UFC fans go wild for 'best ever' rendition of the national anthem at White House event in front of Trump txtify archive
Trump celebrates UFC fight night for birthday spectacular on White House lawn as MAGA stars erupt into patriotic chants for USA win txtify archive
Senator Mitch McConnell, 84, rushed to the hospital after months of public health scares txtify archive
The billionaire's bolthole that won't sell despite slashing $26M from asking price: Drastic move to find a buyer txtify archive
New front in the war between Elon Musk and Jeff Bezos... but your in-flight experience will get so much better whoever wins txtify archive
Anne Schedeen dies at 77: Legendary TV actress best known for playing mom on ALF passes away txtify archive
Every man I've dated wants to do the same thing to me in bed. It's revolting... but they're obsessed with it: DEAR JANE txtify archive
CVE-2026-49762 Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service txtify archive
CVE-2026-7774 tarfile.data_filter path traversal bypass allows writing outside the extraction directory txtify archive
Iran land in USA ahead of 'tense' World Cup opener: Players welcomed to LA by protests, drones, dogs and police escort txtify archive
Donald Trump receives fairytale ending to UFC White House extravaganza as Justin Gaethje stuns Ilia Topuria to win lightweight title txtify archive
CVE-2026-11526 GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle txtify archive
CVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() txtify archive
Cruz and Romeo Beckham take a swipe at Brooklyn as they make public show of support for sister Harper, 14, - after their estranged brother claimed family 'choreographed' teen's visit to his LA mansion txtify archive
Barron Trump sports stylish new look as he's seen for the first time in four months towering over mom and dad at UFC event txtify archive
Blake Lively and Ryan Reynolds finally address ugly behind-the-scenes dilemma at their 'paradise' compound txtify archive
Combative Trump storms into G7 powder keg as world leaders brace for showdowns with Europe and Zelensky txtify archive
Sean Strickland kicked out of White House event by Secret Service after being banned from Trump's bash for 'making fun of Israel and Jeffrey Epstein' txtify archive
Passenger 'jumped from helicopter' in collision that killed internet star Oliver Tree - as KSI leads tributes txtify archive
Dark secrets of the family where people disappear: Five-year-old Summer Wells vanished five years ago but 12 years earlier her aunt also went missing txtify archive
Men who threw young female bungee jumper to her death in horrifying video FLED after realizing they forgot to attach the cord txtify archive
Ohio woman who took pity on 'homeless' couple decided to take them off the streets...then she discovered their horrifying secret txtify archive
Entrepreneur who swindled Trump's top Wall Street nemesis out of millions is now seeking a presidential pardon txtify archive
Pregnant Ohio teen shot and paralyzed during robbery after meeting person through Snapchat txtify archive
Trump says peace deal with Iran is now complete and authorizes full opening of Strait of Hormuz: 'Let the oil flow!' txtify archive
Sydney Sweeney is boyfriend Scooter Braun's 'good luck charm' as they celebrate epic New York Knicks championship txtify archive
Spencer Pratt teams up with unlikely ally to take on Karen Bass over fires destroying Los Angeles homes txtify archive
Very bitchy truth about Taylor Swift's feud with Miles Teller's wife Keleigh: Full nasty story of accusation that left actor 'absolutely disgusted'… and unforgivable betrayal that was 'nail in the coffin' txtify archive
Melania stuns in black as she arrives with military escort for UFC showdown on White House lawn txtify archive
Texas town plagued by 'drone highway' above their heads says constant Amazon air deliveries are driving them MAD txtify archive
Jewish homeowner goes all the way to Supreme Court after city told he couldn't have friends over to PRAY txtify archive
Hundreds of Stanford students walk out on Google CEO Sundar Pichai's commencement speech over tech company's ties to Israel txtify archive
'Hell on Wheels' killer Mackenzie Shirilla's mom makes explosive new claims about 'evil' daughter's relationship with boyfriend and lesbian urges… as jailhouse transformation is revealed txtify archive
Harrowing final moments of two US missionaries murdered in Haiti revealed in new minute-by-minute account... and the heartbreaking final promise made by one victim to his captors txtify archive
Anti-G7 protest turns violent as demonstrators torch Tesla and smash UN office windows txtify archive
Gwyneth Paltrow's 'heated arguments' with husband Brad Falchuk revealed: She's already admitted he thinks she's a Republican... now insiders tell explosive marriage secrets txtify archive
Lauren Sanchez turns heads in a plunging crochet dress as she heads for dinner in Paris txtify archive
Charles Barkley goes viral for wild Sydney Sweeney reaction at NBA Finals... days after sparking meltdown with 'Cardi D' joke txtify archive
Val Kilmer's hellish behavior exposed in legacy-ruining detail by director: Bombshell new claims about what happened behind the scenes... and the unpublishable slur he used 'constantly' txtify archive
Buc-ee's backlash: Turns out not everyone loves massive travel centers disrupting life in their cities txtify archive
New breed of airport lounges with a VERY different offer spreads across America: 'They're goofy and a little silly' txtify archive
Killer dad Chris Watts' OTHER mistress details night of sex horrors weeks before his murders… as leaked trove of unseen texts, obscene internet searches and nude photos exposes nightmarish new depths to his depravity txtify archive
Truth about Donald Trump's friendship with Dana White revealed in full by UFC insiders... as Freedom 250 fight takes place on White House lawn txtify archive
Experts react: The US and Iran just announced an interim peace deal. Here’s what we know so far. txtify archive
The REAL heroes of the World Cup: Classy Japan fans clean up after themselves following draw against the Netherlands txtify archive
National Guardsman pleads guilty to fatal shooting of soldier he found in bed with his ex-girlfriend txtify archive
ISC Stormcast For Monday, June 15th, 2026 https://isc.sans.edu/podcastdetail/9972, (Mon, Jun 15th) txtify archive
Turkey's sore loser captain says his team 'dominated' Socceroos in World Cup loss - after angering Aussies with pre-match taunt txtify archive
'The Office' star rages at Democratic 'hypocrisy' over Graham Platner's Nazi tattoo and trouble with women txtify archive
Historic California colleges with famous civil rights alumni forced to MERGE and re-brand after facing historically bad enrollment rates txtify archive
Trump announces peace deal with Iran, declares Strait of Hormuz will reopen: 'Let the oil flow!' txtify archive
Tragic real reason so many women get ghosted: JANA HOCKING dares to say what no man will admit txtify archive
Karmelo Anthony judge backs jury's verdict after killer sentenced to 35 years for murdering Austin Metcalf txtify archive
Royal Marines capture tanker from Putin's 'shadow fleet'... just in time for Starmer to boast about it at G7 txtify archive
I was at the center of the Great Pyramid scandal. Egyptian officials sentenced me to jail... Here's proof I'm innocent txtify archive
Humiliating truth about Nashville's most hated influencer and her relationship with Riley Green: Insiders reveal secret reason she was desperate to date country star... his brutal opinion of her... and derogatory two-word nickname people call her txtify archive
Boston police arrest 14-year-old after masked suspects allegedly rob siblings’ lemonade stand txtify archive
Trump team outraged after reporters obtain 'sensitive' leaked audio of Situation Room meetings for new book txtify archive
Trump unleashes expletive-laden birthday tirade at Netanyahu and claims he has 'no judgment' in extraordinary outburst txtify archive
Scandal engulfs Trump's 'MAGA warrior' on election eve: Read megachurch pastor's red-hot texts to Miss Oklahoma - and furious wife's vile accusation that shatters family-man image txtify archive
Emily Ratajkowski's sickening X-rated confession reveals a degrading truth about her no one wants to admit. Trust me, I've been a divorced, single mom too: KENNEDY txtify archive
Kim Kardashian congratulates Formula One star boyfriend Lewis Hamilton after legend's first Ferrari win at the Barcelona Grand Prix - one week on from her controversial Monaco appearance txtify archive
Why World Cup stars are 'BANNED' from speaking Spanish in the United States - as storm erupts over FIFA's press conference rules txtify archive
Khamenei's 'target-rich' funeral is Iran’s biggest security gamble, sends message to US: expert txtify archive
Knicks owner James Dolan 'made wild sex demand to New York stars' before NBA Championship playoff run txtify archive
New Yorkers hailed as the real MVPs as social media goes wild over lone moment of 'beauty' amid chaotic Knicks Championship celebrations txtify archive
12 dead after plane full of skydivers CRASHES just after takeoff from Missouri airport txtify archive
Israel fears Trump weary of ‘highly suspicious’ Netanyahu and could 'flip' amid Iran deal: analyst txtify archive
Spencer Pratt and wife Heidi Montag flee LA for a meal after he claimed fire at business was set by enemies txtify archive
Jalen Brunson weighs in on Taylor Swift Knicks controversy as he defends radio host who told popstar to 'get out' of MSG on hot mic txtify archive
Atlanta judge's courthouse sex with top cop was so loud it sickened her law clerks...now her tone-deaf apologies to her mortified staff are exposed txtify archive
Markwayne Mullin tells local cops they'll have to wait for 'delayed' World Cup funds after hopping on DHS $70m jet to fly home txtify archive
Zelenskyy congratulates Trump on turning 80 in birthday call, vows more Ukraine peace talks at G7 on Tuesday txtify archive
Republican leaders embrace viral World Cup fans they say are discovering the 'real America' txtify archive
Gabbard says declassified biolab records validate concerns previously dismissed as misinformation txtify archive
Business owner resorts to hanging massive banner in woke Seattle to dissuade men from soliciting sex outside of his store as open air drugs and crime run rampant txtify archive
Trump marks 80th birthday, now second octogenarian sitting president: 'Seemed to utterly defy age' txtify archive
Inside the final hours of tragic NFL star Aldon Smith: How friends desperately tried to revive struggling ex-49ers linebacker before his death at just 36 txtify archive
Inside the disappearance of Hollywood starlet Jean Spangler that saw Kirk Douglas dragged into investigation... after mysterious note bombshell txtify archive
NBA champion Trevor Ariza stuns fans by revealing tiny monthly salary in bitter custody battle... despite earning $116 MILLION in his career txtify archive
Angelina Jolie allegedly tried to get back with Brad Pitt but he REJECTED her... sparking 'campaign' of revenge: Sensational untold claims about feud and relentless 'parental alienation' plot txtify archive
These 11 upcoming Supreme Court decisions could make or break Trump's second term agenda txtify archive
Party Poopers' Fight Card: Jane Fonda, 'No Kings,' communists roll out rival spectacle to Trump's 250th txtify archive
Biden-appointed judge orders Trump to restore slavery, climate change references at national parks txtify archive
Simple-looking equation proves difficult to solve - can you remember special rule only geniuses can? txtify archive
Secret evidence filed in Anna Kepner Carnival cruise murder case as feds push to jail accused stepbrother txtify archive
Trump turns 80! The president kicks off his new decade with an over-the-top White House bash…. as bruised hands and swollen ankles escalate health fears txtify archive
Alleged Malibu serial squatter featured in new docuseries after years of homeowner complaints txtify archive
Partner of woman killed by dogs recently saved neighbor wounded in similar attack: court records txtify archive
'The Office' star blasts political 'hypocrisy,' explains why sitcom couldn't be made today txtify archive
Inside the frightening phenomena of the Black-Eyed Children who knock on people's doors pleading for help then vanish txtify archive
Two suspects arrested after crashing through Camp Pendleton gate with 112 pounds of cocaine and fentanyl txtify archive
Fox News Campus Radicals Newsletter: Anti-Kirk teacher honored, ICE supporter expelled, Pride display problem txtify archive
