Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47882
Total
3850
Critical
14243
High
13921
Medium
CVE ID Severity Score Description Published
CVE-2026-73509 HIGH 7.6 OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by … Aug 13, 2026
CVE-2026-73508 MEDIUM 5.3 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf … Aug 13, 2026
CVE-2026-73507 HIGH 7.5 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated … Aug 13, 2026
CVE-2026-73506 MEDIUM 6.1 Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names … Aug 13, 2026
CVE-2026-73505 HIGH 7.8 Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes … Aug 13, 2026
CVE-2026-70464 HIGH 7.5 rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake … Aug 13, 2026
CVE-2026-70463 HIGH 8.1 rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, … Aug 13, 2026
CVE-2026-70462 MEDIUM 6.5 rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting … Aug 13, 2026
CVE-2026-70461 HIGH 8.2 rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a … Aug 13, 2026
CVE-2026-70460 HIGH 8.1 rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module … Aug 13, 2026
CVE-2026-70459 MEDIUM 5.3 rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending … Aug 13, 2026
CVE-2026-70458 HIGH 8.2 rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED … Aug 13, 2026
CVE-2026-70457 MEDIUM 6.5 rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a .bss-segment … Aug 13, 2026
CVE-2026-70456 HIGH 8.2 rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending … Aug 13, 2026
CVE-2026-70455 HIGH 7.5 rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias … Aug 13, 2026
CVE-2026-70454 HIGH 8.0 rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted … Aug 13, 2026
CVE-2026-70453 HIGH 7.5 rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering … Aug 13, 2026
CVE-2026-70452 HIGH 7.4 rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during … Aug 13, 2026
CVE-2026-6387 HIGH 7.0 A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges. Aug 13, 2026
CVE-2026-68454 HIGH 8.8 In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to … Aug 13, 2026
CVE-2026-68453 HIGH 7.1 In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size … Aug 13, 2026
CVE-2026-68452 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key requests cca_cipher2protkey() derives the copy length for … Aug 13, 2026
CVE-2026-68451 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA ECC private key requests cca_ecc2protkey() derives the copy length for … Aug 13, 2026
CVE-2026-66256 HIGH 7.2 ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the … Aug 13, 2026
CVE-2026-65936 UNKNOWN A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below. Aug 13, 2026