan PKCS#7 Parsing ! CVE-2026-78126 5.9 NULL Pointer Dereference in strongSwan eap-aka Plugin ! CVE-2026-78129 5.9 Infinite Loop in PKCS#5 Decryption of strongSwan ! CVE-2026-78135 5.6 Authentication Bypass via CREATE_CHILD_SA in strongSwan IKEv2 ! CVE-2026-78124 3.7 StrongSwan PKCS#7 Certificate Enumeration Memory Leak ! CVE-2026-78127 3.7 Memory Leak in StrongSwan's IKE Message Parser ! CVE-2026-78131 3.7 Memory Leak in strongSwan X509 Attribute Certificate Parser security/tang tang-15_1 ! CVE-2023-1672 5.3 Race condition exists in the key generation and rotation functionality security/tinc tinc-1.0.37 ! CVE-2013-1428 6.5 Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc befo security/tinc-devel tinc-devel-1.1pre18_4 ! CVE-2013-1428 6.5 Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc befo security/trousers trousers-0.3.14_5 ! CVE-2020-24330 7.8 trousers: fails to drop the root gid privilege when no longer needed ! CVE-2020-24331 7.8 trousers: tss user still has read and write access to the /etc/tcsd.conf file if tcsd is s security/wazuh-agent wazuh-agent-4.14.7 ! CVE-2026-67307 7.0 Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync security/wazuh-manager wazuh-manager-4.14.7 ! CVE-2026-67307 7.0 Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync security/wpa_supplicant29 wpa_supplicant29-2.9_12 ! CVE-2022-23303 9.8 wpa_supplicant: SAE side channel attacks as a result of cache access patterns ! CVE-2022-23304 9.8 wpa_supplicant: EAP-pwd side-channel attacks as a result of cache access patterns ! CVE-2021-27803 7.5 wpa_supplicant: Use-after-free in P2P provision discovery processing ! CVE-2019-16275 6.5 wpa_supplicant: AP mode PMF disconnection protection bypass ! CVE-2021-30004 4.3 wpa_supplicant: mishandled AlgorithmIdentifier parameters may lead to forging attacks sysutils/busybox busybox-1.38.0 ! CVE-2026-38754 5.1 Heap Overflow in BusyBox Ash Shell Causes Denial of Service ! CVE-2026-38753 4.9 Use-After-Free in BusyBox Awk Leading to Denial of Service ! CVE-2026-38752 2.9 busybox: BusyBox: Denial of Service via crafted AWK script ! CVE-2026-38755 2.9 busybox: Busybox: Denial of Service via heap overflow in evalcommand() function sysutils/consul consul-2.0.3_2 ! CVE-2026-87090 8.3 Consul vulnerable to an authorization bypass in the catalog node-write path ! CVE-2026-88021 7.5 Consul vulnerable to an authorization bypass in the Connect service mesh ! CVE-2026-87106 6.5 Consul vulnerable to a denial of service in the native RPC listener sysutils/coreutils coreutils-9.9 ! CVE-2026-56391 4.6 Out‑of‑bounds Read in GNU coreutils ! CVE-2026-56392 1.8 Heap-based Buffer Overflow in GNU coreutils sysutils/dmg2img dmg2img-1.6.7 ! CVE-2021-32614 7.1 A flaw was found in dmg2img through 20170502. fill_mishblk() does not check the length of ! CVE-2021-3548 7.1 A flaw was found in dmg2img through 20170502. dmg2img did not validate the size of the rea sysutils/edk2 edk2-bhyve-g202508_2 ! CVE-2021-38575 8.1 edk2: remote buffer overflow in IScsiHexToBin function in NetworkPkg/IScsiDxe ! CVE-2017-5731 7.8 edk2: Privilege escalation via processing of malformed files in TianoCompress.c ! CVE-2019-14584 7.8 edk2: NULL pointer dereference in AuthenticodeVerify() ! CVE-2021-28210 7.8 edk2: unlimited FV recursion, round 2 ! CVE-2021-38578 7.4 edk2: integer underflow in SmmEntryPoint function leads to potential SMM privilege escalat ! CVE-2022-36763 7.0 Heap Buffer Overflow in Tcg2MeasureGptTable ! CVE-2022-36764 7.0 Heap Buffer Overflow in Tcg2MeasurePeImage ! CVE-2022-36765 7.0 Integer Overflow in CreateHob ! CVE-2014-8271 6.8 uefi: INTEL-TA-201410-001 && INTEL-TA-201410-002 ! CVE-2023-48733 6.7 An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This al ! CVE-2023-49721 6.7 An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS sysutils/flexbackup flexbackup-1.2.1_8 ! CVE-2005-4802 4.6 Flexbackup 1.2.1 and earlier allows local users to overwrite files and execute code via a sysutils/froxlor froxlor-2.3.5 ! CVE-2026-41228 10.0 Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that l ! CVE-2026-41229 9.1 Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generatio ! CVE-2026-62988 9.0 Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints ! CVE-2026-54347 8.7 Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover ! CVE-2026-41237 8.6 Froxlor has an incomplete fix for CVE-2026-30932 ! CVE-2026-41230 8.5 Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones:: ! CVE-2026-52793 8.1 Froxlor: API Authentication bypasses 2FA Authentication ! CVE-2026-41234 7.6 Froxlor: BIND Zone File Injection via TXT Record Content ! CVE-2026-41231 7.5 Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Director ! CVE-2026-54348 7.2 Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Dat ! CVE-2026-55593 6.5 Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery ! CVE-2026-41233 5.4 Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.ad ! CVE-2026-54543 5.4 Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields ! CVE-2026-41232 5.0 Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allow sysutils/gstreamer1-plugins-cdio gstreamer1-plugins-cdio-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p sysutils/hardlink hardlink-0.3.0_1 ! CVE-2011-3631 8.8 hardlink: Multiple integer overflows, when adding string lengths sysutils/helm helm-3.21.4_2 ! CVE-2026-63308 5.3 Helm Files.Lines Denial of Service via Empty Chart Files sysutils/istio istio-1.7.4_45 ! CVE-2021-31921 9.8 istio/istio: authorization bypass when using AUTO_PASSTHROUGH ! CVE-2026-31837 8.7 Istio JWKS resolver to prevent private key material from being exposed when JWKS fetch fai ! CVE-2021-39155 8.3 Authorization Policy Bypass Due to Case Insensitive Host Comparison ! CVE-2021-39156 8.1 Fragments in Path May Lead to Authorization Policy Bypass ! CVE-2022-23635 7.5 Unauthenticated control plane denial of service attack in Istio ! CVE-2022-24726 7.5 Unauthenticated control plane denial of service attack in Istio ! CVE-2022-39278 7.5 Istio vulnerable to denial of service attack due to Golang Regex Library ! CVE-2023-44487 7.5 KEV HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset A ! CVE-2022-31045 7.0 Ill-formed headers may lead to unexpected behavior in Istio ! CVE-2026-31838 6.9 Istio HTTP debug endpoints on port 15014 to enforce namespace-based authorization, prevent ! CVE-2021-31920 6.5 istio/istio: HTTP request with escaped slash characters can bypass authorization mechanism ! CVE-2026-41413 5.0 Istio Vulnerable to SSRF via RequestAuthentication jwksUri sysutils/kubectl kubectl-1.36.4_1 ! CVE-2023-30513 7.5 jenkins: Improper masking of credentials in multiple plugins sysutils/loganalyzer loganalyzer-php84-4.1.13 ! CVE-2023-34600 9.8 Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. ! CVE-2023-36306 6.1 A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 al sysutils/loki grafana-loki-2.9.2_32 ! CVE-2026-21726 5.3 Loki Path Traversal - CVE-2021-36156 Bypass sysutils/nomad nomad-1.9.6_12 ! CVE-2026-14891 8.7 Nomad vulnerable to sandbox escape in Docker task driver ! CVE-2025-4922 8.1 Nomad Vulnerable To Incorrect ACL Policy Lookup Attached To A Job ! CVE-2026-14373 7.7 Nomad Docker driver Linux host namespace bypass ! CVE-2025-3744 7.6 Nomad Vulnerable To Violation Of Mandatory Sentinel Policies in Nomad Job Submissions via ! CVE-2025-1296 6.5 Nomad Exposes Sensitive Workload Identity and Client Secret Token in Audit Logs ! CVE-2026-6959 6.0 Nomad vulnerable to arbitrary file read/write on client host through symlink attack ! CVE-2026-14896 4.2 Nomad vulnerable to cross-namespace host volume claim deletion sysutils/racktables racktables-php84-0.22.0_1 ! CVE-2023-49453 6.1 racktables: XSS vulnerability allow local attackers to execute arbitrary code ! CVE-2026-18819 5.3 RackTables cross-site request forgery sysutils/syslog-ng syslog-ng-4.12.0_4 ! CVE-2022-38725 7.5 An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allow sysutils/terraform terraform-1.15.9_1 ! CVE-2021-36230 8.8 HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authoriza sysutils/tmux23 tmux23-2.3_2 <000.fbsd@quip.cz> ! CVE-2020-27347 8.8 tmux stack buffer overflow in function input_csi_dispatch_sgr_colon sysutils/xen-tools xen-tools-4.21.0.20260212 ! CVE-2021-28701 7.8 Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xe ! CVE-2022-23033 7.8 xen: arm: guest_physmap_remove_page not removing the p2m mappings (XSA-393) ! CVE-2022-42332 7.8 x86 shadow plus log-dirty mode use-after-free In environments where host assisted address ! CVE-2023-34319 7.8 Linux: buffer overrun in netback due to unusual packet ! CVE-2026-23554 7.8 Use after free of paging structures in EPT ! CVE-2026-23558 7.8 grant table v2 race in status page mapping ! CVE-2024-31145 7.5 error handling in x86 IOMMU identity mapping ! CVE-2024-31146 7.5 PCI device pass-through with shared resources ! CVE-2025-1713 7.5 deadlock potential with VT-d and legacy PCI device pass-through ! CVE-2025-58147 7.5 x86: Incorrect input sanitisation in Viridian hypercalls ! CVE-2025-58148 7.5 x86: Incorrect input sanitisation in Viridian hypercalls ! CVE-2025-58149 7.5 Incorrect removal of permissions on PCI device unplug ! CVE-2024-45817 7.3 x86: Deadlock in vlapic_error() ! CVE-2021-28692 7.1 inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to the ! CVE-2026-23555 7.1 Xenstored DoS by unprivileged domain ! CVE-2018-5244 6.5 xen: memory leak with MSR emulation (XSA-253) ! CVE-2022-42319 6.5 Xenstore: Guests can cause Xenstore to not free temporary memory When working on a request ! CVE-2023-46841 6.5 x86: shadow stack vs exceptions from emulation stubs ! CVE-2023-46842 6.5 x86 HVM hypercalls may trigger Xen bug check ! CVE-2026-23557 6.5 Xenstored DoS via XS_RESET_WATCHES command ! CVE-2022-33748 5.6 lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanu ! CVE-2021-28698 5.5 long running loops in grant table handling In order to properly monitor resource use, Xen ! CVE-2021-28699 5.5 inadequate grant-v2 status frames array bounds check The v2 grant table interface separate ! CVE-2022-42325 5.5 Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA informati ! CVE-2022-42326 5.5 Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA informati ! CVE-2023-34327 5.5 x86/AMD: Debug Mask handling ! CVE-2024-45819 5.5 libxl leaks data to PVH guests via ACPI tables ! CVE-2021-28700 4.9 xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator t ! CVE-2022-23035 4.6 xen: Insufficient cleanup of passed-through device IRQs (XSA-395) ! CVE-2025-27465 4.3 x86: Incorrect stubs exception handling for flags recovery ! CVE-2023-46840 4.1 VT-d: Failure to quarantine devices in !HVM builds ! CVE-2026-23553 2.9 x86: incomplete IBPB for vCPU isolation textproc/antiword antiword-0.37_5 ! CVE-2014-8123 5.0 Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attack textproc/apache-solr apache-solr-10.0.0_1,1 ! CVE-2026-44825 8.1 Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users textproc/catdoc catdoc-0.95_1 ! CVE-2024-52035 8.4 An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser ! CVE-2024-54028 8.4 An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality o ! CVE-2017-11110 7.8 The ole_init function in ole.c in catdoc 0.95 allows remote attackers to cause a denial of ! CVE-2023-31979 7.8 Catdoc v0.95 was discovered to contain a global buffer overflow via the function process_f ! CVE-2023-46345 7.5 Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2cs ! CVE-2023-41633 5.5 Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2cs textproc/ezxml ezxml-0.8.6 ! CVE-2021-26220 8.1 The ezxml_toxml function in ezxml 0.8.6 and earlier is vulnerable to OOB write when openin ! CVE-2021-26221 8.1 The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening ! CVE-2021-26222 8.1 The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening ! CVE-2019-20006 7.5 An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts ! CVE-2021-31598 7.5 An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs ! CVE-2019-20005 6.5 An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while par ! CVE-2019-20007 6.5 An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while p ! CVE-2019-20198 6.5 An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_ent_ok() mishandl ! CVE-2019-20199 6.5 An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while par ! CVE-2019-20200 6.5 An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while par ! CVE-2019-20201 6.5 An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandl ! CVE-2019-20202 6.5 An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content() tr ! CVE-2021-30485 6.5 An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd(), w ! CVE-2021-31229 6.5 An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() pe ! CVE-2021-31347 6.5 An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() perfo ! CVE-2021-31348 6.5 An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() perfo ! CVE-2022-30045 6.5 mapcache: incorrect memory handling in ezml support leading to a heap out-of-bounds read textproc/flex flex-2.6.4_3 ! CVE-2019-6293 5.5 flex: Recursive calls in the function mark_beginning_as_normal resulting in a denial of se textproc/gstreamer1-plugins-zxing gstreamer1-plugins-zxing-1.28.6_1 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p textproc/kibana8 kibana8-8.19.15_1 ! CVE-2026-72665 8.1 Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions ! CVE-2026-78583 8.1 Incorrect Authorization in Kibana Leading to Privilege Escalation ! CVE-2026-82302 8.1 Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification ! CVE-2026-72670 7.7 Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure ! CVE-2026-72669 7.6 Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tamp ! CVE-2026-72658 7.3 Cross-Site Request Forgery in Kibana Leading to Privilege Escalation ! CVE-2026-72677 7.3 Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Othe ! CVE-2026-78590 7.3 Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori ! CVE-2026-78592 7.3 Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori ! CVE-2026-49095 7.2 Improper Input Validation in Kibana Fleet Leading to Privilege Escalation ! CVE-2026-56147 7.1 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Informa ! CVE-2026-72629 7.1 Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access t ! CVE-2026-72630 7.1 Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation ! CVE-2026-72632 7.1 Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearc ! CVE-2026-72675 7.1 Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclo ! CVE-2026-33464 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-33465 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-42399 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-42400 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-49089 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-49094 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-56151 6.5 Improper Input Validation in Kibana Leading to Denial of Service ! CVE-2026-63139 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-63260 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-63261 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-72628 6.5 Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service ! CVE-2026-72651 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72652 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72653 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72654 6.5 Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure ! CVE-2026-72659 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72660 6.5 Uncaught Exception in Kibana Leading to Denial of Service ! CVE-2026-72661 6.5 Missing Authorization in Kibana Leading to Information Disclosure ! CVE-2026-72663 6.5 Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service ! CVE-2026-72664 6.5 Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Act ! CVE-2026-72667 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72676 6.5 Improper Control of Generation of Code in Fleet Server Leading to Code Injection ! CVE-2026-78586 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-78599 6.5 Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources ! CVE-2026-78608 6.5 Missing Authorization in Kibana Leading to Information Disclosure ! CVE-2026-78591 6.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana L ! CVE-2026-72673 5.4 Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private L ! CVE-2026-78598 5.4 Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine ! CVE-2026-33463 5.3 Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized ! CVE-2026-63142 5.0 Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery ! CVE-2026-33462 4.6 Path Traversal in Kibana Leading to Unauthorized Deletion of User Accounts ! CVE-2026-49096 4.3 Uncaught Exception in Kibana Cases Leading to Denial of Service ! CVE-2026-63145 4.3 Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromi ! CVE-2026-72650 4.3 Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosu ! CVE-2026-72655 4.3 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana L ! CVE-2026-72671 4.3 Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning T ! CVE-2026-78593 4.3 Improper Control of Generation of Code in Kibana Leading to Privilege Escalation ! CVE-2026-78596 4.3 Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations ! CVE-2026-78597 4.3 Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation ! CVE-2026-82293 4.3 Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption ! CVE-2026-82298 4.3 Incorrect Authorization in Kibana Leading to Denial of Service ! CVE-2026-78606 4.2 Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and De ! CVE-2026-42401 4.1 Improper Neutralization of Input During Web Page Generation in Kibana Leading to Stored HT textproc/kibana91 kibana91-9.1.10 ! CVE-2026-72665 8.1 Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions ! CVE-2026-78583 8.1 Incorrect Authorization in Kibana Leading to Privilege Escalation ! CVE-2026-82302 8.1 Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification ! CVE-2026-33461 7.7 Incorrect Authorization in Kibana Fleet Leading to Information Disclosure ! CVE-2026-42398 7.7 Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network Access ! CVE-2026-72670 7.7 Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure ! CVE-2026-72672 7.7 Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event D ! CVE-2026-72669 7.6 Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tamp ! CVE-2026-72658 7.3 Cross-Site Request Forgery in Kibana Leading to Privilege Escalation ! CVE-2026-72677 7.3 Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Othe ! CVE-2026-78590 7.3 Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori ! CVE-2026-78592 7.3 Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori ! CVE-2026-49095 7.2 Improper Input Validation in Kibana Fleet Leading to Privilege Escalation ! CVE-2026-56147 7.1 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Informa ! CVE-2026-72629 7.1 Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access t ! CVE-2026-72630 7.1 Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation ! CVE-2026-72632 7.1 Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearc ! CVE-2026-72675 7.1 Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclo ! CVE-2026-72666 6.8 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query E ! CVE-2026-26934 6.5 Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of Service ! CVE-2026-26935 6.5 Improper Input Validation in Kibana Leading to Denial of Service ! CVE-2026-26937 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-26939 6.5 Missing Authorization in Kibana Leading to Unauthorized Endpoint Response Action Configura ! CVE-2026-26940 6.5 Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of Service ! CVE-2026-33459 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-33464 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-33465 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-42399 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-42400 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-49087 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-49089 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-56151 6.5 Improper Input Validation in Kibana Leading to Denial of Service ! CVE-2026-63260 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-63261 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-72628 6.5 Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service ! CVE-2026-72631 6.5 Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Key ! CVE-2026-72644 6.5 Uncaught Exception in Kibana Leading to Denial of Service ! CVE-2026-72651 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72652 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72653 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72654 6.5 Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure ! CVE-2026-72659 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72660 6.5 Uncaught Exception in Kibana Leading to Denial of Service ! CVE-2026-72661 6.5 Missing Authorization in Kibana Leading to Information Disclosure ! CVE-2026-72663 6.5 Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service ! CVE-2026-72664 6.5 Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Act ! CVE-2026-72667 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72676 6.5 Improper Control of Generation of Code in Fleet Server Leading to Code Injection ! CVE-2026-78586 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-78599 6.5 Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources ! CVE-2026-78608 6.5 Missing Authorization in Kibana Leading to Information Disclosure ! CVE-2026-82299 6.5 Incorrect Authorization in Kibana Leading to Information Disclosure ! CVE-2026-78591 6.