CVE-2026-88914Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser | Exploitation statusNot confirmed | FixNot confirmed | Published09/11/2026 | SeverityMedium |
|---|
CVE-2026-88924Gvfs: gvfs-admin socket ownership race permits local root | Exploitation statusPublic exploit | FixNot confirmed | Published09/10/2026 | SeverityHigh |
|---|
CVE-2026-88859Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction | Exploitation statusNot known exploited | FixNot confirmed | Published09/10/2026 | SeverityMedium |
|---|
CVE-2026-84828Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityMedium |
|---|
CVE-2026-18147Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url | Exploitation statusNot known exploited | FixNot confirmed | Published09/09/2026 | SeverityHigh |
|---|
CVE-2026-87876Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up) | Exploitation statusPublic exploit | FixNot confirmed | Published09/09/2026 | SeverityLow |
|---|
CVE-2026-87875Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound | Exploitation statusPublic exploit | FixNot confirmed | Published09/09/2026 | SeverityMedium |
|---|
CVE-2026-87853Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation | Exploitation statusNot known exploited | FixNot confirmed | Published09/09/2026 | SeverityHigh |
|---|
CVE-2026-87766Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup | Exploitation statusNot known exploited | FixYes | Published09/09/2026 | SeverityHigh |
|---|
CVE-2026-86564Dpdk: dpdk: missing length validation before reading command_data in virtio-net control queue handler | Exploitation statusNot known exploited | FixNot confirmed | Published09/08/2026 | SeverityLow |
|---|
CVE-2026-18090Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block | Exploitation statusNot confirmed | FixNot confirmed | Published09/08/2026 | SeverityMedium |
|---|
CVE-2026-74860Libxml2: double-free/uaf in libxml2 python bindings | Exploitation statusNot known exploited | FixNot confirmed | Published09/08/2026 | SeverityHigh |
|---|
CVE-2026-74859Gnome-tweaks: path traversal in theme installer | Exploitation statusNot known exploited | FixNot confirmed | Published09/08/2026 | SeverityMedium |
|---|
CVE-2026-76561Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint) | Exploitation statusNot known exploited | FixNot confirmed | Published09/08/2026 | SeverityHigh |
|---|
CVE-2026-86469Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path | Exploitation statusPublic exploit | FixNot confirmed | Published09/07/2026 | SeverityMedium |
|---|
CVE-2026-19843389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityHigh |
|---|
CVE-2026-18922389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityCritical |
|---|
CVE-2026-18453389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results and use_one_backend control in op_shared_search | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityHigh |
|---|
CVE-2026-18355389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound underflow in sasl_io_start_packet() | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityHigh |
|---|
CVE-2026-76560389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empty bind dn | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityHigh |
|---|
CVE-2026-79678Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityHigh |
|---|
CVE-2026-76578Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci | Exploitation statusNot known exploited | FixNot confirmed | Published09/07/2026 | SeverityCritical |
|---|
CVE-2026-76925Flatpak: flatpak: toctou race condition allows symlink redirection | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityMedium |
|---|
CVE-2026-85769Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityMedium |
|---|
CVE-2026-85534Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityMedium |
|---|
CVE-2026-81666Corosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityMedium |
|---|
CVE-2026-81665Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityHigh |
|---|
CVE-2026-85197Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload | Exploitation statusPublic exploit | FixNot confirmed | Published09/04/2026 | SeverityHigh |
|---|
CVE-2026-84185Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verification | Exploitation statusNot known exploited | FixNot confirmed | Published09/03/2026 | SeverityMedium |
|---|
CVE-2026-71224Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk | Exploitation statusNot known exploited | FixNot confirmed | Published09/03/2026 | SeverityMedium |
|---|
CVE-2026-71222Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing | Exploitation statusNot known exploited | FixNot confirmed | Published09/03/2026 | SeverityMedium |
|---|
CVE-2026-71221Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta | Exploitation statusNot known exploited | FixNot confirmed | Published09/03/2026 | SeverityHigh |
|---|
CVE-2026-71220Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit | Exploitation statusNot known exploited | FixNot confirmed | Published09/03/2026 | SeverityHigh |
|---|
CVE-2026-71219Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal | Exploitation statusNot known exploited | FixNot confirmed | Published09/03/2026 | SeverityMedium |
|---|
CVE-2026-85150Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted digest authorization/www-authenticate header | Exploitation statusNot known exploited | FixNot confirmed | Published09/03/2026 | SeverityHigh |
|---|
CVE-2026-84838Rpm: command injection in rpmuncompress via unescaped filenames passed to popen() | Exploitation statusNot known exploited | FixNot confirmed | Published09/02/2026 | SeverityHigh |
|---|
CVE-2026-84837Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path | Exploitation statusNot known exploited | FixNot confirmed | Published09/02/2026 | SeverityHigh |
|---|
CVE-2026-78409Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks | Exploitation statusPublic exploit | FixNot confirmed | Published09/02/2026 | SeverityHigh |
|---|
CVE-2026-78410Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection | Exploitation statusPublic exploit | FixNot confirmed | Published09/02/2026 | SeverityHigh |
|---|
CVE-2026-78408Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority | Exploitation statusPublic exploit | FixNot confirmed | Published09/02/2026 | SeverityHigh |
|---|
CVE-2026-53683Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html | Exploitation statusNot known exploited | FixNot confirmed | Published09/02/2026 | SeverityMedium |
|---|
CVE-2026-84270Gvfs: mtp: out-of-bounds read in do_read() | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityMedium |
|---|
CVE-2026-84269Gvfs: afp: heap-based buffer overflow in dsi read path | Exploitation statusPublic exploit | FixYes | Published09/01/2026 | SeverityMedium |
|---|
CVE-2026-84267Gvfs: sftp: uninitialized heap disclosure in read_string() | Exploitation statusPublic exploit | FixYes | Published09/01/2026 | SeverityMedium |
|---|
CVE-2026-84268Gvfs: sftp: heap-based buffer overflow in read_reply() | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
|---|
CVE-2026-84233Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames | Exploitation statusNot known exploited | FixNot confirmed | Published09/01/2026 | SeverityHigh |
|---|
CVE-2026-53682Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts | Exploitation statusNot known exploited | FixNot confirmed | Published09/01/2026 | SeverityMedium |
|---|
CVE-2026-11873Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java exception, and stacktrace disclosure | Exploitation statusNot known exploited | FixNot confirmed | Published09/01/2026 | SeverityMedium |
|---|
CVE-2026-18743Popt-devel: popt-static: short realloc in poptconfigfiletostring | Exploitation statusNot known exploited | FixNot confirmed | Published09/01/2026 | SeverityLow |
|---|
CVE-2026-83596Webkitgtk: validate the full featurelist array once in opentypeverticaldata findfeature | Exploitation statusNot known exploited | FixNot confirmed | Published08/31/2026 | SeverityHigh |
|---|
CVE-2026-13732Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf | Exploitation statusNot known exploited | FixNot confirmed | Published08/31/2026 | SeverityHigh |
|---|
CVE-2026-17615Resteasy-core: resteasy sourceprovider remote unauthenticated file read | Exploitation statusNot known exploited | FixNot confirmed | Published08/31/2026 | SeverityHigh |
|---|
CVE-2026-81624Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infinite | Exploitation statusNot known exploited | FixNot confirmed | Published08/31/2026 | SeverityHigh |
|---|
CVE-2026-82343Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling | Exploitation statusNot known exploited | FixNot confirmed | Published08/28/2026 | SeverityMedium |
|---|
CVE-2026-82330Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check | Exploitation statusPublic exploit | FixNot confirmed | Published08/28/2026 | SeverityMedium |
|---|
CVE-2026-82328Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count | Exploitation statusPublic exploit | FixNot confirmed | Published08/28/2026 | SeverityMedium |
|---|
CVE-2026-82327Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist data | Exploitation statusNot known exploited | FixNot confirmed | Published08/28/2026 | SeverityMedium |
|---|
CVE-2026-82324Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0 | Exploitation statusNot known exploited | FixNot confirmed | Published08/28/2026 | SeverityMedium |
|---|
CVE-2026-80179Jwcrypto: jwcrypto: denial of service via malformed jwe tokens | Exploitation statusPublic exploit | FixNot confirmed | Published08/27/2026 | SeverityMedium |
|---|
CVE-2026-81893Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery | Exploitation statusNot known exploited | FixNot confirmed | Published08/27/2026 | SeverityMedium |
|---|
CVE-2026-5680Undertow-core: undertow: denial of service via websocket permessage-deflate processing | Exploitation statusNot known exploited | FixNot confirmed | Published08/27/2026 | SeverityHigh |
|---|
CVE-2026-78002Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function | Exploitation statusNot known exploited | FixNot confirmed | Published08/27/2026 | SeverityHigh |
|---|
CVE-2026-79902Gimp: stack vla size underflow denial of service in seattle | Exploitation statusPublic exploit | FixNot confirmed | Published08/26/2026 | SeverityMedium |
|---|
CVE-2026-80185Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary code execution as root | Exploitation statusNot known exploited | FixNot confirmed | Published08/25/2026 | SeverityMedium |
|---|
CVE-2026-80186Bluez: stack overflow in name2utf8 causes dos and potential code execution | Exploitation statusNot known exploited | FixNot confirmed | Published08/25/2026 | SeverityHigh |
|---|
CVE-2026-80101Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validation | Exploitation statusPublic exploit | FixNot confirmed | Published08/25/2026 | SeverityMedium |
|---|