Judge defends barring cameras from Karmelo Anthony murder trial, says it was 'an easy decision' txtify archive
Courteney Cox shares rare photos of her and ex David Arquette's daughter Coco as she turns 22 txtify archive
Florida man arrested for DUI after troopers allegedly find 34 open alcohol containers in vehicle txtify archive
California couple fights off 70-pound black bear with hatchet and water bottle outside their home txtify archive
A popular boat combo! Beatles biopic recreates Paul and Ringo's 1964 yacht trip with girlfriends txtify archive
Tragic secret life of Knicks star OG Anunoby: Insiders on family agony that forged an NYC icon… that London boy accent… and the A-list romance mystery everyone's whispering about txtify archive
CBP, Coast Guard intercept migrant vessel heading for Puerto Rico; 40 apprehended including Uzbek national txtify archive
Vincent's parents 'never say he's good enough' - so he turned to a middle-aged couple online txtify archive
Obama Presidential Center's $470M safety net under scrutiny as subcontractors say they're owed millions txtify archive
Trump picks James McDonald to lead powerful Southern District of New York after Jay Clayton's departure txtify archive
Rubio, Newsom share World Cup spotlight at US opener as 2028 presidential speculation swirls txtify archive
Multiple people wounded in shooting at South Carolina's largest mall; authorities detain suspects txtify archive
Mexican authorities discover body in trunk near Iranian soccer team's World Cup training grounds: report txtify archive
Helicopter footage captures Florida man allegedly abandoning child during high-speed chase from deputies txtify archive
Residents wake up screaming as cops race to rescue them from late-night apartment blaze: video txtify archive
Workers rip Trump's name from Kennedy center facade months after it goes on, hours after failed appeal txtify archive
'Hell on Wheels' killer Mackenzie Shirilla lands cushy prison job after complaining she is bored behind bars txtify archive
Four accused in alleged anti-Israel University of Michigan threat case released on bond txtify archive
The puzzling case of the two Dan Sullivans: Senate election race probed as rival alleges sneaky trick used to try and swing vote txtify archive
EXCLUSIVE: Collins pits record built in Maine potato fields against Platner's 'angry rhetoric' txtify archive
UNRWA fires 70 Gaza staffers amid allegations of Hamas ties, says terminations not admission of guilt txtify archive
‘Hell on wheels’ killer Mackenzie Shirilla lands prison job while serving life sentence for fatal 2022 crash txtify archive
Hasan Piker celebrates America being 'closer than ever' to socialism as he backs NYC candidates txtify archive
Menendez brothers eyed $20M insurance payout after parents' murders, Jose's ex-business partner claims txtify archive
Platner's 'deranged' response to Musk becoming a trillionaire sparks online outrage: 'Loserthink' txtify archive
Convicted killer Karmelo Anthony sentenced to 35 years after yearlong legal battle: Timeline txtify archive
Woman airlifted to hospital with serious injuries after shark attack at popular Sydney beach txtify archive
CVE-2026-40034 gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule txtify archive
CVE-2026-5223 Crates in third party registries can override the cached source of other crates txtify archive
CVE-2023-5678 Excessive time spent in DH check / generation with large Q parameter value txtify archive
CVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes txtify archive
CVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() txtify archive
CVE-2026-44705 tmp: Path Traversal via unsanitized prefix/postfix enables directory escape txtify archive
CVE-2026-47162 Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name txtify archive
CVE-2026-47167 Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex txtify archive
Moment Brit taunts Ryanair passengers when flight to Spanish holiday island is forced to divert to Portugal after chaos on board txtify archive
Ukrainian national who completed Air Force officer training convicted in ghost gun 3D printing operation txtify archive
Federal judge rules she lacks authority to reinstate fired Yosemite ranger who flew trans pride flag txtify archive
Ohio police chief arrested in Florida after grand jury hands down 70-count child sex indictment txtify archive
California Dems accused of putting sanctuary law over migrant child welfare checks: 'Real children' txtify archive
Trump's name to be removed from Kennedy Center as appeals court denies board's request for administrative stay txtify archive
It’s not a ‘deal.’ But Trump’s memorandum with Iran can be the start of something bigger. txtify archive
Putin's new humiliation on the 'highway of death': How Ukraine has paralysed key Russian supply route with drones hunting down military convoys day and night txtify archive
Mike Waltz says Gulf allies back Trump’s Iran pressure campaign after regional trip: ‘Zero daylight’ txtify archive
Naval Research Laboratory Receives Space Force Antenna, Expanding Joint Space Capabilities txtify archive
Dispatch from Istanbul: Why Turkey is throwing its weight behind ‘zero waste’ ahead of COP31 txtify archive
Where-fur art thou Romeo? Rogue cat invades stage and plays with actor's hair during emotional death scene in Shakespeare play txtify archive
Teen accused of killing elderly couple has brothers who allegedly shot deputy cops say 'will never walk again' txtify archive
Deceased gunman identified after shooting in Midland, Texas, leaves 1 dead, 10 wounded txtify archive
Billionaire hedge fund tycoon buys one of the world's most expensive superyachts at $400m txtify archive
British couple who abandoned their three young children at Spanish hotel to 'go partying' are given suspended jail terms and banned from going near their kids txtify archive
Bigfoot fever grips Canada after spate of sasquatch 'sightings' as witness describes 'massive figure' with 'earthy' smell txtify archive
Satellite images reveal Putin 'is preparing for war with Europe' as UK's defence plans descend into chaos txtify archive
Millionaire German heiress, 26, is mysteriously found shot dead a day after 'close friend' died from gunshot wounds at the same South African safari lodge txtify archive
ISC Stormcast For Friday, June 12th, 2026 https://isc.sans.edu/podcastdetail/9970, (Fri, Jun 12th) txtify archive
World’s Food Supply Imperiled by Iran War, Fertilizer Manufacturer Fertiglobe Chief Says txtify archive
Department of War Publishes Third Release of Unidentified Anomalous Phenomena Files on WAR.GOV/UFO txtify archive
Tran cited in European Policy Center on the size of the euro denominated international transactions txtify archive
World Cup embarrassment as hundreds of seats are left empty for South Korea-Czechia... despite FIFA boasting of 'unprecedented' demand txtify archive
Germany’s Bundesbank Cuts Growth Expectation, Raises Inflation Forecast as War Drags On txtify archive
CVE-2026-46643 Snappy: Binary path is never shell-escaped due to an inverted is_executable check txtify archive
Former South Korean President Yoon Suk Yeol sentenced to 30 years over North Korea drone flights txtify archive
Socialite, 65, who ran over and killed Moroccan mugger who stole her bag is given 18-year sentence in Italy txtify archive
Did missing Michele fall victim to Epstein sex trafficking ring? Mystery of German, 22, who vanished 11 years ago after model scout told paedophile tycoon about woman 'you will love' txtify archive
Starmer in 'seismic' crisis, UK defense chief quits before high-stakes Trump NATO summit txtify archive
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities txtify archive
Inside Tehran: Iranians describe IRGC's brutal rule, poverty — ask Trump to 'stay the course' txtify archive
To stop Chinese dual-use battery dominance, the United States and South Korea need to team up txtify archive
Caribbean countries are feeling the squeeze from this energy crisis—and not just from gas prices txtify archive
Pope Leo hits beaches of popular European migrant entry point after criticizing global immigration policies txtify archive
Missing British mother returns home 'safe and sound' two weeks after she vanished in Paris txtify archive
ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories txtify archive
Christian leaders hold emergency summit in Jerusalem to confront global rise in antisemitism txtify archive
CVE-2026-8829 HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities txtify archive
CVE-2026-5419 Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal txtify archive
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution txtify archive
CVE-2026-42012 Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans txtify archive
CVE-2026-5260 Gnutls: gnutls: information disclosure via heap overread in rsa key exchange txtify archive
CVE-2026-42015 Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling txtify archive
CVE-2026-42013 Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name txtify archive
CVE-2026-50263 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow() txtify archive
CVE-2026-50258 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels txtify archive
CVE-2026-50257 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence() txtify archive
CVE-2026-50259 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing txtify archive
CVE-2026-50260 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter() txtify archive
CVE-2026-50262 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes txtify archive
CVE-2026-50256 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch txtify archive
CVE-2026-50261 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter() txtify archive
CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders txtify archive
CVE-2026-43958 Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service txtify archive
CVE-2026-44185 Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` txtify archive
CVE-2026-44631 Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow txtify archive
CVE-2026-43951 Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash txtify archive
CVE-2026-44119 Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules txtify archive
CVE-2026-48913 Apache HTTP Server: mod_http2 memory corruption when file handles exhausted txtify archive
CrowdStrike Named an Innovation and Growth Leader in the 2026 Frost Radar™: Cloud and Application Runtime Security txtify archive
ISC Stormcast For Thursday, June 11th, 2026 https://isc.sans.edu/podcastdetail/9968, (Thu, Jun 11th) txtify archive
Colombian lawmakers seek suspension of Trump foe Gustavo Petro over alleged meddling in upcoming election txtify archive
Increasing defense spending isn’t enough. The US and its allies must also guarantee interoperability. txtify archive
Britain introduces sweeping new powers to target foreign state-linked groups including Iran's IRGC txtify archive
World court prosecutor who went after Netanyahu for war crimes suspended over sexual misconduct txtify archive
British Muslim police group called IDF a terrorist organization, questioned Hamas atrocity reports txtify archive
How Predators use Marketing Tools, AI & Bad UK Regulations to get into your Kid’s Bedroom The Digital Predator Toolkit "Yellow Bus" comments txtify archive
CVE-2026-45482 Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability txtify archive
CVE-2026-40371 Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability txtify archive
From diversification to integration: A market-based LNG coordination mechanism in Europe txtify archive
CISA Issues New Directive Improving How Federal Agencies Prioritize the Mitigation of Cyber Vulnerabilities txtify archive
EXCLUSIVE: Serbian President Vučić says support for US 'surged' under Trump, invites him to visit Belgrade txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
How has use of framing protection security headers changed in the past 3 years?, (Wed, Jun 10th) txtify archive
CVE-2026-49762 Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service txtify archive
CVE-2026-43059 Bluetooth: MGMT: Fix list corruption and UAF in command complete handlers txtify archive
CVE-2026-46293 clk: microchip: mpfs-ccc: fix out of bounds access during output registration txtify archive
CVE-2026-46280 lib: test_hmm: evict device pages on file close to avoid use-after-free txtify archive
CVE-2026-46275 Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths txtify archive
‘A terrible risk’: Senate appropriators dim prospects of another defense reconciliation bill txtify archive
ISC Stormcast For Wednesday, June 10th, 2026 https://isc.sans.edu/podcastdetail/9966, (Wed, Jun 10th) txtify archive
Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility txtify archive
US Energy Secretary Chris Wright: It will take ‘many months’ to get back to normal after this energy crisis txtify archive
Bystanders hailed as 'heroic' after intervening in brutal knife attack by Sudanese migrant in UK txtify archive
Iran accelerates execution campaign against anti-regime activists amid internet censorship txtify archive
CVE-2025-10263 ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel] txtify archive
CVE-2026-40409 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-40404 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-33828 Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability txtify archive
CVE-2026-34335 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45487 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-45639 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability txtify archive
CVE-2026-45606 Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability txtify archive
CVE-2026-45642 Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability txtify archive
CVE-2026-45648 Windows Active Directory Domain Services Remote Code Execution Vulnerability txtify archive
CVE-2026-40371 Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability txtify archive
CVE-2026-45482 Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability txtify archive
CVE-2026-45586 Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability txtify archive
CVE-2026-45594 Windows Application Identity (AppID) Information Disclosure Vulnerability txtify archive
CVE-2026-45597 Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-45601 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45598 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45596 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45602 Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability txtify archive
CVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45603 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45647 Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability txtify archive
CVE-2026-42910 Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-42836 Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-42908 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability txtify archive
CVE-2026-42911 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-44809 Windows Common Log File System Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-44805 Windows Network Controller (NC) Host Agent Denial of Service Vulnerability txtify archive
CVE-2020-17103 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability txtify archive
War Department Leaders Observe Kansas City's Counter-Drone Preparations Ahead of World Cup txtify archive
Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models txtify archive
CVE-2026-7774 tarfile.data_filter path traversal bypass allows writing outside the extraction directory txtify archive
CVE-2026-8643 pip can extract console_scripts and gui_scripts outside installation directory txtify archive
CVE-2026-43958 Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service txtify archive
CVE-2026-10722 cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow txtify archive
CVE-2026-37460 Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. txtify archive
CVE-2026-50219 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, txtify archive
CVE-2026-50292 In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution txtify archive
CVE-2026-42507 Arbitrary inputs are included in errors without any escaping in net/textproto txtify archive
CVE-2026-50031 ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands "ipmi-oem dell get-active-directory-config" and "ipmi-oem fujitsu get-sel-entry-long-text" were found to have exploitable buffer overflows on response messages. txtify archive
CVE-2026-48959 IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward txtify archive
CVE-2025-15649 IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date txtify archive
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob txtify archive
CVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification txtify archive
CVE-2026-42789 Non-CA certificate accepted as intermediate issuer in public_key path validation txtify archive
CVE-2026-40510 OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c txtify archive
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent txtify archive
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
CVE-2026-23479 redis-server use-after-free in unblock client flow may allow remote code execution txtify archive
CVE-2026-25243 redis-server RESTORE invalid memory access may allow remote code execution txtify archive
CVE-2026-27144 Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile txtify archive
CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile txtify archive
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template txtify archive
CVE-2026-50263 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow() txtify archive
CVE-2026-50258 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels txtify archive
CVE-2026-50257 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence() txtify archive
CVE-2026-50259 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing txtify archive
CVE-2026-50260 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter() txtify archive
CVE-2026-50262 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes txtify archive
CVE-2026-50256 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch txtify archive
CVE-2026-50261 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter() txtify archive
CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders txtify archive
CVE-2026-40930 LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body txtify archive
CVE-2026-50265 Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292 txtify archive
CrowdStrike 2026 Technology Threat Landscape Report: China’s Ambitions Fuel Attacks txtify archive
June 2026 Patch Tuesday: Microsoft Patches 206 Vulnerabilities Including Three Publicly Disclosed Zero-Days txtify archive
ISC Stormcast For Tuesday, June 9th, 2026 https://isc.sans.edu/podcastdetail/9964, (Tue, Jun 9th) txtify archive
DOW Releases List of Chinese Military Companies in Accordance With Section 1260H of the National Defense Authorization Act for Fiscal Year 2021 txtify archive
ISC Stormcast For Monday, June 8th, 2026 https://isc.sans.edu/podcastdetail/9962, (Mon, Jun 8th) txtify archive
The women raped by the Taliban: Victims describe horrific sexual abuse at the hands of multiple men as punishment for getting a job or posting on social media txtify archive
CVE-2026-7774 tarfile.data_filter path traversal bypass allows writing outside the extraction directory txtify archive
CVE-2026-8643 pip can extract console_scripts and gui_scripts outside installation directory txtify archive
CVE-2026-8829 HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities txtify archive
CVE-2026-43958 Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service txtify archive
CVE-2026-5419 Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal txtify archive
CVE-2026-42507 Arbitrary inputs are included in errors without any escaping in net/textproto txtify archive
CVE-2026-37460 Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. txtify archive
CVE-2026-10722 cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow txtify archive
CVE-2026-50219 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, txtify archive
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution txtify archive
Inside the Russian resistance looking to bring down Putin: Exclusive footage shows pro-Ukraine 'Black Spark' rebels 'carrying out bomb attacks on strategic targets' txtify archive
Inside South Africa's whites-only enclave where young people are flocking after deciding 'it's not so wonderful elsewhere' and it's nicer to be 'the majority' txtify archive
Readout of Secretary of War Pete Hegseth's Meeting With French Minister of the Armed Forces Catherine Vautrin txtify archive
India’s energy security at a crossroads: The Hormuz crisis and an opportunity for US-India cooperation txtify archive
Innovation as resilience: Demand-side strategies for critical mineral supply chain security txtify archive
Chhangani’s piece on digital yuan cited in European Central Bank’s report on the international role of the euro txtify archive
CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html txtify archive
CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
Chhangani’s research on China’s Cross-border Interbank Payment System cited in Asia Times txtify archive
تفتت الفصائل المسلحة العراقية بعد تحول النظام الإيراني من الثيوقراطية الى الجنتوقراطية txtify archive
CVE-2026-9149 Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file txtify archive
CVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums txtify archive
CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent txtify archive
CVE-2026-42506 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh txtify archive
CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-43964 Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number. txtify archive
CVE-2026-41140 Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4 txtify archive
CVE-2026-35414 OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters. txtify archive
Charai for The National Interest: Iran’s Mafia State Understands Only Law Backed by Power txtify archive
CVE-2026-42151 Prometheus Azure AD remote write OAuth client secret exposed via config API txtify archive
CVE-2026-8177 XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences txtify archive
CVE-2026-43895 jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts txtify archive
CVE-2026-43894 jq: Wild stack write via signed-integer overflow in decNumber D2U() macro txtify archive
CVE-2026-40226 In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. txtify archive
CVE-2026-5223 Crates in third party registries can override the cached source of other crates txtify archive
CVE-2026-27144 Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile txtify archive
CVE-2026-41889 pgx: SQL Injection via placeholder confusion with dollar quoted string literals txtify archive
CVE-2026-8466 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy txtify archive
CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile txtify archive
CVE-2026-39834 Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh txtify archive
CVE-2026-42506 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-32283 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls txtify archive
CVE-2026-39829 Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-39825 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil txtify archive
CVE-2026-46597 Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh txtify archive
CVE-2026-39830 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh txtify archive
CVE-2026-32282 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix txtify archive
CVE-2026-39819 Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go txtify archive
CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna txtify archive
CVE-2026-29181 OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) txtify archive
CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net txtify archive
CVE-2026-39882 OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies txtify archive
CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent txtify archive
CVE-2025-13462 tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
CVE-2026-33846 Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly txtify archive
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template txtify archive
CVE-2026-23479 redis-server use-after-free in unblock client flow may allow remote code execution txtify archive
CVE-2026-25243 redis-server RESTORE invalid memory access may allow remote code execution txtify archive
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-6383 Kubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluation txtify archive
CVE-2025-58160 Tracing logging user input may result in poisoning logs with ANSI escape sequences txtify archive
CVE-2026-3832 Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response txtify archive
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh txtify archive
CVE-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 txtify archive
CVE-2026-37457 An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component. txtify archive
CVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 txtify archive
CVE-2026-6842 Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions txtify archive
CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html txtify archive
