Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44793
Total
3597
Critical
13314
High
13164
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16944 | MEDIUM | 6.7 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow. | Aug 20, 2026 |
| CVE-2026-16943 | HIGH | 8.2 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a heap-based buffer overflow. | Aug 20, 2026 |
| CVE-2026-16937 | HIGH | 7.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management. | Aug 20, 2026 |
| CVE-2026-16936 | HIGH | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow. | Aug 20, 2026 |
| CVE-2026-16935 | HIGH | 7.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a time-of-check to time-of-use … | Aug 20, 2026 |
| CVE-2026-16934 | HIGH | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap-based buffer overflow. | Aug 20, 2026 |
| CVE-2025-52182 | UNKNOWN | — | The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability. | Aug 20, 2026 |
| CVE-2026-77641 | MEDIUM | 6.5 | tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so … | Aug 20, 2026 |
| CVE-2026-77640 | LOW | 3.7 | tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib … | Aug 20, 2026 |
| CVE-2026-77639 | MEDIUM | 5.3 | Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream … | Aug 20, 2026 |
| CVE-2026-77638 | HIGH | 8.9 | Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that … | Aug 20, 2026 |
| CVE-2026-77587 | MEDIUM | 5.9 | Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose … | Aug 20, 2026 |
| CVE-2026-77584 | HIGH | 7.0 | Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a … | Aug 20, 2026 |
| CVE-2026-77506 | MEDIUM | 4.8 | Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS. | Aug 20, 2026 |
| CVE-2026-76023 | UNKNOWN | — | Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute … | Aug 20, 2026 |
| CVE-2026-76022 | UNKNOWN | — | Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML … | Aug 20, 2026 |
| CVE-2026-76021 | UNKNOWN | — | Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … | Aug 20, 2026 |
| CVE-2026-76020 | UNKNOWN | — | Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Aug 20, 2026 |
| CVE-2026-76019 | UNKNOWN | — | Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to … | Aug 20, 2026 |
| CVE-2026-76018 | UNKNOWN | — | Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox … | Aug 20, 2026 |
| CVE-2026-76017 | UNKNOWN | — | Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network … | Aug 20, 2026 |
| CVE-2026-75484 | UNKNOWN | — | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated remote attacker to smuggle CR, LF, or NUL characters into application-visible … | Aug 20, 2026 |
| CVE-2026-74836 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an unbounded number of HTTP/2 stream processes … | Aug 20, 2026 |
| CVE-2026-73137 | HIGH | 7.7 | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability … | Aug 20, 2026 |
| CVE-2026-73040 | HIGH | 8.8 | Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is … | Aug 20, 2026 |