Tue, May 26 · 02:16 PM CDTCVE-2026-7374
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container r
CVECVE-2026-7374
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 26 · 02:16 PM CDT
ModifiedSun, Aug 02 · 01:16 PM CDT
Sun, Aug 02 · 03:16 PM CDTCVE-2026-65321
9.8/10 · Must read/watchNVDvuln
Summary
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than
CVECVE-2026-65321
SeverityCRITICAL
TypeNEW
PublishedSun, Aug 02 · 03:16 PM CDT
ModifiedSun, Aug 02 · 03:16 PM CDT
Sun, Aug 02 · 01:16 PM CDTCVE-2026-68579
9.6/10 · Must read/watchNVDvuln
Summary
FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests file contents from the
CVECVE-2026-68579
SeverityCRITICAL
TypeNEW
PublishedSun, Aug 02 · 01:16 PM CDT
ModifiedSun, Aug 02 · 01:16 PM CDT
Mon, Jul 20 · 08:16 AM CDTCVE-2026-16242
9.4/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could co
CVECVE-2026-16242
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jul 20 · 08:16 AM CDT
ModifiedSun, Aug 02 · 12:16 PM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49794
9.1/10 · Must read/watchNVDvuln
Summary
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or
CVECVE-2025-49794
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedSun, Aug 02 · 07:16 PM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49796
9.1/10 · Must read/watchNVDvuln
Summary
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive
CVECVE-2025-49796
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedSun, Aug 02 · 07:16 PM CDT
Wed, Feb 12 · 03:15 PM CSTCVE-2025-1244
8.8/10 · Worth your timeNVDvuln
Summary
A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.
CVECVE-2025-1244
SeverityHIGH
TypeUPDATED
PublishedWed, Feb 12 · 03:15 PM CST
ModifiedSun, Aug 02 · 05:16 PM CDT
Tue, Jun 02 · 09:16 AM CDTCVE-2026-1784
8.8/10 · Worth your timeNVDvuln
Summary
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVECVE-2026-1784
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 02 · 09:16 AM CDT
ModifiedSun, Aug 02 · 11:16 AM CDT
Thu, Jul 02 · 12:16 PM CDTCVE-2026-27060
8.8/10 · Worth your timeNVDvuln
Summary
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This issue affects ARMember Premium: from n/a before 7.6.
CVECVE-2026-27060
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 02 · 12:16 PM CDT
ModifiedMon, Aug 03 · 10:16 AM CDT
Mon, Jun 15 · 08:16 PM CDTCVE-2026-52720
8.8/10 · Worth your timeNVDvuln
Summary
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server a
CVECVE-2026-52720
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 15 · 08:16 PM CDT
ModifiedMon, Aug 03 · 10:16 AM CDT
Thu, Jul 16 · 02:16 PM CDTCVE-2026-5674
8.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code
CVECVE-2026-5674
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 16 · 02:16 PM CDT
ModifiedMon, Aug 03 · 08:17 AM CDT
Sun, Jul 19 · 04:17 PM CDTCVE-2026-63923
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify rvu_mbox_handler_rep_event_notify() in drivers/net/ethernet/marvell/ octeontx2/af/rvu_rep.c queues a sender-controlled REP_EVENT_NOTIFY request body verbatim, and rvu_rep_up_notif
CVECVE-2026-63923
SeverityHIGH
TypeUPDATED
PublishedSun, Jul 19 · 04:17 PM CDT
ModifiedMon, Aug 03 · 10:16 AM CDT
Sat, Jul 25 · 10:17 AM CDTCVE-2026-64280
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() afu_ioctl_dma_map() accepts a 64-bit length from userspace via DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value is passed to afu_dma_pin_pages() where npages is deriv
CVECVE-2026-64280
SeverityHIGH
TypeUPDATED
PublishedSat, Jul 25 · 10:17 AM CDT
ModifiedMon, Aug 03 · 10:16 AM CDT
Sun, Aug 02 · 01:16 PM CDTCVE-2026-67356
8.8/10 · Worth your timeNVDvuln
Summary
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, esc
CVECVE-2026-67356
SeverityHIGH
TypeNEW
PublishedSun, Aug 02 · 01:16 PM CDT
ModifiedSun, Aug 02 · 01:16 PM CDT
Sun, Aug 02 · 01:16 PM CDTCVE-2025-71399
8.6/10 · Worth your timeNVDvuln
Summary
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disable
CVECVE-2025-71399
SeverityHIGH
TypeNEW
PublishedSun, Aug 02 · 01:16 PM CDT
ModifiedSun, Aug 02 · 01:16 PM CDT
Fri, Jul 24 · 07:16 PM CDTCVE-2026-17107
8.5/10 · Worth your timeNVDvuln
Summary
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unre
CVECVE-2026-17107
SeverityHIGH
TypeUPDATED
PublishedFri, Jul 24 · 07:16 PM CDT
ModifiedSun, Aug 02 · 12:16 PM CDT
Thu, Jul 23 · 12:18 PM CDTCVE-2026-65526
8.5/10 · Worth your timeNVDvuln
Summary
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.