CVE-2025-60876 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
CVE-2025-58186 Lack of limit when parsing cookies can cause memory exhaustion in net/http txtify archive
CVE-2026-4948 Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization txtify archive
CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs txtify archive
CVE-2026-40356 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message. txtify archive
CVE-2025-55554 pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long(). txtify archive
CVE-2026-40355 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message. txtify archive
CVE-2025-55551 An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation. txtify archive
CVE-2026-41526 In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection. txtify archive
CVE-2026-42009 Gnutls: gnutls: denial of service via dtls packet reordering vulnerability txtify archive
CVE-2024-58266 The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection. txtify archive
CVE-2026-45803 gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection txtify archive
CVE-2026-6357 pip self-update functionality can import newly installed modules after wheel installation txtify archive
CVE-2025-46327 Go Snowflake Driver has race condition when checking access to Easy Logging configuration file txtify archive
CVE-2026-8328 FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address txtify archive
CVE-2025-46394 In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences. txtify archive
CVE-2026-8368 LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects txtify archive
CVE-2024-58251 In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim. txtify archive
CVE-2026-43968 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1 txtify archive
CVE-2025-29923 go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment txtify archive
CVE-2026-7790 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS txtify archive
CVE-2026-43969 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1 txtify archive
CVE-2024-7598 Network restriction bypass via race condition during namespace termination txtify archive
CVE-2026-40225 In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output. txtify archive
CVE-2026-7210 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection txtify archive
CVE-2026-34956 Openvswitch: open vswitch: denial of service via malformed ftp epasv command txtify archive
CVE-2025-1180 GNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruption txtify archive
CVE-2024-30896 InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organizations. A future release of InfluxDB 2.x will remove the ability to retrieve tokens from the API. txtify archive
CVE-2026-42304 Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains txtify archive
CVE-2019-11254 Kubernetes API Server denial of service vulnerability from malicious YAML payloads txtify archive
CVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() txtify archive
CVE-2013-1633 easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product. txtify archive
CVE-2026-6100 Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure txtify archive
CVE-2023-27043 The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python. txtify archive
Five charts that show Latin America’s search for economic growth starts in health systems txtify archive
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor txtify archive
Airlines Called Sustainable Fuel the Future. When an Energy Crisis Broke Out, Barely Any Was Around. txtify archive
CVE-2025-15649 IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date txtify archive
CVE-2026-25833 Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function txtify archive
CVE-2026-34873 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. txtify archive
CVE-2026-34874 An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0. txtify archive
CVE-2025-15504 lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference txtify archive
CVE-2026-34875 An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. txtify archive
CVE-2026-34871 An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). txtify archive
CVE-2026-21711 A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose local IPC endpoints, allowing communication with other processes on the same host outside of the intended network restriction boundary. This vulnerability affects Node.js **25.x** processes using the Permission Model where `--allow-net` is intentionally omitted to restrict network access. Note that `--allow-net` is currently an experimental feature. txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2026-25835 Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). txtify archive
CVE-2026-33672 Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching txtify archive
CVE-2026-34872 An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle). txtify archive
CVE-2017-3736 There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen. txtify archive
CVE-2025-66442 In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. txtify archive
CVE-2026-34876 An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API. txtify archive
CVE-2026-42015 Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling txtify archive
CVE-2026-9538 Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header txtify archive
CVE-2026-7259 Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() txtify archive
CVE-2026-7262 NULL pointer dereference in SOAP apache:Map decoder with missing <value> txtify archive
CVE-2026-46121 mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock txtify archive
CVE-2026-7261 SoapServer session-persisted object use-after-free via SOAP header fault txtify archive
CVE-2026-35579 CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports txtify archive
CVE-2026-34757 LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure txtify archive
CVE-2026-6402 webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins txtify archive
CVE-2026-41080 libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. txtify archive
CVE-2026-42506 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html txtify archive
CVE-2026-39834 Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh txtify archive
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh txtify archive
CVE-2026-39830 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh txtify archive
CVE-2026-39829 Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-39832 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent txtify archive
CVE-2026-42508 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts txtify archive
CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent txtify archive
CVE-2026-21717 A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**. txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-46597 Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh txtify archive
CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna txtify archive
CVE-2026-46595 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh txtify archive
CVE-2026-39831 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh txtify archive
CVE-2026-39824 Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows txtify archive
CVE-2025-14575 Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading txtify archive
CVE-2026-8723 qs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesOnly txtify archive
CVE-2026-42009 Gnutls: gnutls: denial of service via dtls packet reordering vulnerability txtify archive
CVE-2025-23167 A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade. txtify archive
CVE-2026-48959 IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward txtify archive
CVE-2026-6324 Libsoup: libsoup: http request smuggling via unsigned to signed conversion error txtify archive
CVE-2026-10028 Glib-networking: infinite loop in glib-networking gnutls backend allows remote denial of service via circular certificate chain txtify archive
Experts react: Colombia’s presidential runoff pits the far right against the far left. What’s next? txtify archive
The 2025 Africa Cup of Nations was an economic success. Here’s how other tournaments can replicate it. txtify archive
US-Caribbean maritime cooperation: Why stronger ports, supply chains, and security matter now txtify archive
CVE-2026-39829 Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna txtify archive
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh txtify archive
CrowdStrike Brings Enterprise-Grade Security to the AI Factory with NVIDIA Vera BlueField-4 STX txtify archive
CVE-2026-21717 A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**. txtify archive
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) txtify archive
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) txtify archive
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) txtify archive
CVE-2025-23167 A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade. txtify archive
CVE-2024-36137 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file. txtify archive
CVE-2024-22018 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js. txtify archive
CVE-2026-40034 gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule txtify archive
CVE-2025-15649 IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date txtify archive
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob txtify archive
CVE-2026-25833 Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function txtify archive
CVE-2026-34873 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. txtify archive
CVE-2026-34874 An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0. txtify archive
CVE-2025-15504 lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference txtify archive
CVE-2026-34875 An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. txtify archive
CVE-2026-34871 An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2026-25835 Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). txtify archive
CVE-2026-33672 Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching txtify archive
CVE-2026-34872 An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle). txtify archive
CVE-2017-3736 There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen. txtify archive
CVE-2025-66442 In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. txtify archive
CVE-2026-34876 An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API. txtify archive
CVE-2026-48864 Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data txtify archive
CVE-2026-9804 Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read txtify archive
CVE-2026-7374 Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability txtify archive
CVE-2026-42012 Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans txtify archive
CVE-2026-5260 Gnutls: gnutls: information disclosure via heap overread in rsa key exchange txtify archive
CVE-2026-42015 Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling txtify archive
CVE-2026-42013 Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name txtify archive
CVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification txtify archive
CVE-2026-42789 Non-CA certificate accepted as intermediate issuer in public_key path validation txtify archive
CVE-2026-40510 OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c txtify archive
CVE-2026-21711 A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose local IPC endpoints, allowing communication with other processes on the same host outside of the intended network restriction boundary. This vulnerability affects Node.js **25.x** processes using the Permission Model where `--allow-net` is intentionally omitted to restrict network access. Note that `--allow-net` is currently an experimental feature. txtify archive
Secretary of War Pete Hegseth Holds a Press Availability at the U.S. Embassy in Singapore txtify archive
CVE-2026-46138 Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt txtify archive
CVE-2026-46196 tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() txtify archive
CVE-2026-46149 scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() txtify archive
CVE-2026-46180 wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task txtify archive
CVE-2026-46209 drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() txtify archive
CVE-2026-46174 x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache txtify archive
CVE-2026-46121 mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock txtify archive
CVE-2026-46147 KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu() txtify archive
CVE-2026-46187 wifi: rsi: fix kthread lifetime race between self-exit and external-stop txtify archive
CVE-2026-46227 sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL txtify archive
