Fri, Nov 07 · 08:15 PM CSTCVE-2025-10230
10.0/10 · Must read/watchNVDvuln
Summary
A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller
CVECVE-2025-10230
SeverityCRITICAL
TypeUPDATED
PublishedFri, Nov 07 · 08:15 PM CST
ModifiedFri, Aug 21 · 12:16 PM CDT
Fri, Apr 24 · 03:16 PM CDTCVE-2026-31607
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites urb->number_of_packets from the network PDU. This value is subsequently used as the loo
CVECVE-2026-31607
SeverityCRITICAL
TypeUPDATED
PublishedFri, Apr 24 · 03:16 PM CDT
ModifiedFri, Aug 21 · 01:17 PM CDT
Mon, May 18 · 07:16 PM CDTCVE-2026-8836
9.8/10 · Must read/watchNVDvuln
Summary
A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be initiated remotely. T
CVECVE-2026-8836
SeverityCRITICAL
TypeUPDATED
PublishedMon, May 18 · 07:16 PM CDT
ModifiedSat, Aug 22 · 09:16 AM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedFri, Aug 21 · 01:17 PM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49794
9.1/10 · Must read/watchNVDvuln
Summary
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or
CVECVE-2025-49794
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedFri, Aug 21 · 12:16 PM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49796
9.1/10 · Must read/watchNVDvuln
Summary
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive
CVECVE-2025-49796
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedFri, Aug 21 · 12:16 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33210
9.1/10 · Must read/watchNVDvuln
Summary
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This i
CVECVE-2026-33210
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedFri, Aug 21 · 01:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Aug 21 · 01:17 PM CDT
Tue, May 26 · 03:16 PM CDTCVE-2026-4480
9.0/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially cra
CVECVE-2026-4480
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 26 · 03:16 PM CDT
ModifiedFri, Aug 21 · 01:18 PM CDT
Tue, May 14 · 03:42 PM CDTCVE-2024-3727
8.3/10 · Worth your timeNVDvuln
Summary
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
CVECVE-2024-3727
SeverityHIGH
TypeUPDATED
PublishedTue, May 14 · 03:42 PM CDT
ModifiedFri, Aug 21 · 06:16 PM CDT
Tue, Jun 24 · 02:15 PM CDTCVE-2025-6032
8.3/10 · Worth your timeNVDvuln
Summary
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
CVECVE-2025-6032
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 24 · 02:15 PM CDT
ModifiedFri, Aug 21 · 12:16 PM CDT
Mon, Mar 17 · 05:15 PM CDTCVE-2025-2241
8.2/10 · Worth your timeNVDvuln
Summary
A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials
CVECVE-2025-2241
SeverityHIGH
TypeUPDATED
PublishedMon, Mar 17 · 05:15 PM CDT
ModifiedFri, Aug 21 · 06:16 PM CDT
Thu, Mar 26 · 09:17 PM CDTCVE-2026-0966
8.2/10 · Worth your timeNVDvuln
Summary
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_P
CVECVE-2026-0966
SeverityHIGH
TypeUPDATED
PublishedThu, Mar 26 · 09:17 PM CDT
ModifiedFri, Aug 21 · 12:16 PM CDT
Wed, Apr 01 · 02:16 PM CDTCVE-2026-35091
8.2/10 · Worth your timeNVDvuln
Summary
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentiall
CVECVE-2026-35091
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 01 · 02:16 PM CDT
ModifiedFri, Aug 21 · 01:17 PM CDT
Wed, Jun 12 · 09:15 AM CDTCVE-2024-5154
8.1/10 · Worth your timeNVDvuln
Summary
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.
CVECVE-2024-5154
SeverityHIGH
TypeUPDATED
PublishedWed, Jun 12 · 09:15 AM CDT
ModifiedFri, Aug 21 · 12:16 PM CDT
Fri, Sep 05 · 08:15 PM CDTCVE-2025-9566
8.1/10 · Worth your timeNVDvuln
Summary
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritt
CVECVE-2025-9566
SeverityHIGH
TypeUPDATED
PublishedFri, Sep 05 · 08:15 PM CDT
ModifiedFri, Aug 21 · 03:16 PM CDT
Tue, Mar 31 · 08:16 PM CDTCVE-2026-4800
8.1/10 · Worth your timeNVDvuln
Summary
Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as optio
CVECVE-2026-4800
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 31 · 08:16 PM CDT
ModifiedFri, Aug 21 · 01:18 PM CDT
Wed, Dec 15 · 03:15 PM CSTCVE-2021-43226
7.8/10 · Worth your timeNVDvuln
Summary
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVECVE-2021-43226
SeverityHIGH
TypeUPDATED
PublishedWed, Dec 15 · 03:15 PM CST
ModifiedSat, Aug 22 · 04:16 AM CDT
Tue, Apr 07 · 05:16 PM CDTCVE-2025-14821
7.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configur
CVECVE-2025-14821
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 07 · 05:16 PM CDT
ModifiedFri, Aug 21 · 01:16 PM CDT
Thu, Apr 23 · 07:17 PM CDTCVE-2026-33694
7.8/10 · Worth your timeNVDvuln
Summary
This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code with elevated SYSTEM privileges.
CVECVE-2026-33694
SeverityHIGH
TypeUPDATED
PublishedThu, Apr 23 · 07:17 PM CDT
ModifiedFri, Aug 21 · 05:15 PM CDT
Fri, May 08 · 02:16 PM CDTCVE-2026-43329
7.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum number of flowtable hardware offload actions in IPv6 is: * ethernet mangling (4 payload actions, 2 for each ethernet address) * SNAT (4 payload actions) * DNAT (4 payload ac
CVECVE-2026-43329
SeverityHIGH
TypeUPDATED
PublishedFri, May 08 · 02:16 PM CDT
ModifiedFri, Aug 21 · 01:17 PM CDT
Thu, May 21 · 01:16 PM CDTCVE-2026-43499
7.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task
CVECVE-2026-43499
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 01:16 PM CDT
ModifiedSat, Aug 22 · 04:17 AM CDT
Tue, Dec 31 · 03:15 AM CSTCVE-2024-45497
7.6/10 · Worth your timeNVDvuln
Summary
A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from private repositories. The mount is not read-o
CVECVE-2024-45497
SeverityHIGH
TypeUPDATED
PublishedTue, Dec 31 · 03:15 AM CST
ModifiedFri, Aug 21 · 05:16 PM CDT
Thu, Mar 21 · 01:00 PM CDTCVE-2024-1394
7.5/10 · Worth your timeNVDvuln
Summary
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey and ctx. That function uses named return p
CVECVE-2024-1394
SeverityHIGH
TypeUPDATED
PublishedThu, Mar 21 · 01:00 PM CDT
ModifiedFri, Aug 21 · 12:16 PM CDT
Fri, Oct 03 · 11:15 AM CDTCVE-2025-11234
7.5/10 · Worth your timeNVDvuln
Summary
A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket
CVECVE-2025-11234
SeverityHIGH
TypeUPDATED
PublishedFri, Oct 03 · 11:15 AM CDT
ModifiedFri, Aug 21 · 01:16 PM CDT