CVE-2026-77159Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file ownership change via symlink | Exploitation statusNot confirmed | FixNot confirmed | Published09/11/2026 | SeverityMedium |
|---|
CVE-2026-88914Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser | Exploitation statusNot confirmed | FixNot confirmed | Published09/11/2026 | SeverityMedium |
|---|
CVE-2026-88924Gvfs: gvfs-admin socket ownership race permits local root | Exploitation statusPublic exploit | FixNot confirmed | Published09/10/2026 | SeverityHigh |
|---|
CVE-2026-88859Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction | Exploitation statusNot known exploited | FixNot confirmed | Published09/10/2026 | SeverityMedium |
|---|
CVE-2026-18147Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url | Exploitation statusNot known exploited | FixNot confirmed | Published09/09/2026 | SeverityHigh |
|---|
CVE-2026-87876Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up) | Exploitation statusPublic exploit | FixNot confirmed | Published09/09/2026 | SeverityLow |
|---|
CVE-2026-87875Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound | Exploitation statusPublic exploit | FixNot confirmed | Published09/09/2026 | SeverityMedium |
|---|
CVE-2026-87853Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation | Exploitation statusNot known exploited | FixNot confirmed | Published09/09/2026 | SeverityHigh |
|---|
CVE-2026-18090Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block | Exploitation statusNot confirmed | FixNot confirmed | Published09/08/2026 | SeverityMedium |
|---|
CVE-2026-74860Libxml2: double-free/uaf in libxml2 python bindings | Exploitation statusNot known exploited | FixNot confirmed | Published09/08/2026 | SeverityHigh |
|---|
CVE-2026-76561Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint) | Exploitation statusNot known exploited | FixNot confirmed | Published09/08/2026 | SeverityHigh |
|---|
CVE-2026-86469Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path | Exploitation statusPublic exploit | FixNot confirmed | Published09/07/2026 | SeverityMedium |
|---|
CVE-2026-19843389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityHigh |
|---|
CVE-2026-18922389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityCritical |
|---|
CVE-2026-18453389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results and use_one_backend control in op_shared_search | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityHigh |
|---|
CVE-2026-18355389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound underflow in sasl_io_start_packet() | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityHigh |
|---|
CVE-2026-76560389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empty bind dn | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityHigh |
|---|
CVE-2026-79678Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityHigh |
|---|
CVE-2026-76578Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityCritical |
|---|
CVE-2026-85534Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityMedium |
|---|
CVE-2026-85197Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload | Exploitation statusPublic exploit | FixNot confirmed | Published09/04/2026 | SeverityHigh |
|---|
CVE-2026-84838Rpm: command injection in rpmuncompress via unescaped filenames passed to popen() | Exploitation statusNot known exploited | FixNot confirmed | Published09/02/2026 | SeverityHigh |
|---|
CVE-2026-84837Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path | Exploitation statusNot known exploited | FixNot confirmed | Published09/02/2026 | SeverityHigh |
|---|
CVE-2026-53683Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html | Exploitation statusNot known exploited | FixNot confirmed | Published09/02/2026 | SeverityMedium |
|---|
CVE-2026-84270Gvfs: mtp: out-of-bounds read in do_read() | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityMedium |
|---|
CVE-2026-84269Gvfs: afp: heap-based buffer overflow in dsi read path | Exploitation statusPublic exploit | FixYes | Published09/01/2026 | SeverityMedium |
|---|
CVE-2026-84267Gvfs: sftp: uninitialized heap disclosure in read_string() | Exploitation statusPublic exploit | FixYes | Published09/01/2026 | SeverityMedium |
|---|
CVE-2026-84268Gvfs: sftp: heap-based buffer overflow in read_reply() | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
|---|
CVE-2026-84233Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames | Exploitation statusNot known exploited | FixNot confirmed | Published09/01/2026 | SeverityHigh |
|---|
CVE-2026-53682Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts | Exploitation statusNot known exploited | FixNot confirmed | Published09/01/2026 | SeverityMedium |
|---|
CVE-2026-11873Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java exception, and stacktrace disclosure | Exploitation statusNot known exploited | FixNot confirmed | Published09/01/2026 | SeverityMedium |
|---|
CVE-2026-18743Popt-devel: popt-static: short realloc in poptconfigfiletostring | Exploitation statusNot known exploited | FixNot confirmed | Published09/01/2026 | SeverityLow |
|---|
CVE-2026-83596Webkitgtk: validate the full featurelist array once in opentypeverticaldata findfeature | Exploitation statusNot known exploited | FixNot confirmed | Published08/31/2026 | SeverityHigh |
|---|
CVE-2026-13732Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf | Exploitation statusNot known exploited | FixNot confirmed | Published08/31/2026 | SeverityHigh |
|---|
CVE-2026-82343Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling | Exploitation statusNot known exploited | FixNot confirmed | Published08/28/2026 | SeverityMedium |
|---|