Signing is the easy part: Two former US negotiators on the perils of implementing a deal with Iran txtify archive
CVE-2026-26168 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-24293 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-41088 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45859 netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation txtify archive
CVE-2026-46033 crypto: authencesn - reject short ahash digests during instance creation txtify archive
CVE-2026-46094 ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access txtify archive
CVE-2026-45934 btrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation txtify archive
CVE-2026-46174 x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache txtify archive
CVE-2026-46121 mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock txtify archive
CVE-2026-9538 Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header txtify archive
CVE-2026-42497 Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory txtify archive
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory txtify archive
CVE-2026-46138 Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt txtify archive
CVE-2026-46147 KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu() txtify archive
CVE-2026-46187 wifi: rsi: fix kthread lifetime race between self-exit and external-stop txtify archive
CVE-2026-46227 sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL txtify archive
CVE-2026-46132 net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo txtify archive
CVE-2026-46196 tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() txtify archive
CVE-2026-46149 scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() txtify archive
CVE-2026-46159 btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak txtify archive
CVE-2026-46180 wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task txtify archive
CVE-2026-46209 drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() txtify archive
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter txtify archive
CVE-2026-5223 Crates in third party registries can override the cached source of other crates txtify archive
CVE-2026-9149 Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file txtify archive
CVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums txtify archive
CVE-2026-46597 Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh txtify archive
CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent txtify archive
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh txtify archive
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html txtify archive
CVE-2026-46094 ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access txtify archive
CVE-2026-45934 btrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation txtify archive
CVE-2026-45956 drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl() txtify archive
CVE-2026-46065 fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info txtify archive
CVE-2026-45859 netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation txtify archive
CVE-2026-46040 inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails txtify archive
CVE-2026-45571 go-git: Crafted repositories may modify main and submodule .git directories txtify archive
CVE-2026-46033 crypto: authencesn - reject short ahash digests during instance creation txtify archive
CVE-2026-46088 ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() txtify archive
CVE-2026-46075 crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path txtify archive
CVE-2026-46011 media: mtk-jpeg: fix use-after-free in release path due to uncancelled work txtify archive
CVE-2026-40225 In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output. txtify archive
CVE-2026-40226 In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. txtify archive
CVE-2026-5223 Crates in third party registries can override the cached source of other crates txtify archive
CVE-2026-8466 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy txtify archive
CVE-2026-6402 webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins txtify archive
CVE-2026-9149 Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file txtify archive
CVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums txtify archive
CVE-2026-42508 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts txtify archive
CVE-2026-46595 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh txtify archive
CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent txtify archive
CVE-2026-39832 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent txtify archive
CVE-2026-39834 Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh txtify archive
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh txtify archive
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-39831 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh txtify archive
CVE-2026-46597 Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh txtify archive
CVE-2026-39830 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh txtify archive
CVE-2026-39829 Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-39824 Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows txtify archive
CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html txtify archive
CVE-2026-42506 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna txtify archive
CVE-2026-8376 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds txtify archive
CVE-2026-43503 net: skbuff: propagate shared-frag marker through frag-transfer helpers txtify archive
CISA Announces Revised Town Hall Schedule to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure txtify archive
CVE-2026-44283 etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks txtify archive
CVE-2026-43968 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1 txtify archive
CVE-2026-7790 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS txtify archive
CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net txtify archive
CVE-2026-41054 Missing exit out of permission check in haveged could lead to root exploit txtify archive
CVE-2026-7246 Pallets Click contains a command injection via Unsanitized Filename "click.edit()" txtify archive
CVE-2026-44390 Unbounded name compression in certain cases causes degradation of service txtify archive
CVE-2025-51480 Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions. txtify archive
CVE-2026-41035 In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable. txtify archive
CVE-2026-42960 Possible cache poisoning via promiscuous records for the authority section txtify archive
CVE-2026-29518 Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write txtify archive
CVE-2025-14575 Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading txtify archive
CVE-2026-8723 qs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesOnly txtify archive
CVE-2026-41054 Missing exit out of permission check in haveged could lead to root exploit txtify archive
CVE-2026-42009 Gnutls: gnutls: denial of service via dtls packet reordering vulnerability txtify archive
CVE-2026-3593 Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation txtify archive
Media Invitation Announced for United States v. Khalid Shaikh Mohammad et al. Pre-Trial Hearing txtify archive
CVE-2026-23383 bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing txtify archive
CVE-2026-43416 powerpc, perf: Check that current->mm is alive before getting user callchain txtify archive
CVE-2026-23272 netfilter: nf_tables: unconditionally bump set->nelems before insertion txtify archive
CVE-2026-43101 ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() txtify archive
CVE-2025-38585 staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int() txtify archive
CVE-2025-38269 btrfs: exit after state insertion failure at btrfs_convert_extent_bit() txtify archive
CVE-2025-38279 bpf: Do not include stack ptr register in precision backtracking bookkeeping txtify archive
CVE-2026-43161 iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode txtify archive
CVE-2026-31771 Bluetooth: hci_event: move wake reason storage into validated event handlers txtify archive
CVE-2025-68190 drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked() txtify archive
CVE-2026-43049 HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure txtify archive
CVE-2026-6357 pip self-update functionality can import newly installed modules after wheel installation txtify archive
CVE-2026-31592 KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock txtify archive
CVE-2025-37861 scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue txtify archive
CVE-2024-26672 drm/amdgpu: Fix variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()' txtify archive
CVE-2026-31536 smb: server: let send_done handle a completion without IB_SEND_SIGNALED txtify archive
CVE-2025-39932 smb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work) txtify archive
CVE-2025-39905 net: phylink: add lock for serializing concurrent pl->phydev writes with resolver txtify archive
CVE-2026-31767 drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode txtify archive
CVE-2024-50217 btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids() txtify archive
CVE-2026-43496 net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked txtify archive
CVE-2026-43495 net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler txtify archive
Military Commissions Media Invitation Announced for United States v. Abd al-Rahim al-Nashiri Pre-Trial Hearing txtify archive
CVE-2026-43970 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame txtify archive
CVE-2026-45803 gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection txtify archive
CVE-2026-44390 Unbounded name compression in certain cases causes degradation of service txtify archive
CVE-2026-42960 Possible cache poisoning via promiscuous records for the authority section txtify archive
CVE-2026-29518 Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write txtify archive
CVE-2026-47783 In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass. txtify archive
CVE-2026-47784 In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass. txtify archive
CVE-2026-46483 Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag txtify archive
CVE-2026-34956 Openvswitch: open vswitch: denial of service via malformed ftp epasv command txtify archive
Military Commissions Media Invitation Announced for United States v. Encep Nurjaman Pre-Trial Hearing txtify archive
CVE-2026-8328 FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address txtify archive
CVE-2026-7246 Pallets Click contains a command injection via Unsanitized Filename "click.edit()" txtify archive
CVE-2026-43443 ASoC: amd: acp-mach-common: Add missing error check for clock acquisition txtify archive
CVE-2026-44662 rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-padding txtify archive
CVE-2026-41673 xmldom: Denial of service via uncontrolled recursion in XML serialization txtify archive
CVE-2026-41675 xmldom: XML node injection through unvalidated processing instruction serialization txtify archive
CVE-2026-43868 Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern txtify archive
CVE-2026-41082 In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. txtify archive
CVE-2026-25833 Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function txtify archive
CVE-2026-34872 An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle). txtify archive
CVE-2026-34871 An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). txtify archive
CVE-2026-7210 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection txtify archive
CVE-2026-34873 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. txtify archive
CVE-2025-66442 In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. txtify archive
CVE-2026-42011 Gnutls: gnutls: security bypass due to incorrect name constraint handling txtify archive
CVE-2026-25835 Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). txtify archive
CVE-2026-34876 An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API. txtify archive
CVE-2026-34874 An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0. txtify archive
CVE-2026-3833 Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison txtify archive
CVE-2026-43219 net: cpsw_new: Fix potential unregister of netdev that has not been registered yet txtify archive
CVE-2026-6210 Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash txtify archive
CVE-2026-43176 wifi: rtw89: pci: validate release report content before using for RTL8922DE txtify archive
CVE-2026-39819 Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go txtify archive
CVE-2026-40170 ngtcp2 has a qlog transport parameter serialization stack buffer overflow txtify archive