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana L ! CVE-2026-72673 5.4 Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private L ! CVE-2026-78598 5.4 Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine ! CVE-2026-33463 5.3 Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized ! CVE-2026-63142 5.0 Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery ! CVE-2026-26936 4.9 Inefficient Regular Expression Complexity in Kibana Leading to Denial of Service ! CVE-2026-33462 4.6 Path Traversal in Kibana Leading to Unauthorized Deletion of User Accounts ! CVE-2026-33460 4.3 Incorrect Authorization in Kibana Fleet Leading to Information Disclosure ! CVE-2026-49096 4.3 Uncaught Exception in Kibana Cases Leading to Denial of Service ! CVE-2026-63145 4.3 Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromi ! CVE-2026-72633 4.3 Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitorin ! CVE-2026-72650 4.3 Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosu ! CVE-2026-72655 4.3 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana L ! CVE-2026-72671 4.3 Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning T ! CVE-2026-78593 4.3 Improper Control of Generation of Code in Kibana Leading to Privilege Escalation ! CVE-2026-78595 4.3 Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure ! CVE-2026-78596 4.3 Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations ! CVE-2026-78597 4.3 Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation ! CVE-2026-78603 4.3 Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Met ! CVE-2026-82293 4.3 Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption ! CVE-2026-82298 4.3 Incorrect Authorization in Kibana Leading to Denial of Service ! CVE-2026-42401 4.1 Improper Neutralization of Input During Web Page Generation in Kibana Leading to Stored HT textproc/kibana92 kibana92-9.2.8 ! CVE-2026-72665 8.1 Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions ! CVE-2026-78583 8.1 Incorrect Authorization in Kibana Leading to Privilege Escalation ! CVE-2026-82302 8.1 Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification ! CVE-2026-72670 7.7 Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure ! CVE-2026-72672 7.7 Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event D ! CVE-2026-72669 7.6 Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tamp ! CVE-2026-72658 7.3 Cross-Site Request Forgery in Kibana Leading to Privilege Escalation ! CVE-2026-72677 7.3 Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Othe ! CVE-2026-78590 7.3 Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori ! CVE-2026-78592 7.3 Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori ! CVE-2026-49095 7.2 Improper Input Validation in Kibana Fleet Leading to Privilege Escalation ! CVE-2026-56147 7.1 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Informa ! CVE-2026-72629 7.1 Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access t ! CVE-2026-72630 7.1 Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation ! CVE-2026-72632 7.1 Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearc ! CVE-2026-72675 7.1 Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclo ! CVE-2026-72666 6.8 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query E ! CVE-2026-33464 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-33465 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-42399 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-42400 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-49087 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-49089 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-56151 6.5 Improper Input Validation in Kibana Leading to Denial of Service ! CVE-2026-63260 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-63261 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-72628 6.5 Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service ! CVE-2026-72631 6.5 Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Key ! CVE-2026-72644 6.5 Uncaught Exception in Kibana Leading to Denial of Service ! CVE-2026-72651 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72652 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72653 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72654 6.5 Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure ! CVE-2026-72659 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72660 6.5 Uncaught Exception in Kibana Leading to Denial of Service ! CVE-2026-72661 6.5 Missing Authorization in Kibana Leading to Information Disclosure ! CVE-2026-72663 6.5 Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service ! CVE-2026-72664 6.5 Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Act ! CVE-2026-72667 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72676 6.5 Improper Control of Generation of Code in Fleet Server Leading to Code Injection ! CVE-2026-72680 6.5 Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unauth ! CVE-2026-78586 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-78599 6.5 Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources ! CVE-2026-78608 6.5 Missing Authorization in Kibana Leading to Information Disclosure ! CVE-2026-82299 6.5 Incorrect Authorization in Kibana Leading to Information Disclosure ! CVE-2026-78591 6.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana L ! CVE-2026-72673 5.4 Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private L ! CVE-2026-78598 5.4 Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine ! CVE-2026-33463 5.3 Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized ! CVE-2026-63142 5.0 Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery ! CVE-2026-33462 4.6 Path Traversal in Kibana Leading to Unauthorized Deletion of User Accounts ! CVE-2026-49096 4.3 Uncaught Exception in Kibana Cases Leading to Denial of Service ! CVE-2026-63145 4.3 Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromi ! CVE-2026-72633 4.3 Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitorin ! CVE-2026-72650 4.3 Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosu ! CVE-2026-72655 4.3 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana L ! CVE-2026-72671 4.3 Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning T ! CVE-2026-78593 4.3 Improper Control of Generation of Code in Kibana Leading to Privilege Escalation ! CVE-2026-78595 4.3 Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure ! CVE-2026-78596 4.3 Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations ! CVE-2026-78597 4.3 Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation ! CVE-2026-78603 4.3 Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Met ! CVE-2026-82293 4.3 Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption ! CVE-2026-82298 4.3 Incorrect Authorization in Kibana Leading to Denial of Service ! CVE-2026-42401 4.1 Improper Neutralization of Input During Web Page Generation in Kibana Leading to Stored HT textproc/kibana93 kibana93-9.3.4 ! CVE-2026-63137 8.3 Incorrect Authorization in Kibana Leading to Privilege Escalation ! CVE-2026-72665 8.1 Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions ! CVE-2026-78583 8.1 Incorrect Authorization in Kibana Leading to Privilege Escalation ! CVE-2026-82302 8.1 Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification ! CVE-2026-72670 7.7 Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure ! CVE-2026-72672 7.7 Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event D ! CVE-2026-72669 7.6 Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tamp ! CVE-2026-72658 7.3 Cross-Site Request Forgery in Kibana Leading to Privilege Escalation ! CVE-2026-72677 7.3 Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Othe ! CVE-2026-78590 7.3 Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori ! CVE-2026-78592 7.3 Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori ! CVE-2026-49095 7.2 Improper Input Validation in Kibana Fleet Leading to Privilege Escalation ! CVE-2026-56147 7.1 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Informa ! CVE-2026-72629 7.1 Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access t ! CVE-2026-72630 7.1 Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation ! CVE-2026-72632 7.1 Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearc ! CVE-2026-72675 7.1 Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclo ! CVE-2026-72666 6.8 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query E ! CVE-2026-33464 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-42397 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-42399 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-42400 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-49089 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-56151 6.5 Improper Input Validation in Kibana Leading to Denial of Service ! CVE-2026-63139 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-63260 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-63261 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-72628 6.5 Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service ! CVE-2026-72631 6.5 Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Key ! CVE-2026-72644 6.5 Uncaught Exception in Kibana Leading to Denial of Service ! CVE-2026-72651 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72652 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72653 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72654 6.5 Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure ! CVE-2026-72659 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72660 6.5 Uncaught Exception in Kibana Leading to Denial of Service ! CVE-2026-72661 6.5 Missing Authorization in Kibana Leading to Information Disclosure ! CVE-2026-72663 6.5 Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service ! CVE-2026-72664 6.5 Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Act ! CVE-2026-72667 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72674 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72676 6.5 Improper Control of Generation of Code in Fleet Server Leading to Code Injection ! CVE-2026-72680 6.5 Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unauth ! CVE-2026-72682 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-78586 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-78599 6.5 Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources ! CVE-2026-78608 6.5 Missing Authorization in Kibana Leading to Information Disclosure ! CVE-2026-82299 6.5 Incorrect Authorization in Kibana Leading to Information Disclosure ! CVE-2026-63141 6.3 Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management ! CVE-2026-78591 6.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana L ! CVE-2026-72673 5.4 Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private L ! CVE-2026-78598 5.4 Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine ! CVE-2026-33463 5.3 Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized ! CVE-2026-63142 5.0 Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery ! CVE-2026-33462 4.6 Path Traversal in Kibana Leading to Unauthorized Deletion of User Accounts ! CVE-2026-49096 4.3 Uncaught Exception in Kibana Cases Leading to Denial of Service ! CVE-2026-63143 4.3 Missing Authorization in Kibana Leading to Unauthorized Information Disclosure ! CVE-2026-63145 4.3 Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromi ! CVE-2026-72633 4.3 Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitorin ! CVE-2026-72650 4.3 Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosu ! CVE-2026-72655 4.3 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana L ! CVE-2026-72671 4.3 Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning T ! CVE-2026-78593 4.3 Improper Control of Generation of Code in Kibana Leading to Privilege Escalation ! CVE-2026-78595 4.3 Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure ! CVE-2026-78596 4.3 Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations ! CVE-2026-78597 4.3 Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation ! CVE-2026-78603 4.3 Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Met ! CVE-2026-82293 4.3 Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption ! CVE-2026-82298 4.3 Incorrect Authorization in Kibana Leading to Denial of Service ! CVE-2026-78606 4.2 Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and De ! CVE-2026-42401 4.1 Improper Neutralization of Input During Web Page Generation in Kibana Leading to Stored HT textproc/kibana94 kibana94-9.4.1 ! CVE-2026-63137 8.3 Incorrect Authorization in Kibana Leading to Privilege Escalation ! CVE-2026-72665 8.1 Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions ! CVE-2026-78583 8.1 Incorrect Authorization in Kibana Leading to Privilege Escalation ! CVE-2026-82302 8.1 Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification ! CVE-2026-72670 7.7 Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure ! CVE-2026-72672 7.7 Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event D ! CVE-2026-72669 7.6 Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tamp ! CVE-2026-72658 7.3 Cross-Site Request Forgery in Kibana Leading to Privilege Escalation ! CVE-2026-72677 7.3 Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Othe ! CVE-2026-78590 7.3 Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori ! CVE-2026-78592 7.3 Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori ! CVE-2026-49095 7.2 Improper Input Validation in Kibana Fleet Leading to Privilege Escalation ! CVE-2026-56147 7.1 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Informa ! CVE-2026-72629 7.1 Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access t ! CVE-2026-72630 7.1 Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation ! CVE-2026-72632 7.1 Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearc ! CVE-2026-72643 7.1 Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Pri ! CVE-2026-72675 7.1 Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclo ! CVE-2026-72666 6.8 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query E ! CVE-2026-42397 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-42400 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-49089 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-56151 6.5 Improper Input Validation in Kibana Leading to Denial of Service ! CVE-2026-63138 6.5 Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Infor ! CVE-2026-63139 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-63260 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-63261 6.5 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service ! CVE-2026-72628 6.5 Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service ! CVE-2026-72631 6.5 Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Key ! CVE-2026-72644 6.5 Uncaught Exception in Kibana Leading to Denial of Service ! CVE-2026-72651 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72653 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72654 6.5 Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure ! CVE-2026-72659 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72660 6.5 Uncaught Exception in Kibana Leading to Denial of Service ! CVE-2026-72661 6.5 Missing Authorization in Kibana Leading to Information Disclosure ! CVE-2026-72663 6.5 Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service ! CVE-2026-72664 6.5 Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Act ! CVE-2026-72667 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72674 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-72676 6.5 Improper Control of Generation of Code in Fleet Server Leading to Code Injection ! CVE-2026-72680 6.5 Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unauth ! CVE-2026-72681 6.5 Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure ! CVE-2026-72682 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-78586 6.5 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic ! CVE-2026-78599 6.5 Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources ! CVE-2026-78608 6.5 Missing Authorization in Kibana Leading to Information Disclosure ! CVE-2026-82299 6.5 Incorrect Authorization in Kibana Leading to Information Disclosure ! CVE-2026-63141 6.3 Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management ! CVE-2026-78591 6.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana L ! CVE-2026-78601 5.5 Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure ! CVE-2026-56146 5.4 Improper Access Control in Kibana Leading to Unauthorized Data Modification and Informatio ! CVE-2026-72641 5.4 Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data ! CVE-2026-72673 5.4 Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private L ! CVE-2026-78598 5.4 Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine ! CVE-2026-63142 5.0 Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery ! CVE-2026-49092 4.3 Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Inf ! CVE-2026-49096 4.3 Uncaught Exception in Kibana Cases Leading to Denial of Service ! CVE-2026-63143 4.3 Missing Authorization in Kibana Leading to Unauthorized Information Disclosure ! CVE-2026-63145 4.3 Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromi ! CVE-2026-63259 4.3 Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosu ! CVE-2026-63262 4.3 Missing Authorization in Kibana Leading to Information Disclosure ! CVE-2026-72633 4.3 Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitorin ! CVE-2026-72650 4.3 Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosu ! CVE-2026-72655 4.3 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana L ! CVE-2026-72671 4.3 Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning T ! CVE-2026-78584 4.3 Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure ! CVE-2026-78593 4.3 Improper Control of Generation of Code in Kibana Leading to Privilege Escalation ! CVE-2026-78595 4.3 Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure ! CVE-2026-78596 4.3 Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations ! CVE-2026-78597 4.3 Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation ! CVE-2026-78603 4.3 Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Met ! CVE-2026-82293 4.3 Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption ! CVE-2026-82298 4.3 Incorrect Authorization in Kibana Leading to Denial of Service ! CVE-2026-78606 4.2 Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and De textproc/libcroco libcroco-0.6.13_3 ! CVE-2020-12825 7.1 libcroco: Stack overflow in function cr_parser_parse_any_core in cr-parser.c textproc/linux-c7-aspell linux-c7-aspell-0.60.6.1_1 ! CVE-2019-17544 9.1 aspell: stack-based buffer over-read in acommon::unescape in common/getdata.cpp ! CVE-2019-20433 9.1 aspell: UCS-2 and UCS-4 null-terminated string handling OOB read textproc/linux-c7-expat linux-c7-expat-2.1.0_5 ! CVE-2016-0718 9.8 expat: Out-of-bounds heap read on crafted input causing crash ! CVE-2022-22822 9.8 expat: Integer overflow in addBinding in xmlparse.c ! CVE-2022-22823 9.8 expat: Integer overflow in build_model in xmlparse.c ! CVE-2022-22824 9.8 expat: Integer overflow in defineAttribute in xmlparse.c ! CVE-2022-23852 9.8 expat: Integer overflow in function XML_GetBuffer ! CVE-2022-25235 9.8 expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution ! CVE-2022-25236 9.8 expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arb ! CVE-2022-25315 9.8 expat: Integer overflow in storeRawNames() ! CVE-2024-45490 9.8 libexpat: Negative Length Parsing Vulnerability in libexpat ! CVE-2021-45960 8.8 expat: Large number of prefixed XML attributes on a single tag can crash libexpat ! CVE-2022-22825 8.8 expat: Integer overflow in lookup in xmlparse.c ! CVE-2022-22826 8.8 expat: Integer overflow in nextScaffoldPart in xmlparse.c ! CVE-2022-22827 8.8 expat: Integer overflow in storeAtts in xmlparse.c ! CVE-2026-66046 8.7 Expat Denial of Service via storeAtts() Quadratic Complexity ! CVE-2016-4472 8.1 expat: Undefined behavior and pointer overflows ! CVE-2021-46143 8.1 expat: Integer overflow in doProlog in xmlparse.c ! CVE-2022-40674 8.1 expat: a use-after-free in the doContent function in xmlparse.c ! CVE-2016-5300 7.5 expat: Little entropy used for hash initialization ! CVE-2017-9233 7.5 expat: Inifinite loop due to invalid XML in external entity ! CVE-2018-20843 7.5 expat: large number of colons in input makes parser consume high amount of resources, lead ! CVE-2022-23990 7.5 expat: integer overflow in the doProlog function ! CVE-2022-25314 7.5 expat: Integer overflow in copyString() ! CVE-2022-43680 7.5 expat: use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntit ! CVE-2023-52425 7.5 expat: parsing large tokens can trigger a denial of service ! CVE-2024-28757 7.5 expat: XML Entity Expansion ! CVE-2025-59375 7.5 expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via ! CVE-2024-45491 7.3 libexpat: Integer Overflow or Wraparound ! CVE-2024-45492 7.3 libexpat: integer overflow ! CVE-2026-25210 6.9 libexpat: libexpat: Information disclosure and data integrity issues due to integer overfl ! CVE-2026-56132 6.9 expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow ! CVE-2026-56403 6.9 libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts ! CVE-2026-56404 6.9 libexpat before 2.8.2 has an integer overflow in addBinding. ! CVE-2026-56405 6.9 libexpat: libexpat: Information disclosure and arbitrary code execution via integer overfl ! CVE-2026-56406 6.9 libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer ! CVE-2026-56407 6.9 Integer Overflow in libexpat XML Parser ! CVE-2026-56408 6.9 Integer Overflow in libexpat copyString Function ! CVE-2026-56410 6.9 libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbit ! CVE-2026-56411 6.9 expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code ! CVE-2013-0340 6.8 expat: internal entity expansion ! CVE-2015-1283 6.8 chromium-browser: Heap-buffer-overflow in expat. ! CVE-2019-15903 6.5 expat: heap-based buffer over-read via crafted XML input ! CVE-2022-25313 6.5 expat: Stack exhaustion in doctype parsing ! CVE-2026-56409 6.5 Integer Overflow in libexpat xmlwf Output File Handling ! CVE-2026-72522 6.2 expat: libexpat: Denial of Service due to incorrect Unicode surrogate handling ! CVE-2012-6702 5.9 expat: Using XML_Parse before rand() results into non-random output ! CVE-2024-50602 5.9 libexpat: expat: DoS via XML_ResumeParser ! CVE-2023-52426 5.5 expat: recursive XML entity expansion vulnerability ! CVE-2026-50219 4.9 expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking ! CVE-2026-56131 4.9 Use-After-Free in libexpat's XML_ResumeParser Call Depth Tracking ! CVE-2026-56412 4.9 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sec ! CVE-2026-76957 4.9 libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or den ! CVE-2026-32776 4.0 libexpat: libexpat: Denial of Service due to NULL pointer dereference ! CVE-2026-32777 4.0 libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing ! CVE-2025-66382 2.9 libexpat: libexpat: Denial of service via crafted file processing ! CVE-2026-24515 2.9 libexpat: libexpat null pointer dereference ! CVE-2026-32778 2.9 libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory con ! CVE-2026-41080 2.9 libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML ! CVE-2026-45186 2.9 libexpat: denial of service via crafted XML input textproc/linux-c7-expat-devel linux-c7-expat-devel-2.1.0_1 ! CVE-2016-0718 9.8 expat: Out-of-bounds heap read on crafted input causing crash ! CVE-2022-22822 9.8 expat: Integer overflow in addBinding in xmlparse.c ! CVE-2022-22823 9.8 expat: Integer overflow in build_model in xmlparse.c ! CVE-2022-22824 9.8 expat: Integer overflow in defineAttribute in xmlparse.c ! CVE-2022-23852 9.8 expat: Integer overflow in function XML_GetBuffer ! CVE-2022-25235 9.8 expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution ! CVE-2022-25236 9.8 expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arb ! CVE-2022-25315 9.8 expat: Integer overflow in storeRawNames() ! CVE-2024-45490 9.8 libexpat: Negative Length Parsing Vulnerability in libexpat ! CVE-2021-45960 8.8 expat: Large number of prefixed XML attributes on a single tag can crash libexpat ! CVE-2022-22825 8.8 expat: Integer overflow in lookup in xmlparse.c ! CVE-2022-22826 8.8 expat: Integer overflow in nextScaffoldPart in xmlparse.c ! CVE-2022-22827 8.8 expat: Integer overflow in storeAtts in xmlparse.c ! CVE-2026-66046 8.7 Expat Denial of Service via storeAtts() Quadratic Complexity ! CVE-2016-4472 8.1 expat: Undefined behavior and pointer overflows ! CVE-2021-46143 8.1 expat: Integer overflow in doProlog in xmlparse.c ! CVE-2022-40674 8.1 expat: a use-after-free in the doContent function in xmlparse.c ! CVE-2016-5300 7.5 expat: Little entropy used for hash initialization ! CVE-2017-9233 7.5 expat: Inifinite loop due to invalid XML in external entity ! CVE-2018-20843 7.5 