Количество 19 414
Количество 19 414
CVE-2026-28420
Vim has Heap-based Buffer Overflow and OOB Read in :terminal
CVE-2026-28419
Vim has Heap-based Buffer Underflow in Emacs tags parsing
CVE-2026-28418
Vim has Heap-based Buffer Overflow in Emacs tags parsing
CVE-2026-28417
Vim has OS Command Injection in netrw
CVE-2026-28364
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.
CVE-2026-27969
Vitess users with backup storage access can write to arbitrary file paths on restore
CVE-2026-27965
Vitess users with backup storage access can gain unauthorized access to production deployment environments
CVE-2026-27623
Valkey has Pre-Authentication DOS from malformed RESP request
CVE-2026-27601
Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
CVE-2026-27571
nats-server websockets are vulnerable to pre-auth memory DoS
CVE-2026-27459
pyOpenSSL DTLS cookie callback buffer overflow
CVE-2026-27448
pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
CVE-2026-2739
This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.
CVE-2026-27211
Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse
CVE-2026-27199
Werkzeug safe_join() allows Windows special device names
CVE-2026-27171
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
CVE-2026-27142
URLs in meta content attribute actions are not escaped in html/template
CVE-2026-27141
Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net
CVE-2026-27139
FileInfo can escape from a Root in os
CVE-2026-27138
Panic in name constraint checking for malformed certificates in crypto/x509
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-28420 Vim has Heap-based Buffer Overflow and OOB Read in :terminal | CVSS3: 4.4 | 0% Низкий | 26 дней назад | |
CVE-2026-28419 Vim has Heap-based Buffer Underflow in Emacs tags parsing | CVSS3: 5.3 | 0% Низкий | 26 дней назад | |
CVE-2026-28418 Vim has Heap-based Buffer Overflow in Emacs tags parsing | CVSS3: 4.4 | 0% Низкий | 26 дней назад | |
CVE-2026-28417 Vim has OS Command Injection in netrw | CVSS3: 4.4 | 0% Низкий | 26 дней назад | |
CVE-2026-28364 In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data. | CVSS3: 7.9 | 0% Низкий | 17 дней назад | |
CVE-2026-27969 Vitess users with backup storage access can write to arbitrary file paths on restore | 0% Низкий | 26 дней назад | ||
CVE-2026-27965 Vitess users with backup storage access can gain unauthorized access to production deployment environments | 0% Низкий | 23 дня назад | ||
CVE-2026-27623 Valkey has Pre-Authentication DOS from malformed RESP request | 0% Низкий | 1 день назад | ||
CVE-2026-27601 Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack | 0% Низкий | 20 дней назад | ||
CVE-2026-27571 nats-server websockets are vulnerable to pre-auth memory DoS | CVSS3: 5.9 | 0% Низкий | 27 дней назад | |
CVE-2026-27459 pyOpenSSL DTLS cookie callback buffer overflow | 0% Низкий | 8 дней назад | ||
CVE-2026-27448 pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback | 0% Низкий | 8 дней назад | ||
CVE-2026-2739 This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely. | 0% Низкий | 30 дней назад | ||
CVE-2026-27211 Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse | CVSS3: 10 | 0% Низкий | 30 дней назад | |
CVE-2026-27199 Werkzeug safe_join() allows Windows special device names | 0% Низкий | 30 дней назад | ||
CVE-2026-27171 zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition. | CVSS3: 2.9 | 0% Низкий | около 1 месяца назад | |
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template | 0% Низкий | 9 дней назад | ||
CVE-2026-27141 Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net | CVSS3: 7.5 | 0% Низкий | 22 дня назад | |
CVE-2026-27139 FileInfo can escape from a Root in os | 0% Низкий | 16 дней назад | ||
CVE-2026-27138 Panic in name constraint checking for malformed certificates in crypto/x509 | CVSS3: 5.9 | 0% Низкий | 13 дней назад |
Уязвимостей на страницу