CVE-2026-39825 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil txtify archive
CVE-2026-34757 LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure txtify archive
CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net txtify archive
CVE-2025-8224 GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference txtify archive
CVE-2026-31715 f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io() txtify archive
CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs txtify archive
CVE-2026-6357 pip self-update functionality can import newly installed modules after wheel installation txtify archive
CVE-2026-45186 In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. txtify archive
CVE-2026-42256 net-imap: Denial of service via high iteration count for `SCRAM-*` authentication txtify archive
CVE-2026-37459 An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. txtify archive
CVE-2026-37458 Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message. txtify archive
CVE-2026-28808 ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch) txtify archive
CVE-2026-41080 libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. txtify archive
CVE-2026-6477 PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory txtify archive
CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability txtify archive
CVE-2026-43308 btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() txtify archive
CVE-2026-8328 FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address txtify archive
CVE-2026-8368 LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects txtify archive
CVE-2026-7210 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection txtify archive
CVE-2026-44283 etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks txtify archive
CVE-2026-46483 Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag txtify archive
CVE-2026-44662 rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-padding txtify archive
CVE-2026-44431 urllib3: Sensitive headers forwarded across origins in proxied low-level redirects txtify archive
CVE-2026-6479 PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion txtify archive
CVE-2026-6477 PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory txtify archive
CVE-2026-6472 PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege txtify archive
CVE-2026-6475 PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice txtify archive
CVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability txtify archive
CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net txtify archive
CVE-2026-29181 OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) txtify archive
CVE-2026-43968 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1 txtify archive
CVE-2026-7790 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS txtify archive
CVE-2026-43969 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1 txtify archive
CVE-2026-7210 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection txtify archive
CVE-2026-34956 Openvswitch: open vswitch: denial of service via malformed ftp epasv command txtify archive
CVE-2026-42011 Gnutls: gnutls: security bypass due to incorrect name constraint handling txtify archive
CVE-2026-42304 Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains txtify archive
CVE-2025-48431 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error. txtify archive
CVE-2026-42151 Prometheus Azure AD remote write OAuth client secret exposed via config API txtify archive
CVE-2026-42154 Prometheus: remote read endpoint allows denial of service via crafted snappy payload txtify archive
CVE-2026-6210 Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash txtify archive
CVE-2026-8177 XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences txtify archive
CVE-2026-39819 Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go txtify archive
CVE-2026-39825 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil txtify archive
CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net txtify archive
CVE-2026-31767 drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode txtify archive
CVE-2026-43895 jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts txtify archive
CVE-2026-43894 jq: Wild stack write via signed-integer overflow in decNumber D2U() macro txtify archive
CVE-2026-34343 Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability txtify archive
CVE-2026-34344 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-34345 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-35416 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-35418 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-40380 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability txtify archive
CVE-2026-40407 Windows Common Log File System Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability txtify archive
CVE-2026-41088 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability txtify archive
CVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability txtify archive
CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-34337 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-34339 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability txtify archive
CVE-2026-34341 Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability txtify archive
CVE-2026-40397 Windows Common Log File System Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-41086 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability txtify archive
CVE-2026-41103 Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability txtify archive
CVE-2026-42830 Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability txtify archive
CVE-2026-29181 OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) txtify archive
CVE-2026-39882 OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies txtify archive
Secretary of War Pete Hegseth Hosted Bilateral Meeting With the Republic of Korea Minister of National Defense Ahn Gyu-back at the Pentagon txtify archive
GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access txtify archive
So you want to ask an OSINT subreddit for advice on how to find your third grade crush? txtify archive
CVE-2026-31592 KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock txtify archive
CVE-2026-31579 wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit txtify archive
CVE-2026-43308 btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() txtify archive
CVE-2026-43294 drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels txtify archive
CVE-2026-31536 smb: server: let send_done handle a completion without IB_SEND_SIGNALED txtify archive
CVE-2026-43299 btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure() txtify archive
CVE-2024-53201 drm/amd/display: Fix null check for pipe_ctx->plane_state in dcn20_program_pipe txtify archive
CVE-2026-43305 drm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast path txtify archive
CVE-2025-38585 staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int() txtify archive
CVE-2025-38269 btrfs: exit after state insertion failure at btrfs_convert_extent_bit() txtify archive
CVE-2026-43443 ASoC: amd: acp-mach-common: Add missing error check for clock acquisition txtify archive
CVE-2025-38279 bpf: Do not include stack ptr register in precision backtracking bookkeeping txtify archive
CVE-2026-43300 drm/panel: Fix a possible null-pointer dereference in jdi_panel_dsi_remove() txtify archive
CVE-2025-71299 spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing txtify archive
CVE-2026-43416 powerpc, perf: Check that current->mm is alive before getting user callchain txtify archive
CVE-2026-23383 bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing txtify archive
CVE-2026-23272 netfilter: nf_tables: unconditionally bump set->nelems before insertion txtify archive
CVE-2024-36024 drm/amd/display: Disable idle reallow as part of command/gpint execution txtify archive
CVE-2025-40325 md/raid10: wait barrier before returning discard request with REQ_NOWAIT txtify archive
CVE-2024-50217 btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids() txtify archive
CVE-2026-43101 ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() txtify archive
CVE-2026-43219 net: cpsw_new: Fix potential unregister of netdev that has not been registered yet txtify archive
CVE-2024-24856 NULL pointer deference in acpi_db_convert_to_package of Linux acpi module txtify archive
CVE-2024-57898 wifi: cfg80211: clear link ID from bitmap during link delete after clean up txtify archive
CVE-2025-22115 btrfs: fix block group refcount race in btrfs_create_pending_block_groups() txtify archive
CVE-2024-49945 net/ncsi: Disable the ncsi work before freeing the associated structure txtify archive
CVE-2025-21885 RDMA/bnxt_re: Fix the page details for the srq created by kernel consumers txtify archive
CVE-2025-68190 drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked() txtify archive
CVE-2024-47702 bpf: Fail verification for sign-extension of packet data/data_end/data_meta txtify archive
CVE-2026-43161 iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode txtify archive
CVE-2024-47662 drm/amd/display: Remove register from DCN35 DMCUB diagnostic collection txtify archive
CVE-2024-46834 ethtool: fail closed if we can't get max channel used in indirection tables txtify archive
CVE-2026-31715 f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io() txtify archive
CVE-2024-46727 drm/amd/display: Add otg_master NULL check within resource_log_pipe_topology_update txtify archive
CVE-2024-1151 Kernel: stack overflow problem in open vswitch kernel module leading to dos txtify archive
CVE-2025-37861 scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue txtify archive
CVE-2026-31771 Bluetooth: hci_event: move wake reason storage into validated event handlers txtify archive
CVE-2026-43049 HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure txtify archive
CVE-2024-26672 drm/amdgpu: Fix variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()' txtify archive
CVE-2024-58089 btrfs: fix double accounting race when btrfs_run_delalloc_range() failed txtify archive
CVE-2024-25740 A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released. txtify archive
CVE-2024-23848 In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c. txtify archive
CVE-2022-4543 A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems. txtify archive
CVE-2026-7259 Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() txtify archive
CVE-2026-7262 NULL pointer dereference in SOAP apache:Map decoder with missing <value> txtify archive
CVE-2026-7261 SoapServer session-persisted object use-after-free via SOAP header fault txtify archive
CVE-2026-42256 net-imap: Denial of service via high iteration count for `SCRAM-*` authentication txtify archive
CVE-2026-41889 pgx: SQL Injection via placeholder confusion with dollar quoted string literals txtify archive
CVE-2026-33079 Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles txtify archive
CVE-2026-39825 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil txtify archive
CVE-2026-39819 Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go txtify archive
CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net txtify archive
CVE-2026-3832 Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response txtify archive
CVE-2026-4948 Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization txtify archive
CVE-2026-43274 mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq() txtify archive
CVE-2026-43161 iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode txtify archive
CVE-2026-6842 Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions txtify archive
CVE-2026-43101 ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() txtify archive
CVE-2026-25589 RedisBloom RESTORE invalid memory access may allow remote code execution txtify archive
CVE-2026-25588 RedisTimeSeries RESTORE invalid memory access may allow remote code execution txtify archive
CVE-2026-23479 redis-server use-after-free in unblock client flow may allow remote code execution txtify archive
CVE-2026-25243 redis-server RESTORE invalid memory access may allow remote code execution txtify archive
CVE-2026-41673 xmldom: Denial of service via uncontrolled recursion in XML serialization txtify archive
CVE-2026-41675 xmldom: XML node injection through unvalidated processing instruction serialization txtify archive
Chromium: CVE-2026-7944 Insufficient validation of untrusted input in Persistent Cache txtify archive
CVE-2026-33821 Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability txtify archive
CVE-2026-41105 Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability txtify archive
CVE-2026-33109 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability txtify archive