expat: large number of colons in input makes parser consume high amount of resources, lead ! CVE-2022-23990 7.5 expat: integer overflow in the doProlog function ! CVE-2022-25314 7.5 expat: Integer overflow in copyString() ! CVE-2022-43680 7.5 expat: use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntit ! CVE-2023-52425 7.5 expat: parsing large tokens can trigger a denial of service ! CVE-2024-28757 7.5 expat: XML Entity Expansion ! CVE-2025-59375 7.5 expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via ! CVE-2024-45491 7.3 libexpat: Integer Overflow or Wraparound ! CVE-2024-45492 7.3 libexpat: integer overflow ! CVE-2026-25210 6.9 libexpat: libexpat: Information disclosure and data integrity issues due to integer overfl ! CVE-2026-56132 6.9 expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow ! CVE-2026-56403 6.9 libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts ! CVE-2026-56404 6.9 libexpat before 2.8.2 has an integer overflow in addBinding. ! CVE-2026-56405 6.9 libexpat: libexpat: Information disclosure and arbitrary code execution via integer overfl ! CVE-2026-56406 6.9 libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer ! CVE-2026-56407 6.9 Integer Overflow in libexpat XML Parser ! CVE-2026-56408 6.9 Integer Overflow in libexpat copyString Function ! CVE-2026-56410 6.9 libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbit ! CVE-2026-56411 6.9 expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code ! CVE-2013-0340 6.8 expat: internal entity expansion ! CVE-2015-1283 6.8 chromium-browser: Heap-buffer-overflow in expat. ! CVE-2019-15903 6.5 expat: heap-based buffer over-read via crafted XML input ! CVE-2022-25313 6.5 expat: Stack exhaustion in doctype parsing ! CVE-2026-56409 6.5 Integer Overflow in libexpat xmlwf Output File Handling ! CVE-2026-72522 6.2 expat: libexpat: Denial of Service due to incorrect Unicode surrogate handling ! CVE-2012-6702 5.9 expat: Using XML_Parse before rand() results into non-random output ! CVE-2024-50602 5.9 libexpat: expat: DoS via XML_ResumeParser ! CVE-2023-52426 5.5 expat: recursive XML entity expansion vulnerability ! CVE-2026-50219 4.9 expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking ! CVE-2026-56131 4.9 Use-After-Free in libexpat's XML_ResumeParser Call Depth Tracking ! CVE-2026-56412 4.9 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sec ! CVE-2026-76957 4.9 libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or den ! CVE-2026-32776 4.0 libexpat: libexpat: Denial of Service due to NULL pointer dereference ! CVE-2026-32777 4.0 libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing ! CVE-2025-66382 2.9 libexpat: libexpat: Denial of service via crafted file processing ! CVE-2026-24515 2.9 libexpat: libexpat null pointer dereference ! CVE-2026-32778 2.9 libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory con ! CVE-2026-41080 2.9 libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML ! CVE-2026-45186 2.9 libexpat: denial of service via crafted XML input textproc/linux-c7-libcroco linux-c7-libcroco-0.6.12_1 ! CVE-2020-12825 7.1 libcroco: Stack overflow in function cr_parser_parse_any_core in cr-parser.c ! CVE-2017-8834 6.5 libcroco: Memory allocation failure in the cr_tknzr_parse_comment function ! CVE-2017-8871 6.5 libcroco: Infinite loop in the cr_parser_parse_selector_core function ! CVE-2017-7960 5.5 libcroco: Out-of-bounds read due to missing index check in cr-input.c textproc/linux-c7-libxml2 linux-c7-libxml2-2.9.1_4 ! CVE-2015-8710 9.8 libxml2: out-of-bounds memory access when parsing an unclosed HTML comment ! CVE-2016-4448 9.8 libxml2: Format string vulnerability ! CVE-2016-4658 9.8 libxml2: Use after free via namespace node in XPointer ranges ! CVE-2017-16931 9.8 libxml2: Mishandling parameter-entity references ! CVE-2017-7375 9.8 libxml2: Missing validation for external entities in xmlParsePEReference ! CVE-2017-7376 9.8 libxml2: Incorrect limit used for port values ! CVE-2016-5131 8.8 libxml2: Use after free triggered by XPointer paths beginning with range-to ! CVE-2017-15412 8.8 libxml2: Use after free in xmlXPathCompOpEvalPositionalPredicate() function in xpath.c ! CVE-2017-5130 8.8 chromium-browser: heap overflow in libxml2 ! CVE-2021-3518 8.8 libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c ! CVE-2021-3517 8.6 libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c ! CVE-2016-1762 8.1 libxml2: Heap-based buffer-overread in xmlNextChar ! CVE-2022-49043 8.1 libxml: use-after-free in xmlXIncludeAddNode ! CVE-2026-86140 8.0 libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfE ! CVE-2016-1834 7.8 libxml2: Heap-buffer-overflow in xmlStrncat ! CVE-2016-1840 7.8 libxml2: Heap-buffer-overflow in xmlFAParserPosCharGroup ! CVE-2022-40304 7.8 libxml2: dict corruption caused by entity reference cycles ! CVE-2024-56171 7.8 libxml2: Use-After-Free in libxml2 ! CVE-2025-24928 7.8 libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2 ! CVE-2015-6837 7.5 php: NULL pointer dereference in XSLTProcessor class ! CVE-2015-6838 7.5 php: NULL pointer dereference in XSLTProcessor class ! CVE-2015-8806 7.5 libxml2: heap-buffer overread in dict.c ! CVE-2016-3627 7.5 libxml2: stack exhaustion while parsing xml files in recovery mode ! CVE-2016-4447 7.5 libxml2: Heap-based buffer underreads due to xmlParseName ! CVE-2016-4483 7.5 libxml2: out-of-bounds read ! CVE-2017-16932 7.5 libxml2: Infinite recursion in parameter entities ! CVE-2019-19956 7.5 libxml2: memory leak in xmlParseBalancedChunkMemoryRecover in parser.c ! CVE-2022-23308 7.5 libxml2: Use-after-free of ID and IDREF attributes ! CVE-2022-40303 7.5 libxml2: integer overflows with XML_PARSE_HUGE ! CVE-2024-25062 7.5 libxml2: use-after-free in XMLReader ! CVE-2024-34459 7.5 libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c ! CVE-2025-6021 7.5 Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2 ! CVE-2015-5312 7.1 libxml2: CPU exhaustion when processing specially crafted XML input ! CVE-2016-4449 7.1 libxml2: Inappropriate fetch of entities content ! CVE-2026-86138 6.9 libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow ! CVE-2026-86139 6.9 libxml2: libxml2: Integer overflow in xmlURIEscapeStr may lead to arbitrary code execution ! CVE-2026-86142 6.9 libxml2: libxml2: Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturat ! CVE-2026-86143 6.9 libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks ! CVE-2013-0339 6.8 libxml2: CPU consumption DoS and other effects when performing string substitutions during ! CVE-2016-2073 6.5 libxml2: out-of-bounds read in htmlParseNameComplex() ! CVE-2016-9596 6.5 libxml2: stack exhaustion while parsing xml files in recovery mode (unfixed CVE-2016-3627 ! CVE-2016-9598 6.5 libxml2: out-of-bounds read (unfixed CVE-2016-4483 in JBCS) ! CVE-2017-18258 6.5 libxml2: Unrestricted memory usage in xz_head() function in xzlib.c ! CVE-2018-14404 6.5 libxml2: NULL pointer dereference in xmlXPathCompOpEval() function in xpath.c ! CVE-2021-3541 6.5 libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms ! CVE-2022-29824 6.5 libxml2: integer overflows in xmlBuf and xmlBuffer lead to out-of-bounds write ! CVE-2023-28484 6.5 libxml2: NULL dereference in xmlSchemaFixupComplexType ! CVE-2023-29469 6.5 libxml2: Hashing of empty dict strings isn't deterministic ! CVE-2015-8241 6.4 libxml2: Buffer overread with XML parser in xmlNextChar ! CVE-2025-9714 6.2 Stack overflow in libxml2 ! CVE-2016-3709 6.1 libxml2: Incorrect server side include parsing can lead to XSS ! CVE-2021-3537 5.9 libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mo ! CVE-2026-0990 5.9 Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing ! CVE-2015-8242 5.8 libxml2: Buffer overread with HTML parser in push mode in xmlSAX2TextNode ! CVE-2025-32414 5.6 libxml2: Out-of-Bounds Read in libxml2 ! CVE-2026-86144 5.6 libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parse ! CVE-2016-1833 5.5 libxml2: Heap-based buffer overread in htmlCurrentChar ! CVE-2016-1836 5.5 libxml2: Heap use-after-free in xmlDictComputeFastKey ! CVE-2016-1837 5.5 libxml2: Heap use-after-free in htmlPArsePubidLiteral and htmlParseSystemiteral ! CVE-2016-1838 5.5 libxml2: Heap-based buffer overread in xmlPArserPrintFileContextInternal ! CVE-2016-1839 5.5 libxml2: Heap-based buffer overread in xmlDictAddString ! CVE-2016-9318 5.5 libxml2: XML External Entity vulnerability ! CVE-2014-3660 5.0 libxml2: denial of service via recursive entity expansion ! CVE-2015-7497 5.0 libxml2: Heap-based buffer overflow in xmlDictComputeFastQKey ! CVE-2015-7498 5.0 libxml2: Heap-based buffer overflow in xmlParseXmlDecl ! CVE-2015-7499 5.0 libxml2: Heap-based buffer overflow in xmlGROW ! CVE-2015-7500 5.0 libxml2: Heap buffer overflow in xmlParseMisc ! CVE-2015-8317 5.0 libxml2: Out-of-bounds heap read when parsing file with unfinished xml declaration ! CVE-2026-0989 3.7 Libxml2: unbounded relaxng include recursion leading to stack overflow ! CVE-2025-27113 2.9 libxml2: NULL Pointer Dereference in libxml2 xmlPatMatch ! CVE-2025-32415 2.9 libxml2: Out-of-bounds Read in xmlSchemaIDCFillNodeTables ! CVE-2026-0992 2.9 Libxml2: libxml2: denial of service via crafted xml catalogs ! CVE-2026-86137 2.9 libxml2: libxml2: Denial of Service via out-of-bounds read in xmlFAParsePosCharGroup ! CVE-2026-86141 2.9 libxml2: libxml2: Denial of Service due to NULL pointer dereference in xmlRegNewParserCtxt ! CVE-2015-8035 2.6 libxml2: DoS caused by incorrect error detection during XZ decompression ! CVE-2025-6170 2.5 Libxml2: stack buffer overflow in xmllint interactive shell command handling textproc/linux-c7-libxslt linux-c7-libxslt-1.1.28_1 ! CVE-2016-4607 9.8 libxslt: allows remote attacker to cause denial of service ! CVE-2016-4609 9.8 libxslt: Out-of-bounds read at xmlGetLineNoInternal() ! CVE-2019-11068 9.8 libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL ! CVE-2021-30560 8.8 Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote atta ! CVE-2024-55549 7.8 libxslt: Use-After-Free in libxslt (xsltGetInheritedNsList) ! CVE-2025-24855 7.8 libxslt: Use-After-Free in libxslt numbers.c ! CVE-2016-1683 7.5 chromium-browser: out-of-bounds access in libxslt ! CVE-2016-1684 7.5 chromium-browser: integer overflow in libxslt ! CVE-2019-5815 7.5 chromium-browser: Heap buffer overflow in Blink ! CVE-2025-7424 7.5 Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes ! CVE-2022-29824 6.5 libxml2: integer overflows in xmlBuf and xmlBuffer lead to out-of-bounds write ! CVE-2015-9019 5.3 libxslt: math.random() in xslt uses unseeded randomness ! CVE-2015-7995 5.0 libxslt: Type confusion may cause DoS textproc/linux-rl9-expat linux-rl9-expat-2.5.0_8 ! CVE-2024-45490 9.8 libexpat: Negative Length Parsing Vulnerability in libexpat ! CVE-2026-66046 8.7 Expat Denial of Service via storeAtts() Quadratic Complexity ! CVE-2023-52425 7.5 expat: parsing large tokens can trigger a denial of service ! CVE-2024-28757 7.5 expat: XML Entity Expansion ! CVE-2025-59375 7.5 expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via ! CVE-2024-45491 7.3 libexpat: Integer Overflow or Wraparound ! CVE-2024-45492 7.3 libexpat: integer overflow ! CVE-2026-25210 6.9 libexpat: libexpat: Information disclosure and data integrity issues due to integer overfl ! CVE-2026-56132 6.9 expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow ! CVE-2026-56403 6.9 libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts ! CVE-2026-56404 6.9 libexpat before 2.8.2 has an integer overflow in addBinding. ! CVE-2026-56405 6.9 libexpat: libexpat: Information disclosure and arbitrary code execution via integer overfl ! CVE-2026-56406 6.9 libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer ! CVE-2026-56407 6.9 Integer Overflow in libexpat XML Parser ! CVE-2026-56408 6.9 Integer Overflow in libexpat copyString Function ! CVE-2026-56410 6.9 libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbit ! CVE-2026-56411 6.9 expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code ! CVE-2026-56409 6.5 Integer Overflow in libexpat xmlwf Output File Handling ! CVE-2026-72522 6.2 expat: libexpat: Denial of Service due to incorrect Unicode surrogate handling ! CVE-2024-50602 5.9 libexpat: expat: DoS via XML_ResumeParser ! CVE-2023-52426 5.5 expat: recursive XML entity expansion vulnerability ! CVE-2026-50219 4.9 expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking ! CVE-2026-56131 4.9 Use-After-Free in libexpat's XML_ResumeParser Call Depth Tracking ! CVE-2026-56412 4.9 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sec ! CVE-2026-76957 4.9 libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or den ! CVE-2026-32776 4.0 libexpat: libexpat: Denial of Service due to NULL pointer dereference ! CVE-2026-32777 4.0 libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing ! CVE-2025-66382 2.9 libexpat: libexpat: Denial of service via crafted file processing ! CVE-2026-24515 2.9 libexpat: libexpat null pointer dereference ! CVE-2026-32778 2.9 libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory con ! CVE-2026-41080 2.9 libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML ! CVE-2026-45186 2.9 libexpat: denial of service via crafted XML input textproc/linux-rl9-libxml2 linux-rl9-libxml2-2.9.13_9 ! CVE-2022-49043 8.1 libxml: use-after-free in xmlXIncludeAddNode ! CVE-2026-86140 8.0 libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfE ! CVE-2022-40304 7.8 libxml2: dict corruption caused by entity reference cycles ! CVE-2024-56171 7.8 libxml2: Use-After-Free in libxml2 ! CVE-2025-24928 7.8 libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2 ! CVE-2022-40303 7.5 libxml2: integer overflows with XML_PARSE_HUGE ! CVE-2024-25062 7.5 libxml2: use-after-free in XMLReader ! CVE-2024-34459 7.5 libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c ! CVE-2025-6021 7.5 Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2 ! CVE-2026-6653 7.0 libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling ! CVE-2026-86138 6.9 libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow ! CVE-2026-86139 6.9 libxml2: libxml2: Integer overflow in xmlURIEscapeStr may lead to arbitrary code execution ! CVE-2026-86142 6.9 libxml2: libxml2: Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturat ! CVE-2026-86143 6.9 libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks ! CVE-2022-29824 6.5 libxml2: integer overflows in xmlBuf and xmlBuffer lead to out-of-bounds write ! CVE-2023-28484 6.5 libxml2: NULL dereference in xmlSchemaFixupComplexType ! CVE-2023-29469 6.5 libxml2: Hashing of empty dict strings isn't deterministic ! CVE-2025-9714 6.2 Stack overflow in libxml2 ! CVE-2016-3709 6.1 libxml2: Incorrect server side include parsing can lead to XSS ! CVE-2026-0990 5.9 Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing ! CVE-2025-32414 5.6 libxml2: Out-of-Bounds Read in libxml2 ! CVE-2026-86144 5.6 libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parse ! CVE-2026-0989 3.7 Libxml2: unbounded relaxng include recursion leading to stack overflow ! CVE-2025-27113 2.9 libxml2: NULL Pointer Dereference in libxml2 xmlPatMatch ! CVE-2025-32415 2.9 libxml2: Out-of-bounds Read in xmlSchemaIDCFillNodeTables ! CVE-2026-0992 2.9 Libxml2: libxml2: denial of service via crafted xml catalogs ! CVE-2026-86137 2.9 libxml2: libxml2: Denial of Service via out-of-bounds read in xmlFAParsePosCharGroup ! CVE-2026-86141 2.9 libxml2: libxml2: Denial of Service due to NULL pointer dereference in xmlRegNewParserCtxt ! CVE-2025-6170 2.5 Libxml2: stack buffer overflow in xmllint interactive shell command handling textproc/linux-rl9-libxslt linux-rl9-libxslt-1.1.34_4 ! CVE-2021-30560 8.8 Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote atta ! CVE-2024-55549 7.8 libxslt: Use-After-Free in libxslt (xsltGetInheritedNsList) ! CVE-2025-24855 7.8 libxslt: Use-After-Free in libxslt numbers.c ! CVE-2025-7424 7.5 Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes ! CVE-2022-29824 6.5 libxml2: integer overflows in xmlBuf and xmlBuffer lead to out-of-bounds write textproc/opensearch13 opensearch13-1.3.10_2 ! CVE-2025-9624 8.3 OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS textproc/opensearch210 opensearch210-2.10.0_4 ! CVE-2026-83497 8.7 Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination ! CVE-2025-9624 8.3 OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS textproc/opensearch213 opensearch213-2.13.0_3 ! CVE-2026-83497 8.7 Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination ! CVE-2025-9624 8.3 OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS textproc/opensearch216 opensearch216-2.16.0_2 ! CVE-2026-83497 8.7 Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination ! CVE-2025-9624 8.3 OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS textproc/opensearch219 opensearch219-2.19.5 ! CVE-2026-83497 8.7 Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination textproc/py-elasticsearch py312-elasticsearch-9.5.0 ! CVE-2026-72642 8.8 Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference ! CVE-2026-72649 8.8 Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution ! CVE-2026-72639 6.5 Memory Allocation with Excessive Size Value in Elasticsearch Highlighting Leading to Denia ! CVE-2026-72645 6.5 Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service ! CVE-2026-72678 6.5 Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service ! CVE-2026-72686 6.5 Uncontrolled Recursion in Elasticsearch Leading to Denial of Service ! CVE-2026-72687 6.5 Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service ! CVE-2026-78605 5.9 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch L ! CVE-2026-78607 5.4 Missing Authorization in Elasticsearch Leading to Information Disclosure textproc/py-elasticsearch6 py312-elasticsearch6-6.8.2_2 ! CVE-2020-7009 8.8 elasticsearch: Generating API keys with specific steps could result in generating API key ! CVE-2020-7014 8.8 elasticsearch: Incomplete fix for CVE-2020-7009 could result in generating API key with el ! CVE-2020-7019 6.5 elasticsearch: scrolling search can leak fields that should be hidden allowing access rest ! CVE-2021-22144 6.5 elasticsearch: uncontrolled recursion in Grok parser ! CVE-2026-72683 6.5 Uncontrolled Recursion in Elasticsearch Leading to Denial of Service ! CVE-2023-46674 6.0 Elasticsearch-hadoop Unsafe Deserialization ! CVE-2019-7619 5.3 elasticsearch: Username disclosure in API Key service ! CVE-2021-22135 5.3 elasticsearch: Document disclosure flaw in the Elasticsearch suggester ! CVE-2021-22137 5.3 elasticsearch: Document disclosure flaw when Document or Field Level Security is used ! CVE-2020-7021 4.9 elasticsearch: Information disclosure via audit logging with emit_request_body option enab ! CVE-2020-7020 3.1 elasticsearch: not properly preserving security permissions when executing complex queries textproc/py-elasticsearch7 py312-elasticsearch7-7.17.13 ! CVE-2025-37731 6.8 Elasticsearch Improper Authentication ! CVE-2023-46673 6.5 elasticsearch: Improper Handling of Exceptional Conditions ! CVE-2024-43709 6.5 Elasticsearch allocation of resources without limits or throttling leads to crash ! CVE-2024-52979 6.5 Elasticsearch Uncontrolled Resource Consumption vulnerability ! CVE-2024-52980 6.5 Elasticsearch Uncontrolled Resource Consumption vulnerability ! CVE-2025-68384 6.5 Elasticsearch Allocation of Resources Without Limits or Throttling ! CVE-2026-49090 6.5 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service ! CVE-2026-72683 6.5 Uncontrolled Recursion in Elasticsearch Leading to Denial of Service ! CVE-2025-37727 5.7 Elasticsearch Insertion of sensitive information in log file ! CVE-2023-49921 5.2 elasticsearch: Insertion of Sensitive Information into Log File ! CVE-2024-23444 4.9 Elasticsearch elasticsearch-certutil csr fails to encrypt private key ! CVE-2024-23450 4.9 Elasticsearch Uncontrolled Resource Consumption vulnerability ! CVE-2024-52981 4.9 An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText ! CVE-2025-68390 4.9 Elasticsearch Allocation of Resources Without Limits or Throttling textproc/py-nltk py312-nltk-3.10.0,2 ! CVE-2026-79657 9.3 NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization ! CVE-2026-79675 9.3 NLTK before 3.10.3 JVM Argument Injection via Per-Call Options ! CVE-2026-79674 8.8 NLTK 3.10.2 Path Traversal via corpus-reader constructors ! CVE-2026-62384 8.7 NLTK FramenetCorpusReader Symlink Sandbox Bypass before 3.10.2 ! CVE-2026-71513 8.7 NLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name Bypass ! CVE-2026-72818 8.7 NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Input ! CVE-2026-78681 8.7 NLTK before 3.10.3 Entity Expansion DoS via ElementTree ! CVE-2026-78682 8.7 NLTK before 3.10.3 SSRF Protection Bypass via Proxy ! CVE-2026-81722 8.7 nltk PorterStemmer before 3.10.3 Quadratic-time DoS ! CVE-2026-78680 8.5 NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary ! CVE-2026-81726 8.3 NLTK through 3.10.3 Path Traversal via Model-Artifact APIs ! CVE-2026-79676 8.2 NLTK before 3.10.3 Path Traversal via Symlink Bypass ! CVE-2026-80206 8.2 NLTK 3.10.2 Regular Expression Denial of Service via tgrep ! CVE-2026-81724 6.9 NLTK before 3.10.3 Denial of Service via Uncontrolled Recursion ! CVE-2026-81727 6.9 NLTK before 3.10.3 Hardlink File Overwrite via downloader ! CVE-2026-62383 6.8 nltk IPIPANCorpusReader Symlink Arbitrary File Read ! CVE-2026-81723 6.3 NLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusView ! CVE-2026-81725 6.3 NLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReader ! CVE-2026-71514 2.0 NLTK 3.9.4 through 3.10.2 Path Traversal via CrubadanCorpusReader pathsec Bypass textproc/tinyxml tinyxml-2.6.2_4 ! CVE-2021-42260 7.5 TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp ! CVE-2023-34194 7.5 StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a textproc/unrtf unrtf-0.21.10_1 ! CVE-2025-65411 7.5 A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attack ! CVE-2025-65410 6.2 A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cau textproc/xalan-j xalan-j-2.7.2_2 ! CVE-2022-34169 7.5 Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processin www/adguardhome adguardhome-0.107.78_3 ! CVE-2022-32175 5.4 AdGuardHome - CSRF www/chromium chromium-152.0.7977.75_2 ! CVE-2026-87544 9.8 Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-85042 9.6 DevTools Use-After‑Free Allows Remote Code Execution ! CVE-2026-87448 9.6 Chrome DevTools Use-After‑Free Allows Remote Code Execution ! CVE-2026-87455 9.6 Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker t ! CVE-2026-87464 9.6 Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87474 9.6 Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87492 9.6 Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87500 9.6 Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowe ! CVE-2026-87504 9.6 Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker l ! CVE-2026-87526 9.6 Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87527 9.6 Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87529 9.6 Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87547 9.6 Chrome FileSystem Reference Resolution Vulnerability Enabling Arbitrary Code Execution ! CVE-2026-87581 9.6 Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87634 9.6 Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87638 9.6 Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote atta ! CVE-2026-87646 9.6 Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87650 9.6 Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-85043 9.1 Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote att ! CVE-2026-87613 9.0 Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allow ! CVE-2026-85046 8.8 KEV Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to ! CVE-2026-85049 8.8 chromium-browser: skia: chromium-browser: Use after free in Skia ! CVE-2026-85051 8.8 Type Confusion in Chrome Compositing Allows Remote Code Execution ! CVE-2026-85053 8.8 CacheStorage Resource Exposure Enables Remote Code Execution in Chrome ! CVE-2026-87430 8.8 Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87433 8.8 Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87440 8.8 Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87444 8.8 chromium-browser: chromium-browser: Memory corruption in Codecs ! CVE-2026-87460 8.8 chromium-browser: chromium-browser: Use after free in Platform ! CVE-2026-87489 8.8 Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87491 8.8 KEV V8 Out‑of‑Bounds Write Enables Remote Code Execution in Chrome ! CVE-2026-87536 8.8 Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to ! CVE-2026-87542 8.8 Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87569 8.8 Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87570 8.8 Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87579 8.8 Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87587 8.8 Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to ! CVE-2026-87588 8.8 chromium-browser: chromium-browser: Use after free in Chromecast ! CVE-2026-87612 8.8 chromium-browser: chromium-browser: Type confusion in V8 ! CVE-2026-87617 8.8 Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87625 8.8 Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker lev ! CVE-2026-87636 8.8 chromium-browser: chromium-browser: Type confusion in XML ! CVE-2026-87633 8.6 Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker t ! CVE-2026-85048 8.3 Use‑After‑Free in Chrome Compositing Enables Code Execution Outside Sandbox ! CVE-2026-87479 8.3 Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allo ! CVE-2026-87480 8.3 Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87487 8.3 Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87506 8.3 WebUI Privilege Escalation in Google Chrome via Renderer Process ! CVE-2026-87510 8.3 Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87553 8.3 Renderer Process Escalation via Improper SiteIsolation Input Validation in Chrome ! CVE-2026-87572 8.3 Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker wh ! CVE-2026-87578 8.3 Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent att ! CVE-2026-87582 8.3 Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87604 8.3 Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87628 8.3 Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacke ! CVE-2026-87639 8.3 Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87471 8.1 chromium-browser: chromium-browser: Incorrect authorization in ServiceWorker ! CVE-2026-87499 8.1 chromium-browser: chromium-browser: Incorrect authorization in Network ! CVE-2026-87505 8.1 Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-87514 8.1 Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker t ! CVE-2026-87533 8.1 Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacke ! CVE-2026-87537 8.1 Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-85045 7.5 V8 Race Condition Enabling Remote Code Execution in Chrome ! CVE-2026-87431 7.5 Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87450 7.5 Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a r ! CVE-2026-87601 7.5 Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to ! CVE-2026-87429 6.5 Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a r ! CVE-2026-87436 6.5 Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87437 6.5 Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87441 6.5 Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87443 6.5 chromium-browser: chromium-browser: Missing authorization in Actor ! CVE-2026-87446 6.5 Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87447 6.5 Chrome Network Authorization Bypass via Extension ! CVE-2026-87459 6.5 Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87475 6.5 chromium-browser: chromium-browser: Missing authorization in Omnibox ! CVE-2026-87476 6.5 chromium-browser: chromium-browser: Incorrect authorization in Loader ! CVE-2026-87477 6.5 Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87478 6.5 Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87490 6.5 Information leak in Transactions Platform in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87513 6.5 Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87515 6.5 Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87523 6.5 Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87532 6.5 Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87541 6.5 Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87549 6.5 Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87593 6.5 Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87620 6.5 Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87623 6.5 Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87629 6.5 Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87631 6.5 Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote atta ! CVE-2026-87445 5.4 UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87458 5.4 UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87462 5.4 UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87484 5.4 UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87496 5.4 UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87501 5.4 chromium-browser: chromium-browser: UI misrepresentation in Passwords ! CVE-2026-87507 5.4 UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87540 5.4 Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87567 5.4 UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-87571 5.4 Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87575 5.4 Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87599 5.4 Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87615 5.4 Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87635 5.4 chromium-browser: chromium-browser: UI misrepresentation in Payments ! CVE-2026-87645 5.4 chromium-browser: chromium-browser: Improper state validation in Safebrowsing ! CVE-2026-87649 5.4 UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87655 5.4 Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87656 5.4 Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87435 5.3 Information Leak via ControlledFrame in Google Chrome ! CVE-2026-87439 5.3 Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87453 5.3 Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87566 5.3 chromium-browser: chromium-browser: Observable discrepancy in Layout ! CVE-2026-87594 5.3 Incorrect authorization in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87605 5.3 Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87641 5.3 Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87568 4.8 Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-87449 4.3 Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153. ! CVE-2026-87461 4.3 Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87466 4.3 Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87495 4.3 Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87497 4.3 chromium-browser: chromium-browser: Uninitialized resource in Codecs ! CVE-2026-87508 4.3 Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87516 4.3 Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87543 4.3 Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87548 4.3 Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a r ! CVE-2026-87550 4.3 Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 all ! CVE-2026-87551 4.3 Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87556 4.3 Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87557 4.3 Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8010.36 allowe ! CVE-2026-87560 4.3 Chrome Browser Authorization Bypass via Crafted HTML Page ! CVE-2026-87561 4.3 Incorrect authorization in Web Authentication in Google Chrome prior to 153.0.8010.36 allo ! CVE-2026-87563 4.3 Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87564 4.3 chromium-browser: chromium-browser: Type confusion in V8 ! CVE-2026-87573 4.3 Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87574 4.3 chromium-browser: chromium-browser: Information leak in ServiceWorker ! CVE-2026-87577 4.3 Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87586 4.3 Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87592 4.3 Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87596 4.3 Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87598 4.3 chromium-browser: chromium-browser: Incorrect authorization in ServiceWorker ! CVE-2026-87619 4.3 chromium-browser: chromium-browser: Observable discrepancy in Prefetch ! CVE-2026-87622 4.3 Missing authorization in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87630 4.3 Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87632 4.3 Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87642 4.3 Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87651 4.3 Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87658 4.3 Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87432 4.2 Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-87465 4.2 chromium-browser: chromium-browser: Incorrect authorization in Downloads ! CVE-2026-87472 4.2 Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87502 4.2 Confused Deputy in Chrome Fullscreen Allows UI Spoofing via Compromised Renderer ! CVE-2026-87538 4.2 Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker wh ! CVE-2026-87559 4.2 UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87456 3.4 Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87647 3.4 Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-85052 3.1 Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a rem ! CVE-2026-87434 3.1 Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87442 3.1 Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote atta ! CVE-2026-87451 3.1 Information leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87485 3.1 Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87498 3.1 chromium-browser: chromium-browser: Missing authorization in WebUI ! CVE-2026-87521 3.1 Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87531 3.1 Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87539 3.1 Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87611 3.1 Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87614 3.1 Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87652 3.1 Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87657 3.1 chromium-browser: chromium-browser: Use after free in V8 www/civetweb civetweb-1.15 ! CVE-2025-9648 8.7 Denial of Service in CivetWeb ! CVE-2025-55763 7.5 Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote a www/ckeditor ckeditor-4.21.0 ! CVE-2024-24815 6.1 CKEditor4 Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detection ! CVE-2024-24816 6.1 Cross-site scripting (XSS) vulnerability in samples with enabled the preview feature ! CVE-2024-43407 6.1 Code Snippet GeSHi plugin has reflected cross-site scripting (XSS) vulnerability www/codeigniter codeigniter-3.1.13 ! CVE-2023-32692 9.8 Remote Code Execution Vulnerability in Validation Placeholders ! CVE-2020-10793 8.8 CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ! CVE-2023-46240 7.5 CodeIgniter4 vulnerable to information disclosure when detailed error report is displayed ! CVE-2024-41344 7.5 A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily ! CVE-2022-35943 5.9 SameSite may allow cross-site request forgery (CSRF) protection to be bypassed ! CVE-2025-24013 5.3 CodeIgniter validation of header name and value www/dojo dojo-1.15.6 ! CVE-2021-23450 7.5 Prototype Pollution www/dolibarr19 dolibarr19-19.0.4_1 ! CVE-2026-31018 8.8 Authenticated Users Can Inject PHP Code in Dolibarr Website Module ! CVE-2026-22666 8.6 Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard() www/dolibarr20 dolibarr20-20.0.4_1 ! CVE-2026-31018 8.8 Authenticated Users Can Inject PHP Code in Dolibarr Website Module ! CVE-2026-22666 8.6 Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard() www/dolibarr21 dolibarr21-21.0.4 ! CVE-2026-31018 8.8 Authenticated Users Can Inject PHP Code in Dolibarr Website Module ! CVE-2026-22666 8.6 Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard() www/dolibarr22 dolibarr22-22.0.5 ! CVE-2026-22666 8.6 Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard() www/domoticz domoticz-2025.2_1 ! CVE-2026-71265 7.5 Domoticz MochadTCP Stack Buffer Overflow via MOCHAD_RFSEC strcpy() ! CVE-2026-1001 4.8 Domoticz < 2026.1 Stored XSS via Hardware Configuration Endpoint ! CVE-2026-11425 2.0 Domoticz Mobile Dashboard versions prior to 2026.3 Stored XSS via Text/Alert Device Render www/domoticz-devel domoticz-devel-2025.2.16997_1 ! CVE-2026-71265 7.5 Domoticz MochadTCP Stack Buffer Overflow via MOCHAD_RFSEC strcpy() ! CVE-2026-1001 4.8 Domoticz < 2026.1 Stored XSS via Hardware Configuration Endpoint ! CVE-2026-11425 2.0 Domoticz Mobile Dashboard versions prior to 2026.3 Stored XSS via Text/Alert Device Render www/e107 e107-2.3.6 ! CVE-2026-72599 9.8 e107 e107 - SQL Injection ! CVE-2026-57859 7.7 e107 Second-Order Code Execution via eval()-Based Deserialization in e_array::unserialize( www/envoy envoy-1.26.1_14 ! CVE-2023-35941 8.6 Envoy vulnerable to OAuth2 credentials exploit with permanent validity ! CVE-2024-23324 8.6 Envoy ext auth can be bypassed when Proxy protocol filter sets invalid UTF-8 metadata ! CVE-2023-35944 8.2 Envoy vulnerable to incorrect handling of HTTP requests and responses with mixed case sche ! CVE-2023-35945 7.5 Envoy vulnerable to HTTP/2 memory leak in nghttp2 codec ! CVE-2024-23322 7.5 Envoy crashes when idle and request per try timeout occur within the backoff interval ! CVE-2024-23325 7.5 Envoy crashes when using an address type that isn’t supported by the OS ! CVE-2024-23327 7.5 Crash in proxy protocol when command type of LOCAL in Envoy ! CVE-2024-32475 7.5 Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytes ! CVE-2024-32976 7.5 Envoy can enter an endless loop while decompressing Brotli data with extra input ! CVE-2024-53270 7.5 HTTP/1: sending overload crashes when the request is reset beforehand in envoy ! CVE-2026-26308 7.5 Envoy has an RBAC Header Validation Bypass via Multi-Value Header Concatenation ! CVE-2026-47774 7.5 Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK ampli ! CVE-2026-48042 7.5 Envoy: Stack overflow in destructor of highly nested JSON ! CVE-2026-48044 7.5 Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion ! CVE-2026-47775 6.8 Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption ! CVE-2025-62409 6.6 Envoy allows large requests and responses to cause TCP connection pool crash ! CVE-2023-35942 6.5 Envoy's gRPC access log crash caused by the listener draining ! CVE-2024-39305 6.5 Envoy Proxy use after free when route hash policy is configured with cookie attributes ! CVE-2024-45806 6.5 Potential manipulate `x-envoy` headers from external sources in envoy ! CVE-2024-45808 6.5 Malicious log injection via access logs in envoy ! CVE-2024-45810 6.5 Envoy crashes for LocalReply in http async client ! CVE-2025-30157 6.5 Envoy crashes when HTTP ext_proc processes local replies ! CVE-2025-62504 6.5 Envoy Lua filter use-after-free when oversized rewritten response body causes crash ! CVE-2025-64527 6.5 Envoy crashes when JWT authentication is configured with the remote JWKS fetching ! CVE-2026-47204 6.5 Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes ! CVE-2023-35943 6.3 Envoy vulnerable to CORS filter segfault when origin header is removed ! CVE-2025-55162 6.3 Envoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" fla ! CVE-2024-23326 5.9 Envoy incorrectly accepts HTTP 200 response for entering upgrade mode ! CVE-2024-32974 5.9 Envoy affected by a crash in EnvoyQuicServerStream::OnInitialHeadersComplete() ! CVE-2024-32975 5.9 Envoy crashes in QuicheDataReader::PeekVarInt62Length() ! CVE-2024-34362 5.9 Envoy affected by a crash (use-after-free) in EnvoyQuicServerStream ! CVE-2026-26310 5.9 Crash for scoped ip address in Envoy during DNS ! CVE-2026-26311 5.9 Envoy HTTP: filter chain execution on reset streams causing UAF crash ! CVE-2026-47221 5.9 Envoy: Null pointer deref in internal redirects ! CVE-2026-48497 5.9 Envoy: Abnormal process termination in DNS UDP filter ! CVE-2024-34364 5.7 Envoy OOM vector from HTTP async client with unbounded response buffer for mirror response ! CVE-2024-30255 5.3 HTTP/2: CPU exhaustion due to CONTINUATION frame flood ! CVE-2025-46821 5.3 Envoy vulnerable to bypass of RBAC uri_template permission ! CVE-2026-26309 5.3 Envoy has an off-by-one write in JsonEscaper::escapeString() ! CVE-2026-26330 5.3 Envoy global rate limit may crash when the response phase limit is enabled and the respons ! CVE-2025-66220 5.0 Envoy’s TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat ! CVE-2026-47778 4.4 Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (A ! CVE-2024-23323 4.3 Excessive CPU usage when URI template matcher is configured using regex in Envoy ! CVE-2025-64763 3.7 Envoy forwards early CONNECT data in TCP proxy mode www/firefox firefox-156.0,2 ! CVE-2013-5594 4.3 Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml bi www/forgejo15 forgejo15-15.0.7_1 ! CVE-2026-89094 9.9 Remote Code Execution in Forgejo Template Repository ! CVE-2026-89151 3.5 Forgejo Restricted API Token Privilege Escalation www/forgejo16 forgejo16-16.0.3_1 ! CVE-2026-89094 9.9 Remote Code Execution in Forgejo Template Repository ! CVE-2026-89151 3.5 Forgejo Restricted API Token Privilege Escalation www/gitea gitea-1.27.2_2 ! CVE-2026-34966 8.3 Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass www/glpi glpi-11.0.1_1,1 ! CVE-2026-26026 9.1 GLPI has a Server-Side Template Injection via Double-Compilation ! CVE-2026-5385 8.4 GLPI 11.0.0 - Stored XSS in knowledge base ! CVE-2026-22248 8.1 GLPI affected by Remote Code Execution via malicious upload ! CVE-2026-26263 8.1 GLPI has an Unauthenticated SQL Injection via Search engine ! CVE-2025-64516 7.5 GLPI incorrectly authorizes access to documents ! CVE-2025-66417 7.5 GLPI has an unauthenticated SQL injection through the inventory endpoint ! CVE-2026-26027 7.5 GLPI has an Unauthenticated Stored XSS via inventory ! CVE-2026-29047 7.2 GLPI has an Authenticated SQL Injection via log exports ! CVE-2026-40108 7.1 GLPI Vulnerable to Stored XSS in ITIL Costs ! CVE-2026-42317 7.0 GLPI vulnerable to arbitrary files deletion by technician ! CVE-2026-42318 7.0 GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint ! CVE-2026-44281 7.0 GLPI vulnerable to unauthorized reading of a specific asset object ! CVE-2026-25936 6.5 GLPI Vulnerable to Authenticated SQL Injection ! CVE-2026-25937 6.5 GLPI has a MFA bypass ! CVE-2026-42320 5.9 GLPI vulnerable to arbitrary file access ! CVE-2026-32312 5.1 GLPI: Unauthorized export of form structure ! CVE-2026-23624 4.3 GLPI is vulnerable to session stealing on externally authenticated user change ! CVE-2026-22247 4.1 GLPI is Vulnerable to SSRF via Webhooks www/gohugo gohugo-0.165.0_3,1 ! CVE-2026-10582 8.3 Hugo 0.91.0 through 0.165.0 Server-Side Request Forgery via security.http.urls Lacking Des ! CVE-2026-10618 4.8 Hugo 0.93.0 through 0.165.0 Stored Cross-Site Scripting via Unescaped Code-Fence Attribute www/grails grails-1.3.6_2 ! CVE-2016-6521 8.8 Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Consol www/gstreamer1-plugins-neon gstreamer1-plugins-neon-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p www/gstreamer1-plugins-srt gstreamer1-plugins-srt-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p www/ilias php84-ilias-11.3 ! CVE-2026-86416 5.3 ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods www/jetty10 jetty10-10.0.25_2 ! CVE-2026-10050 8.7 Digest authentication lossy encoding ! CVE-2026-12611 8.7 HTTP/2 Race Condition Causing Server Denial of Service in Jetty ! CVE-2026-19204 8.7 Jetty WebSocket Frame Memory Exhaustion via Unknown Opcode and Large Payload ! CVE-2026-19203 8.3 HTTP Request Smuggling via Malformed Chunked Requests in Jetty ! CVE-2025-5115 7.7 MadeYouReset HTTP/2 vulnerability ! CVE-2026-2332 7.4 HTTP Request Smuggling via Chunked Extension Quoted-String Parsing ! CVE-2026-5795 7.4 org.eclipse.jetty.ee10/jetty-ee10: early return from the JASPIAuthenticator class without ! CVE-2026-6790 5.3 In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that th ! CVE-2024-6763 3.7 Jetty URI parsing of invalid authority ! CVE-2025-11143 3.7 org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI p www/jetty12 jetty12-12.0.31_2 ! CVE-2026-10050 8.7 Digest authentication lossy encoding ! CVE-2026-12611 8.7 HTTP/2 Race Condition Causing Server Denial of Service in Jetty ! CVE-2026-19204 8.7 Jetty WebSocket Frame Memory Exhaustion via Unknown Opcode and Large Payload ! CVE-2026-19203 8.3 HTTP Request Smuggling via Malformed Chunked Requests in Jetty ! CVE-2026-1605 7.5 org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inf ! CVE-2026-2332 7.4 HTTP Request Smuggling via Chunked Extension Quoted-String Parsing ! CVE-2026-5795 7.4 org.eclipse.jetty.ee10/jetty-ee10: early return from the JASPIAuthenticator class without ! CVE-2026-10051 6.9 In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the t ! CVE-2026-6790 5.3 In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that th ! CVE-2026-8384 5.3 Jetty Path Normalization Bug Returning Unresolved Paths www/jitsi-meet jitsi-meet-1.0.9008 ! CVE-2024-44081 9.8 In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in ! CVE-2024-33530 7.5 In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make us ! CVE-2024-44080 7.5 In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was impleme ! CVE-2025-64754 2.7 Jitsi Meet has DOM Redirect on Microsoft OAuth Flow www/joomla5 joomla5-5.4.7 ! CVE-2026-73373 8.9 Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0 ! CVE-2026-71574 8.5 Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in J ! CVE-2026-73337 8.2 Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1. ! CVE-2026-71573 6.9 Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6 ! CVE-2026-72531 5.1 Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in ! CVE-2026-72532 5.1 Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Jooml ! CVE-2026-73336 5.1 Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6. ! CVE-2026-73371 5.1 Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4 ! CVE-2026-73372 5.1 Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in ! CVE-2026-71572 4.8 Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5. www/joomla6 joomla6-6.1.2 ! CVE-2026-73373 8.9 Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0 ! CVE-2026-71574 8.5 Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in J ! CVE-2026-73337 8.2 Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1. ! CVE-2026-71573 6.9 Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6 ! CVE-2026-72531 5.1 Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in ! CVE-2026-72532 5.1 Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Jooml ! CVE-2026-73336 5.1 Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6. ! CVE-2026-73371 5.1 Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4 ! CVE-2026-73372 5.1 Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in ! CVE-2026-71572 4.8 Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5. www/kanboard php84-kanboard-1.2.47_1 ! CVE-2026-21881 9.1 Kanboard is Vulnerable to Reverse Proxy Authentication Bypass ! CVE-2026-25924 8.5 Kanboard is Missing Access Control on Plugin Installation leading to Administrative RCE ! CVE-2026-33058 8.4 Kanboard has Authenticated SQL Injection in Project Permissions Handler ! CVE-2026-57862 8.4 Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation ! CVE-2026-58660 7.2 Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop ! CVE-2026-29056 7.0 Kanboard's privilege escalation via mass assignment in user invite registration allows any ! CVE-2026-24885 5.7 Kanboard Affected by Cross-Site Request Forgery (CSRF) via Content-Type Misconfiguration i ! CVE-2026-21880 5.3 Kanboard LDAP Injection Vulnerability can Lead to User Enumeration and Information Disclos ! CVE-2026-56774 5.3 Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated Session ID ! CVE-2026-21879 4.7 Kanboard vulnerable to Open Redirect via protocol-relative URLs ! CVE-2026-25530 4.3 Kanboard is missing authorization check in getSwimlane API allows cross-project data acces ! CVE-2026-25531 4.3 Kanboard TaskCreationController::duplicateProjects() endpoint does not validate user permi www/kannel kannel-1.4.4_15,1 ! CVE-2017-14609 7.8 The server daemons in Kannel 1.5.0 and earlier create a PID file after dropping privileges www/libmicrohttpd libmicrohttpd-1.0.10 ! CVE-2025-59777 8.7 libmicrohttpd: GNU libmicrohttpd null pointer dereference ! CVE-2025-62689 8.7 libmicrohttpd: GNU libmicrohttpd null pointer dereference www/linux-c7-qtwebkit linux-c7-qtwebkit-2.3.4_3 ! CVE-2015-8079 5.3 qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcon www/linux-chrome linux-chrome-152.0.7977.75 ! CVE-2026-87544 9.8 Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-85042 9.6 DevTools Use-After‑Free Allows Remote Code Execution ! CVE-2026-87448 9.6 Chrome DevTools Use-After‑Free Allows Remote Code Execution ! CVE-2026-87455 9.6 Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker t ! CVE-2026-87464 9.6 Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87474 9.6 Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87492 9.6 Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87500 9.6 Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowe ! CVE-2026-87504 9.6 Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker l ! CVE-2026-87526 9.6 Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87527 9.6 Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87529 9.6 Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87547 9.6 Chrome FileSystem Reference Resolution Vulnerability Enabling Arbitrary Code Execution ! CVE-2026-87581 9.6 Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87634 9.6 Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87638 9.6 Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote atta ! CVE-2026-87646 9.6 Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87650 9.6 Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-85043 9.1 Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote att ! CVE-2026-87613 9.0 Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allow ! CVE-2026-85046 8.8 KEV Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to ! CVE-2026-85049 8.8 chromium-browser: skia: chromium-browser: Use after free in Skia ! CVE-2026-85051 8.8 Type Confusion in Chrome Compositing Allows Remote Code Execution ! CVE-2026-85053 8.8 CacheStorage Resource Exposure Enables Remote Code Execution in Chrome ! CVE-2026-87430 8.8 Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87433 8.8 Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87440 8.8 Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87444 8.8 chromium-browser: chromium-browser: Memory corruption in Codecs ! CVE-2026-87460 8.8 chromium-browser: chromium-browser: Use after free in Platform ! CVE-2026-87489 8.8 Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87491 8.8 KEV V8 Out‑of‑Bounds Write Enables Remote Code Execution in Chrome ! CVE-2026-87536 8.8 Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to ! CVE-2026-87542 8.8 Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87569 8.8 Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87570 8.8 Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87579 8.8 Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87587 8.8 Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to ! CVE-2026-87588 8.8 chromium-browser: chromium-browser: Use after free in Chromecast ! CVE-2026-87612 8.8 chromium-browser: chromium-browser: Type confusion in V8 ! CVE-2026-87617 8.8 Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87625 8.8 Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker lev ! CVE-2026-87636 8.8 chromium-browser: chromium-browser: Type confusion in XML ! CVE-2026-87633 8.6 Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker t ! CVE-2026-85048 8.3 Use‑After‑Free in Chrome Compositing Enables Code Execution Outside Sandbox ! CVE-2026-87479 8.3 Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allo ! CVE-2026-87480 8.3 Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87487 8.3 Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87506 8.3 WebUI Privilege Escalation in Google Chrome via Renderer Process ! CVE-2026-87510 8.3 Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87553 8.3 Renderer Process Escalation via Improper SiteIsolation Input Validation in Chrome ! CVE-2026-87572 8.3 Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker wh ! CVE-2026-87578 8.3 Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent att ! CVE-2026-87582 8.3 Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87604 8.3 Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87628 8.3 Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacke ! CVE-2026-87639 8.3 Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87471 8.1 chromium-browser: chromium-browser: Incorrect authorization in ServiceWorker ! CVE-2026-87499 8.1 chromium-browser: chromium-browser: Incorrect authorization in Network ! CVE-2026-87505 8.1 Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-87514 8.1 Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker t ! CVE-2026-87533 8.1 Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacke ! CVE-2026-87537 8.1 Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-85045 7.5 V8 Race Condition Enabling Remote Code Execution in Chrome ! CVE-2026-87431 7.5 Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87450 7.5 Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a r ! CVE-2026-87601 7.5 Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to ! CVE-2026-87429 6.5 Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a r ! CVE-2026-87436 6.5 Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87437 6.5 Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87441 6.5 Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87443 6.5 chromium-browser: chromium-browser: Missing authorization in Actor ! CVE-2026-87446 6.5 Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87447 6.5 Chrome Network Authorization Bypass via Extension ! CVE-2026-87459 6.5 Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87475 6.5 chromium-browser: chromium-browser: Missing authorization in Omnibox ! CVE-2026-87476 6.5 chromium-browser: chromium-browser: Incorrect authorization in Loader ! CVE-2026-87477 6.5 Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87478 6.5 Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87490 6.5 Information leak in Transactions Platform in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87513 6.5 Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87515 6.5 Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87523 6.5 Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87532 6.5 Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87541 6.5 Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87549 6.5 Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87593 6.5 Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87620 6.5 Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87623 6.5 Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87629 6.5 Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87631 6.5 Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote atta ! CVE-2026-87445 5.4 UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87458 5.4 UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87462 5.4 UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87484 5.4 UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87496 5.4 UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87501 5.4 chromium-browser: chromium-browser: UI misrepresentation in Passwords ! CVE-2026-87507 5.4 UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87540 5.4 Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87567 5.4 UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-87571 5.4 Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87575 5.4 Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87599 5.4 Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87615 5.4 Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87635 5.4 chromium-browser: chromium-browser: UI misrepresentation in Payments ! CVE-2026-87645 5.4 chromium-browser: chromium-browser: Improper state validation in Safebrowsing ! CVE-2026-87649 5.4 UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87655 5.4 Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87656 5.4 Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87435 5.3 Information Leak via ControlledFrame in Google Chrome ! CVE-2026-87439 5.3 Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87453 5.3 Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87566 5.3 chromium-browser: chromium-browser: Observable discrepancy in Layout ! CVE-2026-87594 5.3 Incorrect authorization in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87605 5.3 Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87641 5.3 Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87568 4.8 Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-87449 4.3 Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153. ! CVE-2026-87461 4.3 Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87466 4.3 Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87495 4.3 Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87497 4.3 chromium-browser: chromium-browser: Uninitialized resource in Codecs ! CVE-2026-87508 4.3 Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87516 4.3 Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87543 4.3 Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87548 4.3 Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a r ! CVE-2026-87550 4.3 Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 all ! CVE-2026-87551 4.3 Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87556 4.3 Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87557 4.3 Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8010.36 allowe ! CVE-2026-87560 4.3 Chrome Browser Authorization Bypass via Crafted HTML Page ! CVE-2026-87561 4.3 Incorrect authorization in Web Authentication in Google Chrome prior to 153.0.8010.36 allo ! CVE-2026-87563 4.3 Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87564 4.3 chromium-browser: chromium-browser: Type confusion in V8 ! CVE-2026-87573 4.3 Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87574 4.3 chromium-browser: chromium-browser: Information leak in ServiceWorker ! CVE-2026-87577 4.3 Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87586 4.3 Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87592 4.3 Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87596 4.3 Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87598 4.3 chromium-browser: chromium-browser: Incorrect authorization in ServiceWorker ! CVE-2026-87619 4.3 chromium-browser: chromium-browser: Observable discrepancy in Prefetch ! CVE-2026-87622 4.3 Missing authorization in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87630 4.3 Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87632 4.3 Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87642 4.3 Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87651 4.3 Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87658 4.3 Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87432 4.2 Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-87465 4.2 chromium-browser: chromium-browser: Incorrect authorization in Downloads ! CVE-2026-87472 4.2 Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87502 4.2 Confused Deputy in Chrome Fullscreen Allows UI Spoofing via Compromised Renderer ! CVE-2026-87538 4.2 Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker wh ! CVE-2026-87559 4.2 UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87456 3.4 Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87647 3.4 Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-85052 3.1 Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a rem ! CVE-2026-87434 3.1 Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87442 3.1 Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote atta ! CVE-2026-87451 3.1 Information leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87485 3.1 Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87498 3.1 chromium-browser: chromium-browser: Missing authorization in WebUI ! CVE-2026-87521 3.1 Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87531 3.1 Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87539 3.1 Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87611 3.1 Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87614 3.1 Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87652 3.1 Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87657 3.1 chromium-browser: chromium-browser: Use after free in V8 www/man2web man2web-0.88_3 ! CVE-2005-2812 7.5 man2web allows remote attackers to execute arbitrary commands via -P arguments. www/mediawiki143 mediawiki143-php84-1.43.9 ! CVE-2026-58025 5.9 Remote Code Execution via Unsafe Deserialization in LogItem Import ! CVE-2026-58029 5.3 Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata ! CVE-2026-58032 5.3 mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html ! CVE-2026-58033 5.3 "Total number of distinct authors" statistic at action=info does not exclude revisions whe ! CVE-2026-58024 5.1 API identification of users on private wikis ! CVE-2025-6589 2.1 With MultiBlocks enabled and a user who is suppressed via a MultiBlock, a user without 'hi ! CVE-2025-67476 1.3 Importing leaks IP address of importer via EventStreams ! CVE-2025-61645 0.0 CodexTablePager has i18n XSS ! CVE-2025-67477 0.0 Stored XSS through a system message in Special:ApiSandbox ! CVE-2026-58026 0.0 $wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces ! CVE-2026-58028 0.0 Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets ! CVE-2026-58037 0.0 Core log entries for exceptions and XSS issues in log entry formatting code that may be ca www/mediawiki145 mediawiki145-php84-1.45.4 ! CVE-2026-58025 5.9 Remote Code Execution via Unsafe Deserialization in LogItem Import ! CVE-2026-58029 5.3 Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata ! CVE-2026-58032 5.3 mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html ! CVE-2026-58033 5.3 "Total number of distinct authors" statistic at action=info does not exclude revisions whe ! CVE-2026-58024 5.1 API identification of users on private wikis ! CVE-2025-6589 2.1 With MultiBlocks enabled and a user who is suppressed via a MultiBlock, a user without 'hi ! CVE-2026-58026 0.0 $wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces ! CVE-2026-58028 0.0 Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets ! CVE-2026-58037 0.0 Core log entries for exceptions and XSS issues in log entry formatting code that may be ca www/mediawiki146 mediawiki146-php84-1.46.0_1 ! CVE-2026-58025 5.9 Remote Code Execution via Unsafe Deserialization in LogItem Import ! CVE-2026-58029 5.3 Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata ! CVE-2026-58032 5.3 mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html ! CVE-2026-58033 5.3 "Total number of distinct authors" statistic at action=info does not exclude revisions whe ! CVE-2026-58024 5.1 API identification of users on private wikis ! CVE-2025-6589 2.1 With MultiBlocks enabled and a user who is suppressed via a MultiBlock, a user without 'hi ! CVE-2026-58026 0.0 $wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces ! CVE-2026-58028 0.0 Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets ! CVE-2026-58037 0.0 Core log entries for exceptions and XSS issues in log entry formatting code that may be ca www/minio minio-2025.10.15.17.29.55_14 ! CVE-2026-33322 9.2 MinIO: JWT Algorithm Confusion in OIDC Authentication ! CVE-2026-33419 9.1 MinIO: LDAP login brute-force via user enumeration and missing rate limit ! CVE-2026-40344 8.8 MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-T ! CVE-2026-41145 8.8 MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in ! CVE-2018-1000538 7.5 Minio Inc. Minio S3 server version prior to RELEASE.2018-05-16T23-35-33Z contains a Alloca ! CVE-2026-34204 7.1 MinIO is Vulnerable to SSE Metadata Injection via Replication Headers ! CVE-2026-39414 7.1 MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing ! CVE-2026-42600 6.9 MinIO: Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint www/mod_auth_openidc ap24-mod_auth_openidc-2.4.19.1 ! CVE-2026-54789 7.5 mod_auth_openidc has out-of-bounds read and write in state cookie parsing www/mod_fcgid ap24-mod_fcgid-2.3.9 ! CVE-2016-1000104 8.8 mod_fcgid: mod_fcgid sets environmental variable based on user supplied Proxy request head www/mongoose mongoose-5.6_1 ! CVE-2018-20353 9.8 An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in t ! CVE-2018-20354 9.8 An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the ! CVE-2018-20355 9.8 An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_prot ! CVE-2018-20356 9.8 An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto ! CVE-2019-12951 9.8 An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c ha ! CVE-2022-25299 9.8 Arbitrary File Write ! CVE-2026-73251 9.3 Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verifica ! CVE-2026-73253 9.1 Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching ! CVE-2026-73256 9.1 Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE ! CVE-2026-73257 9.1 Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling ! CVE-2026-11404 8.7 Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID Parsing ! CVE-2024-42386 8.2 Use of Out-of-range Pointer Offset in Mongoose Web Server library ! CVE-2023-34188 7.5 The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Lengt ! CVE-2024-42384 7.5 Integer Overflow or Wraparound in Mongoose Web Server library ! CVE-2026-73255 6.5 Mongoose: Path traversal in SSI #include directives enables arbitrary file read ! CVE-2026-73258 6.5 Mongoose: Multipart boundary/header scan logic error in mg_http_next_multipart ! CVE-2026-2966 6.3 Cesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random values ! CVE-2026-2967 6.3 Cesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of source ! CVE-2026-2968 6.3 Cesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt s ! CVE-2026-73254 5.4 Mongoose: Stored XSS via unescaped filenames in directory listing ! CVE-2026-73259 5.4 Mongoose: Reflected XSS via decoded URI in directory listing render ! CVE-2024-42387 5.3 Use of Out-of-range Pointer Offset in Mongoose Web Server library ! CVE-2024-42388 5.3 Use of Out-of-range Pointer Offset in Mongoose Web Server library ! CVE-2024-42389 5.3 Use of Out-of-range Pointer Offset in Mongoose Web Server library ! CVE-2024-42390 4.3 Use of Out-of-range Pointer Offset in Mongoose Web Server library ! CVE-2024-42391 4.3 Use of Out-of-range Pointer Offset in Mongoose Web Server library ! CVE-2025-65502 4.3 Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote at ! CVE-2024-42383 4.2 Use of Out-of-range Pointer Offset in Mongoose Web Server library ! CVE-2024-42385 4.0 Improper Neutralization of Delimiters in Mongoose Web Server library ! CVE-2024-42392 4.0 Improper Neutralization of Delimiters in Mongoose Web Server library www/netsurf netsurf-3.11_2 ! CVE-2024-51317 6.5 An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_ ! CVE-2025-29699 6.5 NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function. ! CVE-2025-45663 6.5 An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when cr www/opencart opencart-4.1.0.4 ! CVE-2024-21514 7.4 This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue ! CVE-2024-21518 7.2 This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was ! CVE-2024-21519 6.6 This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Cre ! CVE-2025-45892 6.1 OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via t ! CVE-2025-45893 6.1 OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via S ! CVE-2026-84437 5.1 OpenCart Autocomplete Workflow address.php cross site scripting ! CVE-2026-84438 5.1 OpenCart Autocomplete Workflow edit.php cross site scripting ! CVE-2024-21515 2.1 This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue ! CVE-2024-21517 2.1 This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue www/openemr openemr-php84-8.0.0 ! CVE-2026-39932 9.4 OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection ! CVE-2026-32238 9.1 OpenEMR has Remote Code Execution in backup functionality ! CVE-2026-32127 8.8 SQL Injection Vulnerability in ajax graphs library (OpenEMR) ! CVE-2026-33917 8.8 OpenEMR has SQL Injection in CAMOS Form ! CVE-2026-33346 8.7 OpenEMR has stored XSS in portal_payment.php via Unescaped table_args ! CVE-2026-33348 8.7 OpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3 ! CVE-2026-39931 8.6 OpenEMR Authenticated SQL Injection via backup.php Import Feature ! CVE-2026-67610 8.6 OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access ! CVE-2026-67611 8.6 OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration ! CVE-2026-33299 8.5 OpenEMR has Stored XSS in patient encounter Eye Exam form answers ! CVE-2026-29187 8.1 OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup. ! CVE-2026-34055 8.1 OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification ! CVE-2026-32121 7.7 OpenEMR: Stored DOM XSS via `.html()` in Portal Signer Modal ! CVE-2026-32123 7.7 OpenEMR: Therapy Group Sensitivity ACL No Longer Enforced ! CVE-2026-33913 7.7 OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files ! CVE-2026-34056 7.7 OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data ! CVE-2026-46518 7.7 OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics ! CVE-2026-33918 7.6 OpenEMR Missing Authorization on Claim File Download Endpoint ! CVE-2026-33932 7.6 OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes ! CVE-2026-33302 7.3 OpenEMR: zhAclCheck Ignores Explicit ACL Denies ! CVE-2026-33321 7.2 OpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF) ! CVE-2026-33910 7.2 OpenEMR has a SQL Injection Vulnerability in patient selection ! CVE-2026-33914 7.2 OpenEMR has SQL Injection in PostCalendar Category Delete ! CVE-2026-32126 7.1 OpenEMR: Inverted ACL Condition in CDR ControllerRouter Allows Any Authenticated User to M ! CVE-2026-33301 7.1 OpenEMR has arbitrary image file read via PDF generator ! CVE-2026-34053 7.1 OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler ! CVE-2026-40506 7.0 OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.php ! CVE-2026-24488 6.5 OpenEMR Vulnerable to Arbitrary File Exfiltration via Fax Endpoint ! CVE-2026-25744 6.5 OpenEMR: POST /api/.../vital Accepts Attacker-Supplied id and Overwrites Arbitrary Vitals ! CVE-2026-25745 6.5 OpenEMR's Message Update Ignores Patient id ! CVE-2026-25928 6.5 OpenEMR Vulnerable to Path Traversal When Zipping DICOM Folders ! CVE-2026-27943 6.5 OpenEMR's Eye Exam View Trusts form_id Without Verifying Patient/Encounter Ownership ! CVE-2026-32120 6.5 OpenEMR has IDOR in Fee Sheet Product Save ! CVE-2026-33304 6.5 OpenEMR has Authorization Bypass in Dated Reminders Log ! CVE-2026-33931 6.5 OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access ! CVE-2026-33933 6.1 Reflected XSS via Unescaped contextName Parameter in Custom Template Editor ! CVE-2026-33909 5.9 OpenEMR Vulnerable to SQL Injection via Unsanitized Variables in MedEx Recall/Reminder Pro ! CVE-2026-32118 5.4 OpenEMR has Stored XSS in Graphical Pain Map legend via unescaped annotation text ! CVE-2026-32124 5.4 OpenEMR: Dynamic Code Picker Renders Unescaped Descriptions (Stored XSS) ! CVE-2026-32125 5.4 OpenEMR: Stored XSS in Track Anything Graphs via Unescaped Dygraph Titles/Labels ! CVE-2026-33303 5.4 OpenEMR Vulnerable to Stored XSS via Unescaped portal_login_username in Credential Print V ! CVE-2026-33305 5.4 OpenEMR has Authorization Bypass in FaxSMS AppDispatch Constructor ! CVE-2026-33911 5.4 OpenEMR vulnerable to reflected XSS in graphs.php via title parameter ! CVE-2026-33912 5.4 OpenEMR has reflected XSS in ajax_download.php via reportID parameter ! CVE-2026-33915 5.4 OpenEMR Missing ACL Checks on Insurance Company API Routes ! CVE-2026-34051 5.4 OpenEMR has Improper ACL On Import/Export Popup ! CVE-2026-40509 5.3 OpenEMR < 8.3.0 CSRF via DICOM Viewer web_path Parameter ! CVE-2026-76614 5.3 OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore ! CVE-2026-40507 5.1 OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal ! CVE-2026-40508 5.1 OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler ! CVE-2026-67612 4.8 OpenEMR 8.2.0 Stored XSS via import_template.php Template Management ! CVE-2026-32119 4.4 OpenEMR has Stored DOM XSS via SearchHighlight text-node reconstruction on Custom Report p ! CVE-2026-32122 4.3 OpenEMR: Missing Authorization on Claim File Tracker UI and AJAX Endpoint (V2) ! CVE-2026-33934 4.3 OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff www/osticket osticket-php84-1.18.4 ! CVE-2022-32074 5.4 A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php o www/otrs otrs-6.0.29_3 ! CVE-2022-39051 6.8 Perl Code execution in Template Toolkit ! CVE-2021-21438 3.5 FAQ articles are shown to users without permission www/p5-Mojolicious p5-Mojolicious-9.49 ! CVE-2024-58134 8.1 Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's www/pear-twig php84-pear-twig-twig-1.29.0 ! CVE-2026-46633 8.7 Twig: PHP code injection via `{% use %}` template name ! CVE-2024-45411 8.6 Twig has a possible sandbox bypass ! CVE-2001-1537 7.5 The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier sto ! CVE-2022-39261 7.5 Twig may load a template outside a configured directory when using the filesystem loader ! CVE-2026-46627 7.1 Twig: Sandbox resource exhaustion via unbounded `for` / `range()` ! CVE-2026-47732 7.1 Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points ! CVE-2026-48806 7.1 Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys ! CVE-2026-48807 7.1 Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filte ! CVE-2026-46638 6.0 Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete f ! CVE-2026-48808 6.0 Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterfa ! CVE-2026-49981 6.0 Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes betwee ! CVE-2026-46629 5.3 Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled argu ! CVE-2026-46635 5.3 Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects) ! CVE-2026-48805 5.3 Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php` ! CVE-2026-46628 5.1 Twig: The `spaceless` filter implicitly marks its output as safe ! CVE-2026-46637 5.1 Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']` ! CVE-2019-9942 3.7 A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because www/phpmyfaq phpmyfaq-php84-4.1.8 ! CVE-2026-76208 8.8 phpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAP ! CVE-2026-85589 5.3 phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API www/phpsysinfo phpsysinfo-php84-3.4.4 ! CVE-2026-55584 7.5 phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP head www/piwigo piwigo-php84-16.4.0 ! CVE-2024-26450 5.4 An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the a www/py-httplib2 py312-httplib2-0.32.0 ! CVE-2020-11078 6.8 CRLF injection in httplib2 www/py-postorius py312-postorius-1.3.13_5 ! CVE-2026-44742 7.2 Unescaped HTML in Message Subject Enables XSS via Held Messages Pop‑up www/py-werkzeug2 py312-werkzeug2-2.3.8 ! CVE-2024-34069 7.5 Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote ! CVE-2024-49767 6.9 Werkzeug possible resource exhaustion when parsing file data in forms ! CVE-2024-49766 6.3 Werkzeug safe_join not safe on Windows ! CVE-2025-66221 6.3 Werkzeug safe_join() allows Windows special device names ! CVE-2026-21860 6.3 Werkzeug safe_join() allows Windows special device names with compound extensions ! CVE-2026-27199 6.3 Werkzeug safe_join() allows Windows special device names www/pydio-cells pydio-cells-5.0.2_4 ! CVE-2026-76032 5.3 Pydio Cells 5.0.0 to 5.0.2 - Missing Authorization on the Share Link REST Handler www/rt44 rt44-4.4.9 ! CVE-2026-44231 9.1 RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint ! CVE-2026-41076 8.1 RT: LDAP authentication bypass via empty password ! CVE-2026-41073 4.6 RT: Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Excel and simil www/rubygem-activeresource4 rubygem-activeresource4-4.1.0 ! CVE-2020-8151 7.5 There is a possible information disclosure issue in Active Resource ! CVE-2026-35611 7.5 Addressable has a Regular Expression Denial of Service in Addressable templates www/rubygem-carrierwave-gitlab rubygem-carrierwave-gitlab-1.3.4 ! CVE-2024-29034 6.8 CarrierWave's Content-Type allowlist bypass vulnerability which possibly leads to XSS rema ! CVE-2026-44587 4.7 CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters www/rubygem-carrierwave1 rubygem-carrierwave1-1.3.4_1 ! CVE-2024-29034 6.8 CarrierWave's Content-Type allowlist bypass vulnerability which possibly leads to XSS rema ! CVE-2026-44587 4.7 CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters www/rubygem-faraday0 rubygem-faraday0-0.17.6 ! CVE-2026-25765 5.8 Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url www/rubygem-faraday1 rubygem-faraday1-1.10.6 ! CVE-2026-25765 5.8 Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url www/rubygem-gon-rails5 rubygem-gon-rails5-6.2.1 ! CVE-2020-25739 6.1 An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor www/rubygem-gon-rails50 rubygem-gon-rails50-6.2.1 ! CVE-2020-25739 6.1 An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor www/rubygem-httparty021 rubygem-httparty021-0.21.0 ! CVE-2025-68696 7.8 httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage www/rubygem-puma6 rubygem-puma6-6.6.1 ! CVE-2026-47736 7.5 Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion ! CVE-2026-47737 7.5 Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections www/rubygem-rack16 rubygem-rack16-1.6.13 ! CVE-2022-30123 10.0 rubygem-rack: crafted requests can cause shell escape sequences ! CVE-2020-8161 8.6 rubygem-rack: directory traversal in Rack::Directory ! CVE-2020-8184 7.5 rubygem-rack: percent-encoded cookies can be used to overwrite existing prefixed cookie na ! CVE-2022-30122 7.5 rubygem-rack: crafted multipart POST request may cause a DoS ! CVE-2024-26141 5.8 Possible DoS Vulnerability with Range Header in Rack ! CVE-2024-25126 5.3 Rack ReDos in content type parsing (2nd degree polynomial) ! CVE-2024-26146 5.3 Possible Denial of Service Vulnerability in Rack Header Parsing www/rubygem-rails4 rubygem-rails4-4.2.11.3 ! CVE-2019-5420 9.8 rubygem-rails: Weak secret token leading to possible code execution ! CVE-2020-8165 9.8 rubygem-activesupport: potentially unintended unmarshalling of user-provided objects in Me ! CVE-2020-8163 8.8 rubygem-rails: potential remote code execution of user-provided local names ! CVE-2026-33195 8.0 Rails Active Storage has possible Path Traversal in DiskService ! CVE-2020-8162 7.5 rubygem-activestorage: circumvention of file size limits in ActiveStorage ! CVE-2020-8164 7.5 rubygem-actionpack: possible strong parameters bypass ! CVE-2021-22880 7.5 rubygem-activerecord: crafted input may cause a regular expression DoS ! CVE-2021-22904 7.5 rails: Possible DoS Vulnerability in Action Controller Token Authentication ! CVE-2023-22792 7.5 rubygem-actionpack: Denial of Service in Action Dispatch ! CVE-2023-22795 7.5 rubygem-actionpack: Denial of Service in Action Dispatch ! CVE-2026-33169 6.9 Rails Active Support has a possible ReDoS vulnerability in number_to_delimited ! CVE-2024-47887 6.6 Action Controller has possible ReDoS vulnerability in HTTP Token authentication ! CVE-2024-47889 6.6 Action Mailer has possible ReDoS vulnerability in block_format ! CVE-2026-33174 6.6 Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range request ! CVE-2026-33176 6.6 Rails Active Support has a possible DoS vulnerability in its number helpers ! CVE-2026-33202 6.6 Rails Active Storage has possible glob injection in its DiskService ! CVE-2020-8167 6.5 rubygem-actionview: CSRF vulnerability in rails-ujs ! CVE-2026-33170 5.3 Rails Active Support has a possible XSS vulnerability in SafeBuffer#% ! CVE-2026-33173 5.3 Rails Active Storage has possible content type bypass via metadata in direct uploads ! CVE-2020-8166 4.3 rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token ! CVE-2026-33658 2.3 Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range reques www/rubygem-rails5 rubygem-rails5-5.1.7_2 ! CVE-2019-5420 9.8 rubygem-rails: Weak secret token leading to possible code execution ! CVE-2020-8165 9.8 rubygem-activesupport: potentially unintended unmarshalling of user-provided objects in Me ! CVE-2022-23634 8.0 Information Exposure when using Puma with Rails ! CVE-2026-33195 8.0 Rails Active Storage has possible Path Traversal in DiskService ! CVE-2020-8162 7.5 rubygem-activestorage: circumvention of file size limits in ActiveStorage ! CVE-2020-8164 7.5 rubygem-actionpack: possible strong parameters bypass ! CVE-2021-22880 7.5 rubygem-activerecord: crafted input may cause a regular expression DoS ! CVE-2021-22904 7.5 rails: Possible DoS Vulnerability in Action Controller Token Authentication ! CVE-2023-22792 7.5 rubygem-actionpack: Denial of Service in Action Dispatch ! CVE-2023-22795 7.5 rubygem-actionpack: Denial of Service in Action Dispatch ! CVE-2022-23633 7.4 Exposure of sensitive information in Action Pack ! CVE-2026-33169 6.9 Rails Active Support has a possible ReDoS vulnerability in number_to_delimited ! CVE-2024-47887 6.6 Action Controller has possible ReDoS vulnerability in HTTP Token authentication ! CVE-2024-47889 6.6 Action Mailer has possible ReDoS vulnerability in block_format ! CVE-2026-33174 6.6 Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range request ! CVE-2026-33176 6.6 Rails Active Support has a possible DoS vulnerability in its number helpers ! CVE-2026-33202 6.6 Rails Active Storage has possible glob injection in its DiskService ! CVE-2020-8167 6.5 rubygem-actionview: CSRF vulnerability in rails-ujs ! CVE-2026-33170 5.3 Rails Active Support has a possible XSS vulnerability in SafeBuffer#% ! CVE-2026-33173 5.3 Rails Active Storage has possible content type bypass via metadata in direct uploads ! CVE-2020-8166 4.3 rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token ! CVE-2026-33658 2.3 Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range reques www/rubygem-rails50 rubygem-rails50-5.0.7.2_2 ! CVE-2019-5420 9.8 rubygem-rails: Weak secret token leading to possible code execution ! CVE-2020-8165 9.8 rubygem-activesupport: potentially unintended unmarshalling of user-provided objects in Me ! CVE-2022-23634 8.0 Information Exposure when using Puma with Rails ! CVE-2026-33195 8.0 Rails Active Storage has possible Path Traversal in DiskService ! CVE-2020-8162 7.5 rubygem-activestorage: circumvention of file size limits in ActiveStorage ! CVE-2020-8164 7.5 rubygem-actionpack: possible strong parameters bypass ! CVE-2021-22880 7.5 rubygem-activerecord: crafted input may cause a regular expression DoS ! CVE-2021-22904 7.5 rails: Possible DoS Vulnerability in Action Controller Token Authentication ! CVE-2023-22792 7.5 rubygem-actionpack: Denial of Service in Action Dispatch ! CVE-2023-22795 7.5 rubygem-actionpack: Denial of Service in Action Dispatch ! CVE-2022-23633 7.4 Exposure of sensitive information in Action Pack ! CVE-2026-33169 6.9 Rails Active Support has a possible ReDoS vulnerability in number_to_delimited ! CVE-2024-47887 6.6 Action Controller has possible ReDoS vulnerability in HTTP Token authentication ! CVE-2024-47889 6.6 Action Mailer has possible ReDoS vulnerability in block_format ! CVE-2026-33174 6.6 Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range request ! CVE-2026-33176 6.6 Rails Active Support has a possible DoS vulnerability in its number helpers ! CVE-2026-33202 6.6 Rails Active Storage has possible glob injection in its DiskService ! CVE-2020-8167 6.5 rubygem-actionview: CSRF vulnerability in rails-ujs ! CVE-2026-33170 5.3 Rails Active Support has a possible XSS vulnerability in SafeBuffer#% ! CVE-2026-33173 5.3 Rails Active Storage has possible content type bypass via metadata in direct uploads ! CVE-2020-8166 4.3 rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token ! CVE-2026-33658 2.3 Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range reques www/rubygem-rails52 rubygem-rails52-5.2.8.1 ! CVE-2026-33195 8.0 Rails Active Storage has possible Path Traversal in DiskService ! CVE-2023-22792 7.5 rubygem-actionpack: Denial of Service in Action Dispatch ! CVE-2023-22795 7.5 rubygem-actionpack: Denial of Service in Action Dispatch ! CVE-2026-33169 6.9 Rails Active Support has a possible ReDoS vulnerability in number_to_delimited ! CVE-2024-47887 6.6 Action Controller has possible ReDoS vulnerability in HTTP Token authentication ! CVE-2024-47889 6.6 Action Mailer has possible ReDoS vulnerability in block_format ! CVE-2026-33174 6.6 Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range request ! CVE-2026-33176 6.6 Rails Active Support has a possible DoS vulnerability in its number helpers ! CVE-2026-33202 6.6 Rails Active Storage has possible glob injection in its DiskService ! CVE-2024-26144 5.3 Possible Sensitive Session Information Leak in Active Storage ! CVE-2026-33170 5.3 Rails Active Support has a possible XSS vulnerability in SafeBuffer#% ! CVE-2026-33173 5.3 Rails Active Storage has possible content type bypass via metadata in direct uploads ! CVE-2026-33658 2.3 Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range reques www/rubygem-rails60 rubygem-rails60-6.0.6.1_2 ! CVE-2026-33195 8.0 Rails Active Storage has possible Path Traversal in DiskService ! CVE-2023-22795 7.5 rubygem-actionpack: Denial of Service in Action Dispatch ! CVE-2026-33169 6.9 Rails Active Support has a possible ReDoS vulnerability in number_to_delimited ! CVE-2024-47887 6.6 Action Controller has possible ReDoS vulnerability in HTTP Token authentication ! CVE-2024-47889 6.6 Action Mailer has possible ReDoS vulnerability in block_format ! CVE-2026-33174 6.6 Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range request ! CVE-2026-33176 6.6 Rails Active Support has a possible DoS vulnerability in its number helpers ! CVE-2026-33202 6.6 Rails Active Storage has possible glob injection in its DiskService ! CVE-2024-26144 5.3 Possible Sensitive Session Information Leak in Active Storage ! CVE-2026-33170 5.3 Rails Active Support has a possible XSS vulnerability in SafeBuffer#% ! CVE-2026-33173 5.3 Rails Active Storage has possible content type bypass via metadata in direct uploads ! CVE-2026-33658 2.3 Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range reques www/rubygem-rails61 rubygem-rails61-6.1.7.10 ! CVE-2026-33195 8.0 Rails Active Storage has possible Path Traversal in DiskService ! CVE-2026-33169 6.9 Rails Active Support has a possible ReDoS vulnerability in number_to_delimited ! CVE-2026-33174 6.6 Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range request ! CVE-2026-33176 6.6 Rails Active Support has a possible DoS vulnerability in its number helpers ! CVE-2026-33202 6.6 Rails Active Storage has possible glob injection in its DiskService ! CVE-2026-33170 5.3 Rails Active Support has a possible XSS vulnerability in SafeBuffer#% ! CVE-2026-33173 5.3 Rails Active Storage has possible content type bypass via metadata in direct uploads ! CVE-2026-33658 2.3 Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range reques www/rubygem-rails70 rubygem-rails70-7.0.10 ! CVE-2026-33195 8.0 Rails Active Storage has possible Path Traversal in DiskService ! CVE-2026-33169 6.9 Rails Active Support has a possible ReDoS vulnerability in number_to_delimited ! CVE-2026-33174 6.6 Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range request ! CVE-2026-33176 6.6 Rails Active Support has a possible DoS vulnerability in its number helpers ! CVE-2026-33202 6.6 Rails Active Storage has possible glob injection in its DiskService ! CVE-2026-33170 5.3 Rails Active Support has a possible XSS vulnerability in SafeBuffer#% ! CVE-2026-33173 5.3 Rails Active Storage has possible content type bypass via metadata in direct uploads ! CVE-2026-33658 2.3 Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range reques www/rubygem-rails71 rubygem-rails71-7.1.6 ! CVE-2026-33195 8.0 Rails Active Storage has possible Path Traversal in DiskService ! CVE-2026-33169 6.9 Rails Active Support has a possible ReDoS vulnerability in number_to_delimited ! CVE-2026-33174 6.6 Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range request ! CVE-2026-33176 6.6 Rails Active Support has a possible DoS vulnerability in its number helpers ! CVE-2026-33202 6.6 Rails Active Storage has possible glob injection in its DiskService ! CVE-2026-33170 5.3 Rails Active Support has a possible XSS vulnerability in SafeBuffer#% ! CVE-2026-33173 5.3 Rails Active Storage has possible content type bypass via metadata in direct uploads ! CVE-2026-33658 2.3 Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range reques www/rubygem-sinatra1 rubygem-sinatra1-1.4.8 ! CVE-2022-29970 7.5 sinatra: path traversal possible outside of public_dir when serving static files ! CVE-2018-11627 6.1 rubygem-sinatra: XSS in the 400 Bad Request page ! CVE-2025-61921 2.7 Sinatra has ReDoS vulnerability in ETag header value generation www/rubygem-sinatra2 rubygem-sinatra2-2.2.4_1 ! CVE-2025-61921 2.7 Sinatra has ReDoS vulnerability in ETag header value generation www/rubygem-sinatra3 rubygem-sinatra3-3.2.0_1 ! CVE-2025-61921 2.7 Sinatra has ReDoS vulnerability in ETag header value generation www/serendipity serendipity-2.5.0_1 ! CVE-2026-67351 8.7 Serendipity < 2.6.1 Authentication Bypass via Username Collision ! CVE-2024-58282 8.6 Serendipity 2.5.0 Remote Code Execution via Authenticated Media Upload ! CVE-2026-73629 8.4 Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses ! CVE-2026-39971 7.2 Serendipity: Host Header Injection leads to SMTP header injection via unvalidated HTTP_HOS ! CVE-2026-39963 6.9 Serendipity: Host Header Injection enables authentication cookie scoping to an attacker-co ! CVE-2026-73628 5.3 Serendipity 2.3.5 Reflected XSS via search clean-URL route ! CVE-2026-67350 2.1 Serendipity < 2.6.1 Open Redirect via exit.php www/squidguard squidGuard-1.4_15 ! CVE-2015-8936 6.1 Cross-site scripting (XSS) vulnerability in squidGuard.cgi in squidGuard before 1.5 allows ! CVE-2009-3700 5.0 squidGuard: buffer overflow in sgLog.c (CVE-2009-3700) and two URL filter bypass issues (C ! CVE-2009-3826 5.0 squidGuard: buffer overflow in sgLog.c (CVE-2009-3700) and two URL filter bypass issues (C www/tinyproxy tinyproxy-1.11.3,1 ! CVE-2026-54387 9.3 Tinyproxy - HTTP Request Smuggling via CL/TE Desynchronization ! CVE-2026-54388 9.3 Tinyproxy - HTTP Request Smuggling via Duplicate Content-Length Headers ! CVE-2026-55202 8.8 Tinyproxy - Stathost Detection Bypass via Host Header Manipulation ! CVE-2026-31842 8.7 Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding hand www/trafficserver trafficserver-10.1.0 ! CVE-2026-58154 9.2 Apache Traffic Server: Memory-safety errors in MIME and header parsing ! CVE-2026-58155 9.2 Apache Traffic Server: Header-name length truncation enables header aliasing and request s ! CVE-2026-58161 9.2 Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server ! CVE-2026-58179 9.2 Apache Traffic Server: regex_remap plugin overflows the stack from attacker input ! CVE-2026-58151 8.7 Apache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the server ! CVE-2026-58162 8.4 Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates ! CVE-2026-58188 8.4 Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins ! CVE-2026-58163 8.3 Apache Traffic Server: Cache deserialization and lifetime errors can corrupt state or cras ! CVE-2026-58164 8.3 Apache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-free ! CVE-2026-58177 8.3 Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts framework ! CVE-2026-58184 8.3 Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory ! CVE-2026-33930 8.2 Apache Traffic Server: Buffer overflow via Host field that has a long string value ! CVE-2026-58158 8.2 Apache Traffic Server: PROXY protocol parsing has port truncation and a stack overflow ! CVE-2026-58175 8.2 Apache Traffic Server: HostDB SRV handling leaks memory ! CVE-2026-58178 8.2 Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request fo ! CVE-2026-58180 8.2 Apache Traffic Server: txn_box plugin overflows the stack from attacker input ! CVE-2026-58181 8.2 Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash ! CVE-2026-58182 8.2 Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors ! CVE-2026-58183 8.2 Apache Traffic Server: prefetch plugin can crash on attacker-influenced input ! CVE-2026-58185 8.2 Apache Traffic Server: Use-after-free in the intercept plugin ! CVE-2026-58186 8.2 Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded respo ! CVE-2026-58189 8.2 Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amplification ! CVE-2026-65324 8.2 Apache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowin ! CVE-2026-58150 7.8 Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing r ! CVE-2026-33267 7.7 Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata ! CVE-2025-58136 7.5 