Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47944
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-70456 | HIGH | 8.2 | rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending … | Aug 13, 2026 |
| CVE-2026-70455 | HIGH | 7.5 | rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias … | Aug 13, 2026 |
| CVE-2026-70454 | HIGH | 8.0 | rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted … | Aug 13, 2026 |
| CVE-2026-70453 | HIGH | 7.5 | rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering … | Aug 13, 2026 |
| CVE-2026-70452 | HIGH | 7.4 | rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during … | Aug 13, 2026 |
| CVE-2026-6387 | HIGH | 7.0 | A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges. | Aug 13, 2026 |
| CVE-2026-68454 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to … | Aug 13, 2026 |
| CVE-2026-68453 | HIGH | 7.1 | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size … | Aug 13, 2026 |
| CVE-2026-68452 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key requests cca_cipher2protkey() derives the copy length for … | Aug 13, 2026 |
| CVE-2026-68451 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA ECC private key requests cca_ecc2protkey() derives the copy length for … | Aug 13, 2026 |
| CVE-2026-66256 | HIGH | 7.2 | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the … | Aug 13, 2026 |
| CVE-2026-65936 | UNKNOWN | — | A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below. | Aug 13, 2026 |
| CVE-2026-65935 | UNKNOWN | — | Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value. See vulnerability B-E3 in the … | Aug 13, 2026 |
| CVE-2026-65934 | UNKNOWN | — | An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module. See vulnerability B-E10 in the related paper below. | Aug 13, 2026 |
| CVE-2026-65933 | UNKNOWN | — | A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below. | Aug 13, 2026 |
| CVE-2026-65932 | UNKNOWN | — | The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related … | Aug 13, 2026 |
| CVE-2026-63426 | HIGH | 7.1 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary … | Aug 13, 2026 |
| CVE-2026-63425 | HIGH | 7.8 | During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute … | Aug 13, 2026 |
| CVE-2026-63424 | HIGH | 7.3 | During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges. | Aug 13, 2026 |
| CVE-2026-63423 | HIGH | 7.8 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local … | Aug 13, 2026 |
| CVE-2026-53803 | HIGH | 7.8 | rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path … | Aug 13, 2026 |
| CVE-2026-53802 | HIGH | 7.1 | rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following … | Aug 13, 2026 |
| CVE-2026-53801 | MEDIUM | 5.9 | rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender to enumerate and … | Aug 13, 2026 |
| CVE-2026-53800 | MEDIUM | 4.7 | rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows attackers with symlink creation access to cause arbitrary file deletion. … | Aug 13, 2026 |
| CVE-2026-53799 | MEDIUM | 6.3 | rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended … | Aug 13, 2026 |