CVE-2026-40379 Microsoft Enterprise Security Token Service (ESTS) Spoofing Vulnerability txtify archive
CVE-2026-33844 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability txtify archive
CVE-2026-6383 Kubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluation txtify archive
CVE-2026-34032 Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string) txtify archive
CVE-2026-34059 Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data() txtify archive
CVE-2026-33523 Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line txtify archive
CVE-2026-3832 Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response txtify archive
CVE-2026-3833 Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison txtify archive
CVE-2026-28810 Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver txtify archive
CVE-2026-43868 Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern txtify archive
CVE-2026-43101 ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() txtify archive
CVE-2026-43219 net: cpsw_new: Fix potential unregister of netdev that has not been registered yet txtify archive
CVE-2026-43237 drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 txtify archive
CVE-2026-43191 drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35 txtify archive
CVE-2026-43274 mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq() txtify archive
CVE-2026-43161 iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode txtify archive
CVE-2026-43176 wifi: rtw89: pci: validate release report content before using for RTL8922DE txtify archive
CVE-2026-42154 Prometheus: remote read endpoint allows denial of service via crafted snappy payload txtify archive
CVE-2026-42151 Prometheus Azure AD remote write OAuth client secret exposed via config API txtify archive
CVE-2026-35579 CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports txtify archive
CVE-2026-32934 CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service txtify archive
CVE-2026-32936 CoreDNS DoH GET path missing size validation causes CPU and memory amplification txtify archive
CVE-2026-33489 CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison txtify archive
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution txtify archive
CVE-2026-34003 Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access txtify archive
CVE-2026-33999 Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling txtify archive
CVE-2026-34001 Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption txtify archive
CVE-2026-41066 lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files txtify archive
GWU Interview with Chris Kubecka, Cybersecurity Expert, Journalist and Volunteer Rescue Worker comments txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs of Staff Gen. Dan Caine Hold a Press Briefing txtify archive
CVE-2026-6842 Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions txtify archive
CVE-2025-8224 GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference txtify archive
CVE-2026-27141 Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net txtify archive
CVE-2026-40170 ngtcp2 has a qlog transport parameter serialization stack buffer overflow txtify archive
CVE-2026-32148 Lockfile checksums not verified in Hex allows dependency integrity bypass txtify archive
CVE-2026-34757 LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure txtify archive
CVE-2026-6842 Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions txtify archive
CVE-2025-8224 GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference txtify archive
CVE-2026-6846 Binutils: binutils: arbitrary code execution via malformed xcoff object file processing txtify archive
CVE-2026-31608 smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list() txtify archive
CVE-2026-4948 Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization txtify archive
CVE-2026-3184 Util-linux: util-linux: access control bypass due to improper hostname canonicalization txtify archive
CVE-2026-27456 util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup txtify archive
CVE-2026-31478 ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() txtify archive
CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing txtify archive
CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling txtify archive
CVE-2026-25645 Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function txtify archive
CVE-2026-3731 libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds txtify archive
CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs txtify archive
CVE-2026-6357 pip self-update functionality can import newly installed modules after wheel installation txtify archive
CVE-2025-48431 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error. txtify archive
CVE-2026-31609 smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush() txtify archive
CVE-2026-31608 smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list() txtify archive
CVE-2026-31599 media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections txtify archive
CVE-2026-24051 OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking txtify archive
CVE-2026-41898 rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer txtify archive
CVE-2026-2708 Libsoup: libsoup: http request smuggling via duplicate content-length headers txtify archive
CVE-2026-5778 Integer underflow leads to out-of-bounds access in sniffer ChaCha decrypt path. txtify archive
CVE-2026-5295 Stack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OID txtify archive
CVE-2026-5503 out-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicName txtify archive
CVE-2026-34477 Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass txtify archive
CVE-2026-35206 Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment txtify archive
CVE-2026-3298 Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2025-15504 lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference txtify archive
CVE-2026-32283 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls txtify archive
CVE-2026-41681 rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check txtify archive
CVE-2026-41677 rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length txtify archive
CVE-2026-6409 Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input txtify archive
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) txtify archive
CVE-2026-41676 rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1 txtify archive
CVE-2026-31512 Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv() txtify archive
CVE-2026-34073 cryptography has incomplete DNS name constraint enforcement on peer names txtify archive
CVE-2026-2100 P11-kit: p11-kit: null dereference via c_derivekey with specific null parameters txtify archive
CVE-2026-31478 ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() txtify archive
CVE-2026-34043 Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects txtify archive
CVE-2026-33916 Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection txtify archive
CVE-2026-23422 dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler txtify archive
CVE-2026-33542 Incus does not verify combined fingerprint when downloading images from simplestreams servers txtify archive
CVE-2026-31576 media: hackrf: fix to not free memory after the device is registered in hackrf_probe() txtify archive
CVE-2026-1005 Integer underflow leads to out-of-bounds access in sniffer AES-GCM/CCM/ARIA-GCM decrypt path txtify archive
CVE-2026-34480 Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters txtify archive
CVE-2026-34479 Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters txtify archive
CVE-2026-34481 Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout txtify archive
CVE-2026-5460 Heap Use-After-Free in PQC Hybrid KeyShare Error Cleanup in wolfSSL TLS 1.3 txtify archive
CVE-2026-31500 Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock txtify archive
CVE-2026-31507 net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer txtify archive
CVE-2026-31619 ALSA: fireworks: bound device-supplied status before string array lookup txtify archive
CVE-2025-48431 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error. txtify archive
CVE-2026-6357 pip self-update functionality can import newly installed modules after wheel installation txtify archive
CVE-2026-31592 KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock txtify archive
CVE-2026-31588 KVM: x86: Use scratch field in MMIO fragment to hold small write values txtify archive
CVE-2026-31496 netfilter: nf_conntrack_expect: skip expectations in other netns via proc txtify archive
CVE-2026-31615 usb: gadget: renesas_usb3: validate endpoint index in standard request handlers txtify archive
CVE-2026-31536 smb: server: let send_done handle a completion without IB_SEND_SIGNALED txtify archive
CISA and U.S. Government Partners Unveil Guide to Accelerate Zero Trust Adoption in Operational Technology txtify archive
CVE-2026-31619 ALSA: fireworks: bound device-supplied status before string array lookup txtify archive
CVE-2026-31592 KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock txtify archive
CVE-2026-31578 media: as102: fix to not free memory after the device is registered in as102_usb_probe() txtify archive
CVE-2026-31576 media: hackrf: fix to not free memory after the device is registered in hackrf_probe() txtify archive
CVE-2026-31588 KVM: x86: Use scratch field in MMIO fragment to hold small write values txtify archive
CVE-2026-33056 tar-rs: unpack_in can chmod arbitrary directories by following symlinks txtify archive
CVE-2026-2369 Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources txtify archive
CVE-2026-22701 filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock txtify archive
CVE-2025-68146 filelock has TOCTOU race condition that allows symlink attacks during lock file creation txtify archive
CVE-2026-2443 Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure txtify archive
CVE-2026-31536 smb: server: let send_done handle a completion without IB_SEND_SIGNALED txtify archive
CVE-2026-41677 rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2026-41140 Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4 txtify archive
CVE-2026-34003 Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access txtify archive
CVE-2026-34001 Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption txtify archive
CVE-2026-33999 Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling txtify archive
CVE-2026-27141 Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net txtify archive
CVE-2026-24051 OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking txtify archive
CVE-2026-29181 OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) txtify archive
CVE-2026-41898 rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer txtify archive
CVE-2026-2708 Libsoup: libsoup: http request smuggling via duplicate content-length headers txtify archive
CVE-2026-41066 lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files txtify archive
CVE-2026-31670 net: rfkill: prevent unlimited numbers of rfkill events from being created txtify archive
CVE-2026-31579 wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit txtify archive
CVE-2026-31577 nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map txtify archive
CVE-2026-31552 wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom txtify archive
CVE-2026-31478 ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() txtify archive
CVE-2026-41079 OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users txtify archive
CVE-2026-33103 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability txtify archive
CVE-2026-23368 net: phy: register phy led_triggers during probe to avoid AB-BA deadlock txtify archive
CVE-2026-31592 KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock txtify archive
CVE-2026-31578 media: as102: fix to not free memory after the device is registered in as102_usb_probe() txtify archive
CVE-2026-31595 PCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanup txtify archive
CVE-2026-31576 media: hackrf: fix to not free memory after the device is registered in hackrf_probe() txtify archive
CVE-2026-31588 KVM: x86: Use scratch field in MMIO fragment to hold small write values txtify archive
CVE-2026-31579 wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit txtify archive
CVE-2026-41681 rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check txtify archive
CVE-2026-41677 rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length txtify archive
CVE-2026-31609 smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush() txtify archive
CVE-2026-41676 rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1 txtify archive
CVE-2026-31608 smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list() txtify archive