CVE-2026-82330Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check | Exploitation statusPublic exploit | FixNot confirmed | Published08/28/2026 | SeverityMedium |
|---|
CVE-2026-82328Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count | Exploitation statusPublic exploit | FixNot confirmed | Published08/28/2026 | SeverityMedium |
|---|
CVE-2026-82324Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0 | Exploitation statusNot known exploited | FixNot confirmed | Published08/28/2026 | SeverityMedium |
|---|
CVE-2026-81893Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery | Exploitation statusNot known exploited | FixNot confirmed | Published08/27/2026 | SeverityMedium |
|---|
CVE-2026-78002Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function | Exploitation statusNot known exploited | FixNot confirmed | Published08/27/2026 | SeverityHigh |
|---|
CVE-2026-79902Gimp: stack vla size underflow denial of service in seattle | Exploitation statusPublic exploit | FixNot confirmed | Published08/26/2026 | SeverityMedium |
|---|
CVE-2026-80185Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary code execution as root | Exploitation statusNot known exploited | FixNot confirmed | Published08/25/2026 | SeverityMedium |
|---|
CVE-2026-80186Bluez: stack overflow in name2utf8 causes dos and potential code execution | Exploitation statusNot known exploited | FixNot confirmed | Published08/25/2026 | SeverityHigh |
|---|
CVE-2026-80101Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validation | Exploitation statusPublic exploit | FixNot confirmed | Published08/25/2026 | SeverityMedium |
|---|
CVE-2026-79992Emacs: local shell command injection through the user field in emacs tramp | Exploitation statusNot known exploited | FixNot confirmed | Published08/25/2026 | SeverityHigh |
|---|
CVE-2026-79655Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write | Exploitation statusPublic exploit | FixNot confirmed | Published08/25/2026 | SeverityHigh |
|---|
CVE-2026-78701389-ds-base: 389-ds-base: cve-2026-11610 incomplete fix may introduce a connection-stall dos | Exploitation statusNot known exploited | FixNot confirmed | Published08/25/2026 | SeverityMedium |
|---|
CVE-2026-78322File-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and rar handlers | Exploitation statusPublic exploit | FixNot confirmed | Published08/25/2026 | SeverityMedium |
|---|
CVE-2026-78475Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader | Exploitation statusNot known exploited | FixNot confirmed | Published08/24/2026 | SeverityMedium |
|---|
CVE-2026-78465Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit | Exploitation statusPublic exploit | FixNot confirmed | Published08/24/2026 | SeverityHigh |
|---|
CVE-2026-19685Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615) | Exploitation statusNot known exploited | FixNot confirmed | Published08/24/2026 | SeverityCritical |
|---|
CVE-2026-78367Rpm: rpmbuild gettarspec() crafted tar member name → macro injection | Exploitation statusPublic exploit | FixNot confirmed | Published08/24/2026 | SeverityHigh |
|---|
CVE-2026-78376Webkitgtk: use-after-free of jscvalue function parameters | Exploitation statusNot known exploited | FixNot confirmed | Published08/24/2026 | SeverityHigh |
|---|
CVE-2026-78323Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates | Exploitation statusNot known exploited | FixNot confirmed | Published08/24/2026 | SeverityMedium |
|---|
CVE-2026-73199Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value | Exploitation statusPublic exploit | FixNot confirmed | Published08/20/2026 | SeverityMedium |
|---|
CVE-2026-11861Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityCritical |
|---|
CVE-2026-73198Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityHigh |
|---|
CVE-2026-13097Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityHigh |
|---|
CVE-2026-73196Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityMedium |
|---|
CVE-2026-73197Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body read | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityHigh |
|---|
CVE-2026-18917Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityHigh |
|---|
CVE-2026-77014Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of http range responses | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityMedium |
|---|
CVE-2026-19582CVE-2026-19582 | Exploitation statusNot confirmed | FixNot confirmed | Published08/20/2026 | SeverityUnknown |
|---|
CVE-2026-43961Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() filter() expression allows arbitrary code execution | Exploitation statusNot known exploited | FixYes | Published08/19/2026 | SeverityHigh |
|---|
CVE-2026-75032Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2026 | SeverityMedium |
|---|
CVE-2026-13002Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing | Exploitation statusNot known exploited | FixNot confirmed | Published08/14/2026 | SeverityMedium |
|---|
CVE-2026-58224Samba: ctdb fails to do integrity checking of received packets | Exploitation statusNot known exploited | FixNot confirmed | Published08/14/2026 | SeverityMedium |
|---|
CVE-2026-19617Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser | Exploitation statusNot known exploited | FixNot confirmed | Published08/14/2026 | SeverityMedium |
|---|
CVE-2026-73584Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling | Exploitation statusNot known exploited | FixNot confirmed | Published08/13/2026 | SeverityMedium |
|---|
CVE-2026-73583Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr | Exploitation statusNot known exploited | FixNot confirmed | Published08/13/2026 | SeverityMedium |
|---|
