Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51667
Total
4097
Critical
15338
High
14987
Medium
CVE ID Severity Score Description Published
CVE-2026-55990 MEDIUM 5.9 In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound … Jul 22, 2026
CVE-2026-55973 HIGH 7.5 In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream … Jul 22, 2026
CVE-2026-55717 MEDIUM 5.9 In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' … Jul 22, 2026
CVE-2026-55708 LOW 3.1 In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an … Jul 22, 2026
CVE-2026-54478 LOW 3.7 In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash … Jul 22, 2026
CVE-2026-53910 UNKNOWN — diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping … Jul 22, 2026
CVE-2026-52863 MEDIUM 5.9 In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy … Jul 22, 2026
CVE-2026-50252 UNKNOWN — In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases … Jul 22, 2026
CVE-2026-50251 MEDIUM 5.3 In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 … Jul 22, 2026
CVE-2026-50248 MEDIUM 6.5 In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it … Jul 22, 2026
CVE-2026-50243 UNKNOWN — In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with … Jul 22, 2026
CVE-2026-50046 MEDIUM 5.9 In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's … Jul 22, 2026
CVE-2026-50045 MEDIUM 5.3 In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause … Jul 22, 2026
CVE-2026-46582 LOW 3.7 In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered … Jul 22, 2026
CVE-2026-44690 HIGH 7.5 In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive … Jul 22, 2026
CVE-2026-44687 LOW 3.7 In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC … Jul 22, 2026
CVE-2026-44621 MEDIUM 5.9 With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold … Jul 22, 2026
CVE-2026-42955 LOW 3.7 In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was … Jul 22, 2026
CVE-2026-41637 LOW 3.7 In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation … Jul 22, 2026
CVE-2026-40691 HIGH 7.5 In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails … Jul 22, 2026
CVE-2026-32665 HIGH 7.5 In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC … Jul 22, 2026
CVE-2026-16560 MEDIUM 5.3 A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another … Jul 22, 2026
CVE-2026-16232 CRITICAL 9.1 An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it … Jul 22, 2026
CVE-2026-14932 MEDIUM 6.5 In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension … Jul 22, 2026
CVE-2026-14865 MEDIUM 5.3 In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service … Jul 22, 2026