| gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing CVE-2026-73434 | Severity medium |
| gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux FUJIFILM strd parsing leading to out-of-bounds read/write CVE-2026-73433 | Severity medium |
| ipa: FreeIPA: Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read CVE-2026-73198 | Severity high |
| ipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read CVE-2026-73197 | Severity high |
| libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return CVE-2026-71227 | Severity medium |
| libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi's one-shot AIO path CVE-2026-71226 | Severity high |
| libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries CVE-2026-71225 | Severity medium |
| gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk CVE-2026-71224 | Severity medium |
| gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing CVE-2026-71222 | Severity medium |
| gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta CVE-2026-71221 | Severity high |
| gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit CVE-2026-71220 | Severity high |
| gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal CVE-2026-71219 | Severity medium |
| gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted FITS images CVE-2026-66758 | Severity high |
| libssh: libssh: denial of service via automatic certificate authentication loop CVE-2026-59849 | Severity high |
| libssh: libssh: information disclosure via short GSSAPI Curve25519 public key CVE-2026-59842 | Severity medium |
| gimp: GIMP: Arbitrary code execution in PSD plugin due to unsigned underflow CVE-2026-59090 | Severity critical |
| gimp: gimp: Integer overflow in read_RLE_channel() CVE-2026-58384 | Severity high |
| gimp: gimp: Double-free in read_layer_block() CVE-2026-58381 | Severity high |
| gimp: gimp: Stack buffer overflow in pnmscanner_gettoken() CVE-2026-58380 | Severity high |
| samba: CTDB fails to do integrity checking of received packets CVE-2026-58224 | Severity medium |
| glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" CVE-2026-58016 | Severity critical |
| glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive CVE-2026-58015 | Severity high |
| glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" CVE-2026-58014 | Severity high |
| glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" CVE-2026-58013 | Severity high |
| glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() CVE-2026-58012 | Severity high |
| glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime CVE-2026-58011 | Severity high |
| glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() CVE-2026-58010 | Severity high |
| openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel… CVE-2026-55654 | Severity low |
| abrt: unsanitized systemd journal content written to dump directory files enables content injection CVE-2026-54231 | Severity medium |
| abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites CVE-2026-54230 | Severity high |
| kernel: ipv6: fix possible UAF in icmpv6_rcv() CVE-2026-53006 | Severity critical |
| kernel: netfilter: conntrack: remove sprintf usage CVE-2026-53002 | Severity critical |
| kernel: netfilter: nat: use kfree_rcu to release ops CVE-2026-53000 | Severity high |
| libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data CVE-2026-48864 | Severity high |
| mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() CVE-2026-44172 | Severity critical |
| gimp: GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c) CVE-2026-42169 | Severity high |
| nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers CVE-2026-42055 | Severity high |
| gnutls: gnutls: Authentication Bypass via NUL Character in Username CVE-2026-42010 | Severity critical |
| gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability CVE-2026-42009 | Severity high |
| Apache Tomcat Missing Encryption of Sensitive Data Vulnerability CVE-2026-34486 | Severity high Exploited yes |
| gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment CVE-2026-33845 | Severity critical |
| undertow: Undertow: Request Smuggling via Malformed HTTP Request Headers CVE-2026-28369 | Severity critical |
| undertow: Undertow: Request smuggling via inconsistent header parsing CVE-2026-28368 | Severity critical |
| rsyslog: A configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash… CVE-2026-19654 | Severity high |
| libdm: lvm2: libdm: Denial of Service via uncontrolled recursion in config parser CVE-2026-19617 | Severity medium |
| freeipa: ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes CVE-2026-19550 | Severity high |
| tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite CVE-2026-18508 | Severity medium |
| tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape CVE-2026-18477 | Severity medium |
| libssh: libssh: stack buffer overflow in SFTP server longname construction CVE-2026-15370 | Severity high |
| p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing CVE-2026-13757 | Severity medium |
| ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore CVE-2026-13097 | Severity high |
| FreeIPA: idm: ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships CVE-2026-11861 | Severity high |
| gimp: GIMP: Arbitrary code execution or denial of service via buffer overflow in GIF image processing CVE-2026-6384 | Severity high |
| tar: tar: Hidden file injection via crafted archives CVE-2026-5704 | Severity medium |
| libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing CVE-2026-5121 | Severity high |
| firewalld: firewalld: Local unprivileged user can modify firewall state due to D-Bus setter mis-authorization CVE-2026-4948 | Severity medium |
| polkit: Polkit: Denial of Service via unbounded input processing through standard input CVE-2026-4897 | Severity medium |
| libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() CVE-2026-4878 | Severity high |
| libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing CVE-2026-4775 | Severity high |
| libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing CVE-2026-4424 | Severity high |
| samba: Remote Code Execution in SAMR CVE-2026-4408 | Severity critical |
| gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison CVE-2026-3833 | Severity high |
| gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response CVE-2026-3832 | Severity low |
| samba: group policy certificate enrollment uses http:// without validation CVE-2026-3012 | Severity high |
| samba: vfs_worm does not block directory modification CVE-2026-2340 | Severity medium |
| p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters CVE-2026-2100 | Severity high |
| samba: Missing access check on reparse point operations CVE-2026-1933 | Severity high |
| Apple Multiple Products Buffer Overflow Vulnerability CVE-2025-31277 | Severity high Exploited yes |
| glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow CVE-2025-14512 | Severity medium |
| glib: GLib: Buffer underflow in GVariant parser leads to heap corruption CVE-2025-14087 | Severity critical |
| undertow: Undertow MadeYouReset HTTP/2 DDoS Vulnerability CVE-2025-9784 | Severity high |
| libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling CVE-2025-6170 | Severity low |
| libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 CVE-2025-6021 | Severity high |
| libarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c CVE-2025-5914 | Severity high |
| rsync: Info Leak via Uninitialized Stack Contents CVE-2024-12085 | Severity high |
| An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API… CVE-2023-52355 | Severity high |
| A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key… CVE-2023-50781 | Severity high |
| IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@… CVE-2023-39417 | Severity high |
| A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file… CVE-2023-39329 | Severity medium |
| A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning… CVE-2023-39327 | Severity medium |
| A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias'… CVE-2023-6710 | Severity medium |
| An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of… CVE-2023-6563 | Severity high |
| A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A… CVE-2023-6291 | Severity high |
| A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This… CVE-2023-6134 | Severity medium |
| A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive… CVE-2023-4061 | Severity medium |
| A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the… CVE-2023-1380 | Severity high |
| A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user… CVE-2022-1199 | Severity high |
| OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of… CVE-2020-6851 | Severity high |
| Red Hat Libuser Race Condition Vulnerability CVE-2015-3246 | Severity high Exploited yes |
| The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute… CVE-2004-2771 | |