CVE-2026-73585Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack | Exploitation statusNot known exploited | FixNot confirmed | Published08/13/2026 | SeverityMedium |
|---|
CVE-2026-19654Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd | Exploitation statusNot known exploited | FixNot confirmed | Published08/12/2026 | SeverityHigh |
|---|
CVE-2026-19548Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing | Exploitation statusNot known exploited | FixNot confirmed | Published08/12/2026 | SeverityMedium |
|---|
CVE-2026-18663389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext() via critical session tracking control | Exploitation statusNot known exploited | FixNot confirmed | Published08/12/2026 | SeverityMedium |
|---|
CVE-2026-19550Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes | Exploitation statusNot known exploited | FixNot confirmed | Published08/11/2026 | SeverityHigh |
|---|
CVE-2026-19546Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via caller-influenced profile attribute | Exploitation statusNot known exploited | FixNot confirmed | Published08/11/2026 | SeverityHigh |
|---|
CVE-2026-72693Kbd: local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login | Exploitation statusNot known exploited | FixNot confirmed | Published08/11/2026 | SeverityHigh |
|---|
CVE-2026-72694Mrtg: mrtg daemon symlink-following chown allows local privilege escalation via pid file path manipulation | Exploitation statusNot known exploited | FixNot confirmed | Published08/11/2026 | SeverityHigh |
|---|
CVE-2026-6426Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access | Exploitation statusNot known exploited | FixNot confirmed | Published08/10/2026 | SeverityMedium |
|---|
CVE-2026-63622Libvirt: swtpm privilege escalation via symlink following | Exploitation statusNot known exploited | FixNot confirmed | Published08/10/2026 | SeverityHigh |
|---|
CVE-2026-59091Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file | Exploitation statusNot known exploited | FixNot confirmed | Published08/10/2026 | SeverityHigh |
|---|
CVE-2026-63623Libvirt: information disclosure via world-readable storage volume images during clone/convert | Exploitation statusNot known exploited | FixNot confirmed | Published08/10/2026 | SeverityMedium |
|---|
CVE-2026-59090Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow | Exploitation statusPublic exploit | FixNot confirmed | Published08/10/2026 | SeverityHigh |
|---|
CVE-2026-59088Gimp: gimp: denial of service via signed integer overflow in fli file processing | Exploitation statusNot known exploited | FixNot confirmed | Published08/10/2026 | SeverityMedium |
|---|
CVE-2026-59087Gimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes attacker-controlled length into undersized allocation | Exploitation statusNot known exploited | FixNot confirmed | Published08/10/2026 | SeverityHigh |
|---|
CVE-2026-19404389-ds-base: 389-ds-base: missing authorization allows anonymous clients to start or abort cleanallruv replication maintenance | Exploitation statusNot known exploited | FixNot confirmed | Published08/10/2026 | SeverityMedium |
|---|
CVE-2026-42170Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_layer() (ddsread.c) | Exploitation statusNot known exploited | FixNot confirmed | Published08/08/2026 | SeverityHigh |
|---|
CVE-2026-61477Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection | Exploitation statusNot known exploited | FixNot confirmed | Published08/07/2026 | SeverityLow |
|---|
CVE-2026-15816Dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() | Exploitation statusNot known exploited | FixNot confirmed | Published08/07/2026 | SeverityHigh |
|---|
CVE-2026-18938P11-kit: integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems | Exploitation statusNot known exploited | FixNot confirmed | Published08/07/2026 | SeverityMedium |
|---|
CVE-2026-19079Policycoreutils: policycoreutils: toctou race condition in fixfiles allows arbitrary selinux label manipulation | Exploitation statusNot known exploited | FixNot confirmed | Published08/07/2026 | SeverityMedium |
|---|
CVE-2026-18839Popt-devel: popt-static: size_t underflow in singleoptionhelp | Exploitation statusNot known exploited | FixNot confirmed | Published08/05/2026 | SeverityLow |
|---|
CVE-2026-44605Rpm: heap buffer overflow in ndb slot table parsing | Exploitation statusNot known exploited | FixNot confirmed | Published08/05/2026 | SeverityMedium |
|---|
CVE-2026-18103Dhcp-server: dhcp-server: persistent denial of service due to buffer overflow via omapi | Exploitation statusNot known exploited | FixNot confirmed | Published08/04/2026 | SeverityMedium |
|---|
CVE-2026-68743Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1 | Exploitation statusNot known exploited | FixNot confirmed | Published08/04/2026 | SeverityMedium |
|---|
CVE-2026-70368Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message | Exploitation statusNot known exploited | FixYes | Published08/04/2026 | SeverityMedium |
|---|
CVE-2026-70367Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and unspecified addresses allows access to loopback-only services | Exploitation statusPublic exploit | FixYes | Published08/04/2026 | SeverityMedium |
|---|
CVE-2026-18739Popt-devel: popt-static: off-by-one in poptstuffargs | Exploitation statusNot known exploited | FixNot confirmed | Published08/04/2026 | SeverityLow |
|---|
CVE-2026-68744Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply | Exploitation statusNot known exploited | FixNot confirmed | Published08/04/2026 | SeverityLow |
|---|
CVE-2026-42169Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr width (file-png.c) | Exploitation statusNot known exploited | FixNot confirmed | Published08/04/2026 | SeverityHigh |
|---|