Apache Traffic Server: A simple legitimate POST request causes a crash ! CVE-2025-65114 7.5 Apache Traffic Server: Malformed chunked message body allows request smuggling ! CVE-2026-59173 7.5 Apache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditions ! CVE-2026-41920 7.0 Apache Traffic Server: SNI to Host header matching policy is not properly enforced ! CVE-2026-57834 7.0 Apache Traffic Server: Malformed chunked message body allows request smuggling ! CVE-2026-58159 7.0 Apache Traffic Server: Listener and ACL handling allow access-control bypass ! CVE-2026-22068 6.9 Apache Traffic Server: Regex mappings match with malicious domain names ! CVE-2026-24033 6.9 Apache Traffic Server: Request smuggling via chunked extension quoted-string parsing ! CVE-2026-58152 6.9 Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrupt memory ! CVE-2026-58157 6.9 Apache Traffic Server: Improper server-session reuse can expose data across client connect ! CVE-2026-58153 6.3 Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients uns ! CVE-2026-58156 6.3 Apache Traffic Server: URL and port parsing errors allow access-control bypass ! CVE-2026-58160 6.3 Apache Traffic Server: Out-of-bounds reads while parsing DNS responses ! CVE-2026-58187 6.3 Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of service ! CVE-2026-65100 6.3 Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header ! CVE-2026-65325 6.3 Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate r www/typo3-11 typo3-11-php84-11.5.40_1 ! CVE-2024-55924 8.0 Cross-Site Request Forgery in Scheduler Module in TYPO3 ! CVE-2024-55921 7.5 Cross-Site Request Forgery in Extension Manager Module in TYPO3 ! CVE-2024-45232 7.3 An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to valid ! CVE-2024-45233 7.3 An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions i ! CVE-2025-47940 7.2 TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainer ! CVE-2025-59018 7.1 Information Disclosure in Workspaces Module ! CVE-2025-59022 7.1 TYPO3 CMS Allows Broken Access Control in Recycler Module ! CVE-2024-55922 5.4 Cross-Site Request Forgery in Form Framework Module in TYPO3 ! CVE-2025-47939 5.4 TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer ! CVE-2025-59013 5.3 Open Redirect in TYPO3 CMS ! CVE-2025-59016 5.3 Information Disclosure via File Abstraction Layer ! CVE-2025-59017 5.3 Broken Access Control in Backend AJAX Routes ! CVE-2025-59019 5.3 Information Disclosure via CSV Download ! CVE-2025-59020 5.3 TYPO3 CMS Allows Broken Access Control in Edit Document Controller ! CVE-2025-59021 5.3 TYPO3 CMS Allows Broken Access Control in Redirects Module ! CVE-2026-0859 5.2 TYPO3 CMS Allows Insecure Deserialization via Mailer File Spool ! CVE-2025-59014 5.1 Denial of Service in TYPO3 Bookmark Toolbar ! CVE-2024-55892 4.8 Potential Open Redirect via Parsing Differences in TYPO3 ! CVE-2024-55893 4.3 TYPO3 Cross-Site Request Forgery in Log Module ! CVE-2024-55894 4.3 TYPO3 Cross-Site Request Forgery in Backend User Module ! CVE-2024-55920 4.3 Cross-Site Request Forgery in Dashboard Module in TYPO3 ! CVE-2024-55923 4.3 Cross-Site Request Forgery in Indexed Search Module in TYPO3 ! CVE-2024-55945 4.3 Cross-Site Request Forgery in DB Check Module in TYPO3 ! CVE-2025-47938 3.8 TYPO3 Vulnerable to Unverified Password Change for Backend Users ! CVE-2025-47937 3.7 TYPO3 Vulnerable to Information Disclosure via DBAL Restriction Handling ! CVE-2024-55891 3.1 Information Disclosure via Exception Handling/Logger in TYPO3 www/typo3-12 typo3-12-php84-12.4.41 ! CVE-2024-55891 3.1 Information Disclosure via Exception Handling/Logger in TYPO3 www/ungoogled-chromium ungoogled-chromium-151.0.7922.169_2 ! CVE-2026-79090 9.8 Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a r ! CVE-2026-84325 9.8 Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed ! CVE-2026-87544 9.8 Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-78900 9.6 Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-78904 9.6 Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-78909 9.6 Use-After-Free in Chrome Views Enables Remote Code Execution via Crafted HTML Page ! CVE-2026-78939 9.6 Use After Free in Chromecast Allowing Remote Code Execution via Crafted HTML Page ! CVE-2026-78945 9.6 Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-78948 9.6 Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-78951 9.6 Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-78985 9.6 Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allow ! CVE-2026-79026 9.6 Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79043 9.6 Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79047 9.6 Use-After-Free in Chrome Views Enables Remote Code Execution ! CVE-2026-79052 9.6 Use-After-Free Exploit in Chrome Aura Enables Remote Code Execution ! CVE-2026-79056 9.6 Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-79078 9.6 FedCM Use‑After‑Free Enables Remote Code Execution in Chrome ! CVE-2026-79111 9.6 Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79130 9.6 Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-79131 9.6 Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79149 9.6 Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-79188 9.6 Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79189 9.6 Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79200 9.6 Use After Free in Chrome's Aura Enables Remote Code Execution via Crafted HTML Page ! CVE-2026-79232 9.6 Chrome Aura Use‑After‑Free Enables Remote Code Execution ! CVE-2026-79235 9.6 Use‑After‑Free in WebGL Enables Remote Code Execution Outside Sandbox ! CVE-2026-79257 9.6 Use After Free in Chrome Views Enables Remote Code Execution ! CVE-2026-79275 9.6 Use‑After‑Free in ANGLE Enables Remote Code Execution Outside Sandbox ! CVE-2026-79290 9.6 Use‑After‑Free in Chrome Aura Enables Remote Code Execution via Malicious HTML ! CVE-2026-84354 9.6 Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a re ! CVE-2026-85042 9.6 DevTools Use-After‑Free Allows Remote Code Execution ! CVE-2026-87448 9.6 Chrome DevTools Use-After‑Free Allows Remote Code Execution ! CVE-2026-87455 9.6 Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker t ! CVE-2026-87464 9.6 Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87474 9.6 Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87492 9.6 Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87500 9.6 Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowe ! CVE-2026-87504 9.6 Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker l ! CVE-2026-87526 9.6 Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87527 9.6 Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87529 9.6 Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87547 9.6 Chrome FileSystem Reference Resolution Vulnerability Enabling Arbitrary Code Execution ! CVE-2026-87581 9.6 Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87634 9.6 Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87638 9.6 Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote atta ! CVE-2026-87646 9.6 Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87650 9.6 Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-79058 9.1 Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79148 9.1 Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-85043 9.1 Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote att ! CVE-2026-84324 9.0 Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker ! CVE-2026-87613 9.0 Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allow ! CVE-2026-76017 8.8 Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote att ! CVE-2026-76018 8.8 chromium-browser: Google Chrome: Arbitrary Code Execution via crafted file in Import compo ! CVE-2026-76021 8.8 chromium-browser: chromium-browser: Use after free in DOM ! CVE-2026-76022 8.8 Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attac ! CVE-2026-76023 8.8 chromium-browser: chromium-browser: Improper resource control in Linux Toolkit Theming ! CVE-2026-78891 8.8 Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacke ! CVE-2026-78899 8.8 Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to ! CVE-2026-78905 8.8 Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-78910 8.8 Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to ! CVE-2026-78938 8.8 Chrome V8 Type Confusion Allows Remote Code Execution via Crafted HTML ! CVE-2026-78944 8.8 Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attack ! CVE-2026-78950 8.8 Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attack ! CVE-2026-78956 8.8 Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker lev ! CVE-2026-78963 8.8 Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-78990 8.8 Use after free in Compositing in Google Chrome prior to 152.0.7977.65 allowed a remote att ! CVE-2026-79033 8.8 Insufficient control flow management in DevTools in Google Chrome prior to 152.0.7977.65 a ! CVE-2026-79045 8.8 Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker lev ! CVE-2026-79073 8.8 Remote Code Execution in Chrome's Parser via Improper State Validation ! CVE-2026-79097 8.8 Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to ! CVE-2026-79119 8.8 Use after free in PDF in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to ! CVE-2026-79127 8.8 Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79182 8.8 Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79183 8.8 Use after free in Accessibility in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-79187 8.8 Use After Free in WebRTC Enables Remote Code Execution in Chrome ! CVE-2026-79195 8.8 Remote Code Execution via Use‑After‑Free in Chrome Script Module ! CVE-2026-79197 8.8 Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to ! CVE-2026-79198 8.8 Use‑after‑free in Chrome Platform allows arbitrary code execution from malicious HTML ! CVE-2026-79202 8.8 Chromecast Use-After-Free Enables Remote Code Execution ! CVE-2026-79209 8.8 Type confusion in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attac ! CVE-2026-79215 8.8 Integer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacke ! CVE-2026-79219 8.8 Use after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote attac ! CVE-2026-79223 8.8 Integer overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79226 8.8 Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.797 ! CVE-2026-79227 8.8 Type confusion in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attack ! CVE-2026-79231 8.8 Buffer overflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-79236 8.8 Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to ! CVE-2026-79244 8.8 Use after free in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attac ! CVE-2026-79266 8.8 Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attack ! CVE-2026-84326 8.8 chromium-browser: Chromium-browser: Arbitrary code execution via crafted HTML page ! CVE-2026-84347 8.8 Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker ! CVE-2026-84350 8.8 Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attack ! CVE-2026-85046 8.8 KEV Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to ! CVE-2026-85049 8.8 chromium-browser: skia: chromium-browser: Use after free in Skia ! CVE-2026-85051 8.8 Type Confusion in Chrome Compositing Allows Remote Code Execution ! CVE-2026-85053 8.8 CacheStorage Resource Exposure Enables Remote Code Execution in Chrome ! CVE-2026-87430 8.8 Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87433 8.8 Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87440 8.8 Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87444 8.8 chromium-browser: chromium-browser: Memory corruption in Codecs ! CVE-2026-87460 8.8 chromium-browser: chromium-browser: Use after free in Platform ! CVE-2026-87489 8.8 Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87491 8.8 KEV V8 Out‑of‑Bounds Write Enables Remote Code Execution in Chrome ! CVE-2026-87536 8.8 Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to ! CVE-2026-87542 8.8 Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87569 8.8 Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87570 8.8 Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87579 8.8 Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87587 8.8 Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to ! CVE-2026-87588 8.8 chromium-browser: chromium-browser: Use after free in Chromecast ! CVE-2026-87612 8.8 chromium-browser: chromium-browser: Type confusion in V8 ! CVE-2026-87617 8.8 Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87625 8.8 Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker lev ! CVE-2026-87636 8.8 chromium-browser: chromium-browser: Type confusion in XML ! CVE-2026-87633 8.6 Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker t ! CVE-2026-78911 8.3 Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote at ! CVE-2026-78934 8.3 Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attac ! CVE-2026-78983 8.3 Use-After-Free in Chrome's Views Allows Remote Code Execution via Crafted HTML ! CVE-2026-78999 8.3 Improper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowe ! CVE-2026-79054 8.3 Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79071 8.3 Race condition in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker wh ! CVE-2026-79109 8.3 Improper input validation in Printing in Google Chrome prior to 152.0.7977.65 allowed a re ! CVE-2026-79121 8.3 Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79155 8.3 Race condition in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79218 8.3 Incorrect authorization in Sandbox in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79224 8.3 Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79292 8.3 Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote at ! CVE-2026-84335 8.3 chromium-browser: Google Chrome TabStrip: Arbitrary Code Execution via Crafted HTML Page ! CVE-2026-84349 8.3 chromium-browser: chromium-browser: Use after free in Browser ! CVE-2026-85048 8.3 Use‑After‑Free in Chrome Compositing Enables Code Execution Outside Sandbox ! CVE-2026-87479 8.3 Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allo ! CVE-2026-87480 8.3 Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87487 8.3 Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87506 8.3 WebUI Privilege Escalation in Google Chrome via Renderer Process ! CVE-2026-87510 8.3 Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87553 8.3 Renderer Process Escalation via Improper SiteIsolation Input Validation in Chrome ! CVE-2026-87572 8.3 Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker wh ! CVE-2026-87578 8.3 Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent att ! CVE-2026-87582 8.3 Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87604 8.3 Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87628 8.3 Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacke ! CVE-2026-87639 8.3 Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-76019 8.1 Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remo ! CVE-2026-78913 8.1 Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79011 8.1 UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-79020 8.1 chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia ! CVE-2026-79027 8.1 Remote Code Execution via Use‑After‑Free in Chrome WebRTC ! CVE-2026-79072 8.1 Improper state validation in Performance in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79263 8.1 Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-87471 8.1 chromium-browser: chromium-browser: Incorrect authorization in ServiceWorker ! CVE-2026-87499 8.1 chromium-browser: chromium-browser: Incorrect authorization in Network ! CVE-2026-87505 8.1 Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-87514 8.1 Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker t ! CVE-2026-87533 8.1 Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacke ! CVE-2026-87537 8.1 Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-79245 7.7 Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who ! CVE-2026-76020 7.5 chromium-browser: chromium-browser: Race condition in V8 ! CVE-2026-78901 7.5 Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to ! CVE-2026-78906 7.5 Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-79083 7.5 Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977. ! CVE-2026-79216 7.5 Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-85045 7.5 V8 Race Condition Enabling Remote Code Execution in Chrome ! CVE-2026-87431 7.5 Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87450 7.5 Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a r ! CVE-2026-87601 7.5 Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to ! CVE-2026-79032 6.8 Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a rem ! CVE-2026-78893 6.5 Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-78897 6.5 Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remo ! CVE-2026-78907 6.5 Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a re ! CVE-2026-78914 6.5 Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote at ! CVE-2026-78947 6.5 Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote at ! CVE-2026-78955 6.5 Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed ! CVE-2026-78959 6.5 Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.6 ! CVE-2026-78960 6.5 Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote at ! CVE-2026-78967 6.5 Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-78968 6.5 Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote att ! CVE-2026-78969 6.5 Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-78975 6.5 Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote at ! CVE-2026-79005 6.5 Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowe ! CVE-2026-79017 6.5 Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79018 6.5 Information leak in FoldableAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79021 6.5 Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79023 6.5 Incorrect authorization in Editing in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79024 6.5 Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79038 6.5 Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a re ! CVE-2026-79060 6.5 Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowe ! CVE-2026-79075 6.5 Information leak in Geolocation in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-79076 6.5 Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79094 6.5 Race Condition in Google Chrome Workers Enables Privilege Escalation ! CVE-2026-79099 6.5 Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79107 6.5 Incorrect authorization in TabGroups in Google Chrome prior to 152.0.7977.65 allowed a rem ! CVE-2026-79108 6.5 UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome pri ! CVE-2026-79112 6.5 chromium-browser: skia: chromium-browser: Out of bounds read in Skia ! CVE-2026-79120 6.5 Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-79125 6.5 Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker t ! CVE-2026-79133 6.5 Incorrect authorization in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79134 6.5 Incorrect authorization in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79154 6.5 Missing authorization in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79176 6.5 UI misrepresentation in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79179 6.5 Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote at ! CVE-2026-79206 6.5 Out of bounds read in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79221 6.5 Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote at ! CVE-2026-79229 6.5 Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-79234 6.5 Injection in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to pote ! CVE-2026-79246 6.5 Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79249 6.5 Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attac ! CVE-2026-79258 6.5 chromium-browser: Google Chrome WebXR: Information disclosure via incorrect authorization ! CVE-2026-79260 6.5 Improper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a rem ! CVE-2026-79270 6.5 Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-79271 6.5 Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-79291 6.5 Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-79293 6.5 Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote att ! CVE-2026-84332 6.5 Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a ! CVE-2026-84348 6.5 Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote ! CVE-2026-84357 6.5 chromium-browser: chromium-browser: Improper input validation in Omnibox ! CVE-2026-87429 6.5 Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a r ! CVE-2026-87436 6.5 Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87437 6.5 Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87441 6.5 Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87443 6.5 chromium-browser: chromium-browser: Missing authorization in Actor ! CVE-2026-87446 6.5 Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87447 6.5 Chrome Network Authorization Bypass via Extension ! CVE-2026-87459 6.5 Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87475 6.5 chromium-browser: chromium-browser: Missing authorization in Omnibox ! CVE-2026-87476 6.5 chromium-browser: chromium-browser: Incorrect authorization in Loader ! CVE-2026-87477 6.5 Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87478 6.5 Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87490 6.5 Information leak in Transactions Platform in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87513 6.5 Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87515 6.5 Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87523 6.5 Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87532 6.5 Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87541 6.5 Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87549 6.5 Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87593 6.5 Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87620 6.5 Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87623 6.5 Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87629 6.5 Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87631 6.5 Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote atta ! CVE-2026-79013 5.9 Remote Sensitive Data Disclosure via Malicious Sync Traffic in Google Chrome ! CVE-2026-79122 5.9 Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attack ! CVE-2026-79208 5.9 Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote at ! CVE-2026-78898 5.4 Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a rem ! CVE-2026-78912 5.4 UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-78974 5.4 UI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allo ! CVE-2026-79088 5.4 Incorrect Authorization in Chrome FileSystem API Allows Unauthorized File Access ! CVE-2026-79173 5.4 UI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0.7977.65 allowed a r ! CVE-2026-79250 5.4 UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79283 5.4 Google Chrome UI Spoofing via Geometry Rendering ! CVE-2026-87445 5.4 UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87458 5.4 UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87462 5.4 UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87484 5.4 UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87496 5.4 UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87501 5.4 chromium-browser: chromium-browser: UI misrepresentation in Passwords ! CVE-2026-87507 5.4 UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87540 5.4 Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87567 5.4 UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-87571 5.4 Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87575 5.4 Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87599 5.4 Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-87615 5.4 Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87635 5.4 chromium-browser: chromium-browser: UI misrepresentation in Payments ! CVE-2026-87645 5.4 chromium-browser: chromium-browser: Improper state validation in Safebrowsing ! CVE-2026-87649 5.4 UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87655 5.4 Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87656 5.4 Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed ! CVE-2026-78991 5.3 Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79028 5.3 Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79030 5.3 Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79074 5.3 Remote renderer compromise enables network information leakage in Chrome <152.0.7977.65 ! CVE-2026-79104 5.3 Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-79147 5.3 Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-79181 5.3 Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote at ! CVE-2026-79196 5.3 Race condition in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacke ! CVE-2026-79220 5.3 Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attac ! CVE-2026-79242 5.3 Chrome HTML Discrepancy Allows Remote Sensitive Information Leakage ! CVE-2026-79265 5.3 Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79287 5.3 Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-84323 5.3 chromium-browser: chromium-browser: Missing authorization in FileSystem ! CVE-2026-87435 5.3 Information Leak via ControlledFrame in Google Chrome ! CVE-2026-87439 5.3 Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87453 5.3 Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87566 5.3 chromium-browser: chromium-browser: Observable discrepancy in Layout ! CVE-2026-87594 5.3 Incorrect authorization in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87605 5.3 Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87641 5.3 Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacke ! CVE-2026-87568 4.8 Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-78895 4.3 Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacke ! CVE-2026-78896 4.3 Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a rem ! CVE-2026-78908 4.3 Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attack ! CVE-2026-78940 4.3 Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-78942 4.3 Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-78946 4.3 Same-origin policy bypass via Select element in Google Chrome ! CVE-2026-78954 4.3 Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a re ! CVE-2026-78961 4.3 Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-78962 4.3 Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-78965 4.3 Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-78966 4.3 Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-78976 4.3 Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allo ! CVE-2026-78980 4.3 Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-78987 4.3 Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attack ! CVE-2026-79000 4.3 Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0 ! CVE-2026-79003 4.3 Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79006 4.3 Protection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allo ! CVE-2026-79009 4.3 UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attack ! CVE-2026-79010 4.3 Operation on a resource after expiration or release in Network in Google Chrome prior to 1 ! CVE-2026-79014 4.3 Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attack ! CVE-2026-79015 4.3 Improper input validation in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed ! CVE-2026-79016 4.3 Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote att ! CVE-2026-79022 4.3 UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allo ! CVE-2026-79049 4.3 Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65 allowe ! CVE-2026-79050 4.3 Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79051 4.3 Incorrect authorization in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79065 4.3 Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a rem ! CVE-2026-79067 4.3 Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79068 4.3 Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79070 4.3 Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79077 4.3 Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a re ! CVE-2026-79082 4.3 Incorrect authorization in Transactions Platform in Google Chrome prior to 152.0.7977.65 a ! CVE-2026-79085 4.3 Renderer Process Authorization Bypass Allows Origin Policy Circumvention in Google Chrome ! CVE-2026-79087 4.3 Injection in Chrome Tabs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-79093 4.3 Incorrect authorization in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79095 4.3 Information leak in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79098 4.3 UI misrepresentation in PermissionElement in Google Chrome prior to 152.0.7977.65 allowed ! CVE-2026-79106 4.3 Improper input validation in Input in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79110 4.3 Missing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79116 4.3 Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote atta ! CVE-2026-79118 4.3 Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote a ! CVE-2026-79136 4.3 Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79137 4.3 Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a re ! CVE-2026-79141 4.3 Incorrect authorization in Browser in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79143 4.3 Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a re ! CVE-2026-79144 4.3 chromium-browser: skia: chromium-browser: Information leak in Skia ! CVE-2026-79151 4.3 Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed ! CVE-2026-79174 4.3 Chrome Extension Authorization Bypass Enabling Unauthorized Privileged Page Access ! CVE-2026-79178 4.3 Incorrect authorization in Web Authentication (Passkeys & Security Keys) in Google Chrome ! CVE-2026-79184 4.3 Missing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79185 4.3 Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-79190 4.3 Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a re ! CVE-2026-79192 4.3 Improper input validation in Variations in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79193 4.3 Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attack ! CVE-2026-79199 4.3 Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79201 4.3 Improper access control in Workers in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79205 4.3 Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79211 4.3 Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote at ! CVE-2026-79212 4.3 Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79214 4.3 Improper input validation in Preload in Google Chrome prior to 152.0.7977.65 allowed a rem ! CVE-2026-79237 4.3 Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.65 allowed a re ! CVE-2026-79238 4.3 Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79248 4.3 Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79251 4.3 Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a rem ! CVE-2026-79252 4.3 Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote ! CVE-2026-79259 4.3 Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed ! CVE-2026-79261 4.3 Incorrect authorization in Controls in Google Chrome prior to 152.0.7977.65 allowed a remo ! CVE-2026-79262 4.3 Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79264 4.3 Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed ! CVE-2026-79267 4.3 Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacke ! CVE-2026-79269 4.3 chromium-browser: Chromium: Web origin policy bypass via uninitialized resource in ANGLE ! CVE-2026-79274 4.3 Information leak in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-79276 4.3 chromium-browser: Google Chrome: Privilege management bypass via crafted HTML page ! CVE-2026-84356 4.3 chromium-browser: chromium-browser: UI misrepresentation in FullScreen ! CVE-2026-87449 4.3 Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153. ! CVE-2026-87461 4.3 Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87466 4.3 Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87495 4.3 Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87497 4.3 chromium-browser: chromium-browser: Uninitialized resource in Codecs ! CVE-2026-87508 4.3 Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87516 4.3 Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87543 4.3 Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87548 4.3 Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a r ! CVE-2026-87550 4.3 Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 all ! CVE-2026-87551 4.3 Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87556 4.3 Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87557 4.3 Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8010.36 allowe ! CVE-2026-87560 4.3 Chrome Browser Authorization Bypass via Crafted HTML Page ! CVE-2026-87561 4.3 Incorrect authorization in Web Authentication in Google Chrome prior to 153.0.8010.36 allo ! CVE-2026-87563 4.3 Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87564 4.3 chromium-browser: chromium-browser: Type confusion in V8 ! CVE-2026-87573 4.3 Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87574 4.3 chromium-browser: chromium-browser: Information leak in ServiceWorker ! CVE-2026-87577 4.3 Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87586 4.3 Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87592 4.3 Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87596 4.3 Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attac ! CVE-2026-87598 4.3 chromium-browser: chromium-browser: Incorrect authorization in ServiceWorker ! CVE-2026-87619 4.3 chromium-browser: chromium-browser: Observable discrepancy in Prefetch ! CVE-2026-87622 4.3 Missing authorization in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-87630 4.3 Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87632 4.3 Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 allowed a rem ! CVE-2026-87642 4.3 Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87651 4.3 Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87658 4.3 Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote at ! CVE-2026-79025 4.2 Improper input validation in Workers in Google Chrome prior to 152.0.7977.65 allowed a rem ! CVE-2026-84358 4.2 chromium-browser: chromium-browser: Improper privilege management in Downloads ! CVE-2026-87432 4.2 Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a re ! CVE-2026-87465 4.2 chromium-browser: chromium-browser: Incorrect authorization in Downloads ! CVE-2026-87472 4.2 Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87502 4.2 Confused Deputy in Chrome Fullscreen Allows UI Spoofing via Compromised Renderer ! CVE-2026-87538 4.2 Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker wh ! CVE-2026-87559 4.2 UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-78984 3.4 Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote att ! CVE-2026-79004 3.4 Out of bounds read in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attac ! CVE-2026-87456 3.4 Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87647 3.4 Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-78894 3.1 Race Condition in Chrome Payments Module Enables Cross‑Origin Data Leakage ! CVE-2026-78903 3.1 Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remo ! CVE-2026-78941 3.1 Information leak in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker ! CVE-2026-78943 3.1 Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a rem ! CVE-2026-78953 3.1 Site Isolation Bypass via Crafted PDF in Google Chrome ! CVE-2026-78958 3.1 chromium-browser: skia: chromium-browser: Uninitialized resource in Skia ! CVE-2026-78986 3.1 Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote att ! CVE-2026-79002 3.1 Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79007 3.1 Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote att ! CVE-2026-79031 3.1 Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a re ! CVE-2026-79034 3.1 CORS Failure Enables Cross‑Origin Data Leak in Chrome Prior to v152.0.7977.65 ! CVE-2026-79053 3.1 Missing authorization in Lighthouse in Google Chrome prior to 152.0.7977.65 allowed a remo ! CVE-2026-79059 3.1 Information leak in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attac ! CVE-2026-79066 3.1 Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79103 3.1 Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79186 3.1 Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remot ! CVE-2026-79191 3.1 Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79203 3.1 Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a re ! CVE-2026-79228 3.1 Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79255 3.1 Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remo ! CVE-2026-79272 3.1 Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a ! CVE-2026-79289 3.1 Improper control of a resource through its lifetime in Workers in Google Chrome prior to 1 ! CVE-2026-84328 3.1 chromium-browser: Google Chrome: Web origin policy bypass due to missing authorization ! CVE-2026-84331 3.1 Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote ! CVE-2026-84355 3.1 chromium-browser: chromium-browser: Incorrect authorization in Navigation ! CVE-2026-84359 3.1 chromium-browser: chromium-browser: Information leak in Skia ! CVE-2026-85052 3.1 Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a rem ! CVE-2026-87434 3.1 Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87442 3.1 Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote atta ! CVE-2026-87451 3.1 Information leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote att ! CVE-2026-87485 3.1 Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote a ! CVE-2026-87498 3.1 chromium-browser: chromium-browser: Missing authorization in WebUI ! CVE-2026-87521 3.1 Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attack ! CVE-2026-87531 3.1 Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker ! CVE-2026-87539 3.1 Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote ! CVE-2026-87611 3.1 Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remo ! CVE-2026-87614 3.1 Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a ! CVE-2026-87652 3.1 Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remot ! CVE-2026-87657 3.1 chromium-browser: chromium-browser: Use after free in V8 www/varnish7 varnish7-7.7.3_1 ! CVE-2023-44487 7.5 KEV HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset A www/webkit2-gtk webkit2-gtk_60-2.46.6_8 ! CVE-2025-43342 9.8 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process cr ! CVE-2025-43343 9.8 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process cr ! CVE-2025-31277 8.8 KEV webkitgtk: Processing maliciously crafted web content may lead to memory corruption ! CVE-2025-6558 8.8 KEV chromium-browser: Chromium insufficient validation www/wordpress wordpress-7.1,1 ! CVE-2026-64638 8.9 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. www/xoops xoops-2.5.10 ! CVE-2023-36217 9.0 Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execu ! CVE-2019-16683 4.8 An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing ! CVE-2019-16684 4.8 An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaSc www/yarn-node20 yarn-node20-1.22.19_1 ! CVE-2025-8262 5.3 yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redos ! CVE-2025-9308 4.8 yarnpkg Yarn request-manager.js setOptions redos www/yarn-node22 yarn-node22-1.22.19_1 ! CVE-2025-8262 5.3 yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redos ! CVE-2025-9308 4.8 yarnpkg Yarn request-manager.js setOptions redos www/yarn-node24 yarn-node24-1.22.19_1 ! CVE-2025-8262 5.3 yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redos ! CVE-2025-9308 4.8 yarnpkg Yarn request-manager.js setOptions redos www/yarn-node26 yarn-node26-1.22.19_1 ! CVE-2025-8262 5.3 yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redos ! CVE-2025-9308 4.8 yarnpkg Yarn request-manager.js setOptions redos x11-fonts/libXfont libXfont-1.5.4_3,2 ! CVE-2026-56002 8.5 libXfont2 PCF Font Parsing Heap Buffer Overflow x11-fonts/linux-c7-fontconfig linux-c7-fontconfig-2.13.0 ! CVE-2026-34085 5.9 fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash x11-fonts/linux-rl9-fontconfig linux-rl9-fontconfig-2.14.0_2 ! CVE-2026-34085 5.9 fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash x11-servers/xorg-server xorg-server-21.1.24,1 ! CVE-2026-56000 9.0 xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent() ! CVE-2026-55999 8.5 xorg-server / xwayland glamor font atlas Heap Buffer Overflow ! CVE-2023-5574 7.0 Xorg-x11-server: use-after-free bug in damagedestroy x11-toolkits/gstreamer1-plugins-gtk gstreamer1-plugins-gtk-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p x11-toolkits/gstreamer1-plugins-pango gstreamer1-plugins-pango-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p x11-toolkits/gstreamer1-plugins-qt5 gstreamer1-plugins-qt5-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p x11-toolkits/gstreamer1-plugins-qt6 gstreamer1-plugins-qt6-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p x11-toolkits/gtk20 gtk2-2.24.33_1 ! CVE-2014-1949 7.2 GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other app x11-toolkits/linux-c7-gtk2 linux-c7-gtk2-2.24.31_1 ! CVE-2014-1949 7.2 GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other app x11-toolkits/linux-c7-pango linux-c7-pango-1.42.4_2 ! CVE-2019-1010238 9.8 pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow x11-toolkits/linux-c7-qt-x11 linux-c7-qt-x11-4.8.7_5 ! CVE-2017-10904 9.8 Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via ! CVE-2018-19873 9.8 qt5-qtbase: QBmpHandler segmentation fault on malformed BMP file ! CVE-2024-36048 9.8 qtnetworkauth: badly seeded PRNG may result in guessable values ! CVE-2015-1290 8.8 The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in ! CVE-2018-19870 8.8 qt5-qtbase: QImage allocation failure in qgifhandler ! CVE-2024-39936 8.6 qtbase: qtbase: Delay any communication until encrypted() can be responded to ! CVE-2025-5455 8.4 Possible denial of service when passing malformed data in a URL to qDecodeDataUrl ! CVE-2018-21035 7.5 qt5-qtwebsockets: websocket implementation allows only limited size for frames and message ! CVE-2022-25634 7.5 qt: allows loading of system library files from an unintended working directory. ! CVE-2023-32763 7.5 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x be ! CVE-2023-37369 7.5 qtbase: buffer overflow in QXmlStreamReader ! CVE-2023-38197 7.5 qtbase: infinite loops in QXmlStreamReader ! CVE-2020-0570 7.3 qt: files placed by attacker can influence the working directory and lead to malicious cod ! CVE-2025-4211 7.3 Improper Link Resolution Before File Access in QFileSystemEngine on Windows ! CVE-2018-19869 6.5 qt5-qtsvg: Invalid parsing of malformed url reference resulting in a denial of service ! CVE-2018-19871 6.5 qt5-qtimageformats: QTgaFile CPU exhaustion ! CVE-2023-32573 6.5 qt: Uninitialized variable usage in m_unitsPerEm ! CVE-2026-9499 6.3 Out-of-bounds read in QTextCodec::codecForName() in Qt ! CVE-2025-30348 5.8 encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy an ! CVE-2017-10905 5.3 A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attacke ! CVE-2020-17507 5.3 qt: buffer over-read in read_xbm_body in gui/image/qxbmhandler.cpp ! CVE-2014-0190 4.3 qt: NULL pointer dereference flaw in QGIFFormat::fillRect ! CVE-2025-23050 3.1 qt: qt5: qt6: Qt missing length checks ! CVE-2026-15037 2.9 XML injection vulnerability in QDom comment, CDATA and processing-instruction serializatio x11-toolkits/linux-rl9-gtk2 linux-rl9-gtk2-2.24.33 ! CVE-2014-1949 7.2 GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other app x11-toolkits/plib plib-1.8.5_8 ! CVE-2021-38714 8.8 In Plib through 1.85, there is an integer overflow vulnerability that could result in arbi x11-toolkits/vte vte-0.28.2_4 ! CVE-2012-2738 4.0 vte: DoS (long loop) via escape sequences with large repeat counts x11-wm/fvwm3 fvwm3-1.1.5_4 ! CVE-2003-1308 4.6 CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x ! CVE-2006-5969 4.6 CRLF injection vulnerability in the evalFolderLine function in fvwm 2.5.18 and earlier all x11/gstreamer1-plugins-x gstreamer1-plugins-x-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p x11/gstreamer1-plugins-ximagesrc gstreamer1-plugins-ximagesrc-1.28.6 ! CVE-2026-73433 6.6 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd p x11/libinput libinput-1.31.1 ! CVE-2026-50292 7.4 libinput: local privilege escalation via crafted uinput devices x11/linux-c7-libxkbcommon linux-c7-libxkbcommon-0.7.1_1 ! CVE-2018-15857 7.8 libxkbcommon: Invalid free in ExprAppendMultiKeysymList resulting in a crash ! CVE-2018-15853 5.5 libxkbcommon: Endless recursion in xkbcomp/expr.c resulting in a crash ! CVE-2018-15858 5.5 libxkbcommon: NULL pointer dereference when handling invalid aliases in CopyKeyAliasesToKe ! CVE-2018-15859 5.5 libxkbcommon: NULL pointer dereference when parsing invalid atoms in ExprResolveLhs result ! CVE-2018-15861 5.5 libxkbcommon: NULL pointer dereference in ExprResolveLhs resulting in a crash ! CVE-2018-15862 5.5 libxkbcommon: NULL pointer dereference in LookupModMask resulting in a crash ! CVE-2018-15863 5.5 libxkbcommon: NULL pointer dereference in ResolveStateAndPredicate resulting in a crash ! CVE-2018-15864 5.5 libxkbcommon: NULL pointer dereference in resolve_keysym resulting in a crash x11/linux-c7-pixman linux-c7-pixman-0.34.0 ! CVE-2022-44638 8.8 pixman: Integer overflow in pixman_sample_floor_y leading to heap out-of-bounds write x11/linux-rl9-pixman linux-rl9-pixman-0.40.0_2 ! CVE-2022-44638 8.8 pixman: Integer overflow in pixman_sample_floor_y leading to heap out-of-bounds write x11/nvidia-driver-304 nvidia-driver-304-304.137_11 ! CVE-2015-5950 6.9 The NVIDIA display driver R352 before 353.82 and R340 before 341.81 on Windows; R304 befor x11/nvidia-driver-340 nvidia-driver-340-340.108_5 ! CVE-2016-4959 7.5 For the NVIDIA Quadro, NVS, and GeForce products, there is a Remote Desktop denial of serv ! CVE-2015-5950 6.9 The NVIDIA display driver R352 before 353.82 and R340 before 341.81 on Windows; R304 befor ! CVE-2016-5025 6.6 For the NVIDIA Quadro, NVS, and GeForce products, improper sanitization of parameters in t 35143 port(s): 3350 with CPE, 767 affected, 0 with only unconfirmed CVEs, 296 with no known CVEs; 31793 without CPE info, 0 make error(s). 96 finding(s) for disputed CVEs hidden (--include-disputed). 352 link(s) to CVEs rejected by their CNA skipped. ! = affected (CNA ranges, else NVD CPE data) ? = linked CVE without usable version data