Количество 25 355
Количество 25 355
CVE-2026-3087
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVE-2026-30656
A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.
CVE-2026-3063
Chromium: CVE-2026-3063 Inappropriate implementation in DevTools
CVE-2026-3062
Chromium: CVE-2026-3062 Out of bounds read and write in Tint
CVE-2026-3061
Chromium: CVE-2026-3061 Out of bounds read in Media
CVE-2026-3039
BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-29786
node-tar: Hardlink Path Traversal via Drive-Relative Linkpath
CVE-2026-29785
NATS Server panic via malicious compression on leafnode port
CVE-2026-29518
Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write
CVE-2026-29181
OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
CVE-2026-29170
Apache HTTP Server: mod_proxy_ftp XSS
CVE-2026-29169
Apache HTTP Server: mod_dav_lock indirect lock crash
CVE-2026-29168
Apache HTTP Server: mod_md unrestricted OCSP response
CVE-2026-29167
Apache HTTP Server: mod_ldap per-dir use-after-free
CVE-2026-29111
systemd: Local unprivileged user can trigger an assert
CVE-2026-28810
Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver
CVE-2026-28808
ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)
CVE-2026-28755
NGINX ngx_stream_ssl_module vulnerability
CVE-2026-28753
NGINX ngx_mail_proxy_module vulnerability
CVE-2026-28532
FRRouting < 10.5.3 Integer Overflow in OSPF TLV Parser Functions
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs | 1% Низкий | 3 месяца назад | ||
CVE-2026-30656 A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-3063 Chromium: CVE-2026-3063 Inappropriate implementation in DevTools | 0% Низкий | 5 месяцев назад | ||
CVE-2026-3062 Chromium: CVE-2026-3062 Out of bounds read and write in Tint | 0% Низкий | 5 месяцев назад | ||
CVE-2026-3061 Chromium: CVE-2026-3061 Out of bounds read in Media | 0% Низкий | 5 месяцев назад | ||
CVE-2026-3039 BIND 9 server memory exhaustion during GSS-API TKEY negotiation | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-29786 node-tar: Hardlink Path Traversal via Drive-Relative Linkpath | 0% Низкий | 5 месяцев назад | ||
CVE-2026-29785 NATS Server panic via malicious compression on leafnode port | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-29518 Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write | CVSS3: 7 | 0% Низкий | 3 месяца назад | |
CVE-2026-29181 OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-29170 Apache HTTP Server: mod_proxy_ftp XSS | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-29169 Apache HTTP Server: mod_dav_lock indirect lock crash | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-29168 Apache HTTP Server: mod_md unrestricted OCSP response | CVSS3: 7.3 | 1% Низкий | 3 месяца назад | |
CVE-2026-29167 Apache HTTP Server: mod_ldap per-dir use-after-free | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-29111 systemd: Local unprivileged user can trigger an assert | CVSS3: 5.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-28810 Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver | 0% Низкий | 4 месяца назад | ||
CVE-2026-28808 ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch) | 1% Низкий | 4 месяца назад | ||
CVE-2026-28755 NGINX ngx_stream_ssl_module vulnerability | CVSS3: 5.4 | 0% Низкий | 4 месяца назад | |
CVE-2026-28753 NGINX ngx_mail_proxy_module vulnerability | CVSS3: 3.7 | 0% Низкий | 4 месяца назад | |
CVE-2026-28532 FRRouting < 10.5.3 Integer Overflow in OSPF TLV Parser Functions | CVSS3: 6.5 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу