Tue, May 26 · 02:16 PM CDTCVE-2026-7374
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container r
CVECVE-2026-7374
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 26 · 02:16 PM CDT
ModifiedSun, Jul 19 · 12:16 PM CDT
Thu, Jul 16 · 05:16 PM CDTCVE-2026-46562
9.8/10 · Must read/watchNVDvuln
Summary
Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a ClassFilter, so a user with the ChangeMissionDatabase privilege could ov
CVECVE-2026-46562
SeverityCRITICAL
TypeUPDATED
PublishedThu, Jul 16 · 05:16 PM CDT
ModifiedMon, Jul 20 · 01:53 AM CDT
Thu, Jul 16 · 05:16 PM CDTCVE-2026-45568
9.1/10 · Must read/watchNVDvuln
Summary
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path to replace the configured target host and causing requests.request to ret
CVECVE-2026-45568
SeverityCRITICAL
TypeUPDATED
PublishedThu, Jul 16 · 05:16 PM CDT
ModifiedMon, Jul 20 · 01:58 AM CDT
Thu, Jul 16 · 05:16 PM CDTCVE-2026-46621
9.1/10 · Must read/watchNVDvuln
Summary
Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase
CVECVE-2026-46621
SeverityCRITICAL
TypeUPDATED
PublishedThu, Jul 16 · 05:16 PM CDT
ModifiedMon, Jul 20 · 01:46 AM CDT
Wed, Nov 12 · 05:15 PM CSTCVE-2025-2843
8.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create
CVECVE-2025-2843
SeverityHIGH
TypeUPDATED
PublishedWed, Nov 12 · 05:15 PM CST
ModifiedSun, Jul 19 · 12:16 PM CDT
Tue, Jun 02 · 09:16 AM CDTCVE-2026-1784
8.8/10 · Worth your timeNVDvuln
Summary
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVECVE-2026-1784
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 02 · 09:16 AM CDT
ModifiedMon, Jul 20 · 05:16 AM CDT
Tue, Jun 24 · 02:15 PM CDTCVE-2025-5318
8.1/10 · Worth your timeNVDvuln
Summary
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This
CVECVE-2025-5318
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 24 · 02:15 PM CDT
ModifiedSun, Jul 19 · 05:16 PM CDT
Mon, Jun 09 · 08:15 PM CDTCVE-2025-5914
7.8/10 · Worth your timeNVDvuln
Summary
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to
CVECVE-2025-5914
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 09 · 08:15 PM CDT
ModifiedMon, Jul 20 · 04:16 AM CDT
Tue, Jun 17 · 01:15 PM CDTCVE-2025-6020
7.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
CVECVE-2025-6020
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 17 · 01:15 PM CDT
ModifiedSun, Jul 19 · 05:16 PM CDT
Thu, Jul 10 · 02:15 PM CDTCVE-2025-7425
7.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, caus
CVECVE-2025-7425
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 10 · 02:15 PM CDT
ModifiedMon, Jul 20 · 04:16 AM CDT
Wed, Mar 01 · 08:15 AM CSTCVE-2023-0567
7.7/10 · Worth your timeNVDvuln
Summary
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid.
CVECVE-2023-0567
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 01 · 08:15 AM CST
ModifiedSun, Jul 19 · 07:16 PM CDT
Thu, Jan 25 · 08:15 PM CSTCVE-2023-52355
7.5/10 · Worth your timeNVDvuln
Summary
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
CVECVE-2023-52355
SeverityHIGH
TypeUPDATED
PublishedThu, Jan 25 · 08:15 PM CST
ModifiedMon, Jul 20 · 05:16 AM CDT
Tue, Jan 14 · 06:15 PM CSTCVE-2024-12085
7.5/10 · Worth your timeNVDvuln
Summary
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
CVECVE-2024-12085
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 14 · 06:15 PM CST
ModifiedSun, Jul 19 · 05:16 PM CDT
Tue, Jul 14 · 07:16 PM CDTCVE-2026-15637
7.5/10 · Worth your timeNVDvuln
Summary
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier.
CVECVE-2026-15637
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 14 · 07:16 PM CDT
ModifiedMon, Jul 20 · 02:11 AM CDT
Thu, Mar 05 · 04:16 PM CSTCVE-2026-30796
7.5/10 · Worth your timeNVDvuln
Summary
Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Sniffing Attacks. The client places the preset address-book password verba
CVECVE-2026-30796
SeverityHIGH
TypeUPDATED
PublishedThu, Mar 05 · 04:16 PM CST
ModifiedSun, Jul 19 · 12:16 PM CDT
Thu, Apr 30 · 06:16 PM CDTCVE-2026-33845
7.5/10 · Worth your timeNVDvuln
Summary
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.
CVECVE-2026-33845
SeverityHIGH
TypeUPDATED
PublishedThu, Apr 30 · 06:16 PM CDT
ModifiedMon, Jul 20 · 10:16 AM CDT
Mon, May 04 · 10:15 AM CDTCVE-2026-33846
7.5/10 · Worth your timeNVDvuln
Summary
A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fra
CVECVE-2026-33846
SeverityHIGH
TypeUPDATED
PublishedMon, May 04 · 10:15 AM CDT
ModifiedMon, Jul 20 · 10:16 AM CDT
Mon, May 18 · 01:16 PM CDTCVE-2026-42009
7.5/10 · Worth your timeNVDvuln
Summary
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable
CVECVE-2026-42009
SeverityHIGH
TypeUPDATED
PublishedMon, May 18 · 01:16 PM CDT
ModifiedMon, Jul 20 · 10:16 AM CDT
Thu, Jul 16 · 05:16 PM CDTCVE-2026-45576
7.5/10 · Worth your timeNVDvuln
Summary
zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarget.WriteStream, allowing the sync pipeline to write files outside the sele
CVECVE-2026-45576
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 16 · 05:16 PM CDT
ModifiedMon, Jul 20 · 01:54 AM CDT
Tue, Jun 30 · 12:16 PM CDTCVE-2026-57080
7.5/10 · Worth your timeNVDvuln
Summary
Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framing in _process_messages trusts the 4-byte length prefix sent by a connected peer with no upper bound, while receive_data appends every inbound byte to the input buffer. A pe
CVECVE-2026-57080
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 30 · 12:16 PM CDT
ModifiedMon, Jul 20 · 07:16 AM CDT
Tue, Jun 30 · 12:16 PM CDTCVE-2026-57081
7.5/10 · Worth your timeNVDvuln
Summary
Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining buffer by value while the list and dictionary branches capture the whole remainder,
CVECVE-2026-57081
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 30 · 12:16 PM CDT
ModifiedMon, Jul 20 · 07:16 AM CDT
Mon, Jun 29 · 05:16 PM CDTCVE-2026-12912
7.3/10 · Worth your timeNVDvuln
Summary
A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. Thi
CVECVE-2026-12912
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 29 · 05:16 PM CDT
ModifiedMon, Jul 20 · 04:16 AM CDT
Wed, Jul 15 · 08:17 PM CDTCVE-2026-45738
7.3/10 · Worth your timeNVDvuln
Summary
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/src/app/applications/components/application-summary/application-summary.t
CVECVE-2026-45738
SeverityHIGH
TypeUPDATED
PublishedWed, Jul 15 · 08:17 PM CDT
ModifiedMon, Jul 20 · 02:06 AM CDT
Thu, Jun 04 · 12:16 PM CDTCVE-2026-10840
7.1/10 · Worth your timeNVDvuln
Summary
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated
CVECVE-2026-10840
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 04 · 12:16 PM CDT
ModifiedSun, Jul 19 · 03:16 PM CDT
Tue, Jul 14 · 07:16 PM CDTCVE-2026-15641
7.1/10 · Worth your timeNVDvuln
Summary
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.
CVECVE-2026-15641
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 14 · 07:16 PM CDT
ModifiedMon, Jul 20 · 02:10 AM CDT