CVE Vulnerability Database

Search and browse 397,909 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-43497HIGH7.3In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to preven...
CVE-2026-43496MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_red: Replace direct dequeue call wit...
CVE-2026-43495HIGH8.8In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against messag...
CVE-2026-43494HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fail...
CVE-2026-0393MEDIUM6.5The affected product may expose credentials remotely between low privileged visualization users during concurrent login ...
CVE-2026-45255HIGH7.5When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and u...
CVE-2026-45254MEDIUM6.5In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key ...
CVE-2026-45253HIGH8.4ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls. As a...
CVE-2026-45252MEDIUM5.5When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace ...
CVE-2026-45251HIGH7.8A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. B...
CVE-2026-42396MEDIUM6.5Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail
CVE-2026-42002HIGH7.5Concurrency and locking defects in GSS-TSIG
CVE-2026-42001HIGH7.5Insufficient Validation of Autoprimary SOA Queries
CVE-2026-42000HIGH8.6Insufficient Validation of Names During AXFR
CVE-2026-41999MEDIUM4.8Incorrect Behaviour of Views with TCP PROXY Requests
CVE-2026-39461HIGH8.8libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for ...
CVE-2026-28764HIGH7.8A heap-based buffer overflow vulnerability exists in the LXF element parsing functionality of MediaInfoLib (version(s): ...
CVE-2026-9157HIGH8.6Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remo...
CVE-2026-7837LOW3.7A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-pr...
CVE-2026-5434MEDIUM5.9Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An atta...
CVE-2026-5433CRITICAL9.1Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could ...
CVE-2026-4858CRITICAL9.9Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration ...
CVE-2026-45250HIGH7.8The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is ...
CVE-2026-44075LOW3.7A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch...
CVE-2026-44074LOW3.7Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when mu...