CVE-2026-79992Emacs: local shell command injection through the user field in emacs tramp | Exploitation statusNot known exploited | FixNot confirmed | Published08/25/2026 | SeverityHigh |
|---|
CVE-2026-79655Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write | Exploitation statusPublic exploit | FixNot confirmed | Published08/25/2026 | SeverityHigh |
|---|
CVE-2026-78701389-ds-base: 389-ds-base: cve-2026-11610 incomplete fix may introduce a connection-stall dos | Exploitation statusNot known exploited | FixNot confirmed | Published08/25/2026 | SeverityMedium |
|---|
CVE-2026-78475Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader | Exploitation statusNot known exploited | FixNot confirmed | Published08/24/2026 | SeverityMedium |
|---|
CVE-2026-78465Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit | Exploitation statusPublic exploit | FixNot confirmed | Published08/24/2026 | SeverityHigh |
|---|
CVE-2026-19685Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615) | Exploitation statusNot known exploited | FixNot confirmed | Published08/24/2026 | SeverityCritical |
|---|
CVE-2026-78367Rpm: rpmbuild gettarspec() crafted tar member name → macro injection | Exploitation statusPublic exploit | FixNot confirmed | Published08/24/2026 | SeverityHigh |
|---|
CVE-2026-78376Webkitgtk: use-after-free of jscvalue function parameters | Exploitation statusNot known exploited | FixNot confirmed | Published08/24/2026 | SeverityHigh |
|---|
CVE-2026-78323Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates | Exploitation statusNot known exploited | FixNot confirmed | Published08/24/2026 | SeverityMedium |
|---|
CVE-2026-73199Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value | Exploitation statusPublic exploit | FixNot confirmed | Published08/20/2026 | SeverityMedium |
|---|
CVE-2026-11861Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityCritical |
|---|
CVE-2026-73198Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityHigh |
|---|
CVE-2026-13097Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityHigh |
|---|
CVE-2026-73196Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityMedium |
|---|
CVE-2026-73197Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body read | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityHigh |
|---|
CVE-2026-18917Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityHigh |
|---|
CVE-2026-77014Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of http range responses | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2026 | SeverityMedium |
|---|
CVE-2026-19582CVE-2026-19582 | Exploitation statusNot confirmed | FixNot confirmed | Published08/20/2026 | SeverityUnknown |
|---|
CVE-2026-43961Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() filter() expression allows arbitrary code execution | Exploitation statusNot known exploited | FixYes | Published08/19/2026 | SeverityHigh |
|---|
CVE-2026-76235Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie in send_login_html | Exploitation statusNot known exploited | FixNot confirmed | Published08/19/2026 | SeverityHigh |
|---|
CVE-2026-75900Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs sizeof(struct) mismatch | Exploitation statusNot known exploited | FixNot confirmed | Published08/19/2026 | SeverityMedium |
|---|
CVE-2026-75032Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2026 | SeverityMedium |
|---|
CVE-2026-13002Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing | Exploitation statusNot known exploited | FixNot confirmed | Published08/14/2026 | SeverityMedium |
|---|
CVE-2026-19879Io.undertow/undertow: undertow: http response header integrity issue due to character truncation | Exploitation statusNot known exploited | FixNot confirmed | Published08/14/2026 | SeverityMedium |
|---|
CVE-2026-58224Samba: ctdb fails to do integrity checking of received packets | Exploitation statusNot known exploited | FixNot confirmed | Published08/14/2026 | SeverityMedium |
|---|
CVE-2026-19617Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser | Exploitation statusNot known exploited | FixNot confirmed | Published08/14/2026 | SeverityMedium |
|---|
CVE-2026-19730Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives | Exploitation statusPublic exploit | FixNot confirmed | Published08/13/2026 | SeverityMedium |
|---|
CVE-2026-73584Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling | Exploitation statusNot known exploited | FixNot confirmed | Published08/13/2026 | SeverityMedium |
|---|
CVE-2026-73583Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr | Exploitation statusNot known exploited | FixNot confirmed | Published08/13/2026 | SeverityMedium |
|---|
CVE-2026-73585Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack | Exploitation statusNot known exploited | FixNot confirmed | Published08/13/2026 | SeverityMedium |
|---|
CVE-2026-18728Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing | Exploitation statusNot known exploited | FixNot confirmed | Published08/13/2026 | SeverityMedium |
|---|
CVE-2026-18727Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing | Exploitation statusNot known exploited | FixNot confirmed | Published08/12/2026 | SeverityMedium |
|---|
CVE-2026-18726Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing | Exploitation statusNot known exploited | FixNot confirmed | Published08/12/2026 | SeverityMedium |
|---|
CVE-2026-19654Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd | Exploitation statusNot known exploited | FixNot confirmed | Published08/12/2026 | SeverityHigh |
|---|