CVECVE-2026-65526
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 23 · 12:18 PM CDT
ModifiedMon, Aug 03 · 10:16 AM CDT
Tue, Jun 24 · 02:15 PM CDTCVE-2025-5318
8.1/10 · Worth your timeNVDvuln
Summary
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This
CVECVE-2025-5318
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 24 · 02:15 PM CDT
ModifiedSun, Aug 02 · 01:16 PM CDT
Sun, Aug 02 · 01:16 PM CDTCVE-2026-68581
8.1/10 · Worth your timeNVDvuln
Summary
Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treated as that user by t
CVECVE-2026-68581
SeverityHIGH
TypeNEW
PublishedSun, Aug 02 · 01:16 PM CDT
ModifiedSun, Aug 02 · 01:16 PM CDT
Mon, Jul 29 · 05:15 PM CDTCVE-2024-42088
7.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link Commit e70b8dd26711 ("ASoC: mediatek: mt8195: Remove afe-dai component and rework codec link") removed the codec entry for the ETDM1_OUT_BE dai link entirely instead of replacing it w
CVECVE-2024-42088
SeverityHIGH
TypeUPDATED
PublishedMon, Jul 29 · 05:15 PM CDT
ModifiedMon, Aug 03 · 10:16 AM CDT
Mon, Dec 08 · 01:16 AM CSTCVE-2025-40307
7.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: exfat: validate cluster allocation bits of the allocation bitmap syzbot created an exfat image with cluster bits not set for the allocation bitmap. exfat-fs reads and uses the allocation bitmap without checking this. The problem is that if the start cl
CVECVE-2025-40307
SeverityHIGH
TypeUPDATED
PublishedMon, Dec 08 · 01:16 AM CST
ModifiedMon, Aug 03 · 10:16 AM CDT
Mon, Jun 09 · 08:15 PM CDTCVE-2025-5914
7.8/10 · Worth your timeNVDvuln
Summary
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to
CVECVE-2025-5914
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 09 · 08:15 PM CDT
ModifiedMon, Aug 03 · 07:16 AM CDT
Tue, Jun 17 · 01:15 PM CDTCVE-2025-6020
7.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
CVECVE-2025-6020
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 17 · 01:15 PM CDT
ModifiedMon, Aug 03 · 08:17 AM CDT
Thu, Jul 10 · 02:15 PM CDTCVE-2025-7425
7.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, caus
CVECVE-2025-7425
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 10 · 02:15 PM CDT
ModifiedMon, Aug 03 · 08:17 AM CDT
Wed, Jun 24 · 05:17 PM CDTCVE-2026-53078
7.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg, the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the destination register in the !fullsock /
CVECVE-2026-53078
SeverityHIGH
TypeUPDATED
PublishedWed, Jun 24 · 05:17 PM CDT
ModifiedMon, Aug 03 · 10:16 AM CDT