CVE-2026-31670 net: rfkill: prevent unlimited numbers of rfkill events from being created txtify archive
CVE-2026-41907 uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided txtify archive
CVE-2026-31615 usb: gadget: renesas_usb3: validate endpoint index in standard request handlers txtify archive
CVE-2026-41066 lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files txtify archive
CVE-2026-41140 Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4 txtify archive
CVE-2026-31577 nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map txtify archive
CVE-2026-23422 dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler txtify archive
CVE-2026-31599 media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections txtify archive
CVE-2026-23401 KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE txtify archive
CVE-2026-23399 nf_tables: nft_dynset: fix possible stateful expression memleak in error path txtify archive
CVE-2026-31536 smb: server: let send_done handle a completion without IB_SEND_SIGNALED txtify archive
CVE-2026-23392 netfilter: nf_tables: release flowtable after rcu grace period on error txtify archive
CVE-2026-31593 KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU txtify archive
CVE-2026-31646 net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() txtify archive
CVE-2026-31619 ALSA: fireworks: bound device-supplied status before string array lookup txtify archive
CVE-2026-41079 OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users txtify archive
CVE-2026-23439 udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n txtify archive
CVE-2026-23438 net: mvpp2: guard flow control update with global_tx_fc in buffer switching txtify archive
CVE-2026-23340 net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs txtify archive
CVE-2026-23324 can: usb: etas_es58x: correctly anchor the urb in the read bulk callback txtify archive
CVE-2026-23315 wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() txtify archive
Media Invitation Announced for United States v. Khalid Shaikh Mohammad et al. Pre-Trial Hearing txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs of Staff Gen. Dan Caine Hold a Press Briefing txtify archive
CVE-2026-31478 ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() txtify archive
CVE-2026-31500 Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock txtify archive
CVE-2026-31507 net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer txtify archive
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite txtify archive
CISA, National Cyber Security Centre (NCSC) UK, and Global Partners Issue Advisory on Chinese Government-Linked Covert Cyber Networks txtify archive
CISA Warns of FIRESTARTER Malware Targeting Cisco ASA including Firepower and Secure Firewall Products txtify archive
CVE-2026-39882 OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies txtify archive
CVE-2026-33750 brace-expansion: Zero-step sequence causes process hang and memory exhaustion txtify archive
CVE-2026-27820 zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption txtify archive
CVE-2026-6409 Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input txtify archive
CVE-2026-28808 ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch) txtify archive
CVE-2026-6507 Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing txtify archive
CVE-2026-31512 Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv() txtify archive
CVE-2026-31451 ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio txtify archive
CVE-2026-31478 ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() txtify archive
CVE-2026-31500 Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock txtify archive
CVE-2026-31507 net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer txtify archive
CVE-2026-31469 virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false txtify archive
CVE-2026-31496 netfilter: nf_conntrack_expect: skip expectations in other netns via proc txtify archive
CVE-2026-40890 github.com/gomarkdown/markdown: Out-of-bounds Read in SmartypantsRenderer txtify archive
CVE-2025-14821 Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows txtify archive
CVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() txtify archive
Honorable Jay Hurst and Lt. Gen. Steven Whitney Hold Press Briefing on the Department's Fiscal Year 2027 Defense Budget txtify archive
CVE-2026-32223 Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-26168 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-21523 GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability txtify archive
CVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() txtify archive
CVE-2026-6100 Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure txtify archive
CVE-2026-33056 tar-rs: unpack_in can chmod arbitrary directories by following symlinks txtify archive
CVE-2026-40179 Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer txtify archive
CVE-2025-14821 Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows txtify archive
CVE-2026-39956 jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure txtify archive
CVE-2026-35199 SymCrypt SymCryptXmssSign function - Heap overflow via 64->32-bit leaf-count truncation txtify archive
CVE-2026-39979 jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers txtify archive
CVE-2026-33948 jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input txtify archive
CVE-2026-33947 jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted() txtify archive
CVE-2026-32316 jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs of Staff Gen. Dan Caine Hold a Press Briefing txtify archive
CVE-2026-32223 Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-34757 LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure txtify archive
CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile txtify archive
CVE-2026-32282 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix txtify archive
CVE-2026-27144 Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile txtify archive
CVE-2026-32283 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2026-33056 tar-rs: unpack_in can chmod arbitrary directories by following symlinks txtify archive
CVE-2026-2646 Heap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function txtify archive
CVE-2026-2645 Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2 txtify archive
CVE-2026-35611 Addressable has a Regular Expression Denial of Service in Addressable templates txtify archive
CVE-2026-35093 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins txtify archive
CVE-2026-34601 xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion txtify archive
CVE-2026-4176 Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib txtify archive
CVE-2026-27171 zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition. txtify archive
CVE-2025-14523 Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins) txtify archive
CVE-2026-33940 Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial txtify archive
CVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 txtify archive
CVE-2026-33939 Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation txtify archive
CVE-2026-33941 Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options txtify archive
CVE-2026-33938 Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block txtify archive
CVE-2026-33891 Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input txtify archive
CVE-2026-33896 Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation) txtify archive
CVE-2026-1519 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation txtify archive
CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` txtify archive
CVE-2025-30258 In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS." txtify archive
CVE-2026-40175 Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain txtify archive
CVE-2026-34480 Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters txtify archive
CVE-2026-34479 Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters txtify archive
CVE-2026-34481 Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout txtify archive
CVE-2026-5460 Heap Use-After-Free in PQC Hybrid KeyShare Error Cleanup in wolfSSL TLS 1.3 txtify archive
CVE-2026-5778 Integer underflow leads to out-of-bounds access in sniffer ChaCha decrypt path. txtify archive
CVE-2026-5295 Stack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OID txtify archive
CVE-2026-5503 out-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicName txtify archive
CVE-2026-5501 Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates txtify archive
CVE-2026-5500 Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass txtify archive
CVE-2026-23653 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability txtify archive
CVE-2026-25184 Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-23670 Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability txtify archive
CVE-2026-26155 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability txtify archive
CVE-2026-26174 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-26183 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability txtify archive
CVE-2026-27908 Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-27917 Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-27921 Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-27926 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-27929 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-32071 Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability txtify archive
CVE-2026-32073 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-32082 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-32083 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-32087 Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-32093 Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-32181 Connected User Experiences and Telemetry Service Denial of Service Vulnerability txtify archive
CVE-2026-32184 Microsoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability txtify archive
CVE-2026-32216 Windows Redirected Drive Buffering System Denial of Service Vulnerability txtify archive
CVE-2026-32223 Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-32224 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-33098 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-33116 .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability txtify archive
CVE-2026-32212 Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability txtify archive
CVE-2026-32631 GitHub: CVE-2026-32631 'git clone' from manipulated repositories can leak NTLM hashes txtify archive
CVE-2026-21637 HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers txtify archive
CVE-2026-26153 Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-26168 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-26173 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-26176 Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-26177 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-26178 Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability txtify archive
CVE-2026-26182 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-27922 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-32068 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-32070 Windows Common Log File System Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-32086 Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-32150 Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-33099 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-33100 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-33103 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability txtify archive
CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability txtify archive
CVE-2026-32214 Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability txtify archive
CVE-2026-32187 Microsoft Edge (Chromium-based) Defense in Depth Vulnerability - Rejected txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2026-3184 Util-linux: util-linux: access control bypass due to improper hostname canonicalization txtify archive
CVE-2026-27456 util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup txtify archive
CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing txtify archive
CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling txtify archive
CVE-2026-4647 Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library txtify archive
CVE-2025-69649 GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed. txtify archive
CVE-2025-69645 Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file. txtify archive
CVE-2025-69652 GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service. txtify archive
CVE-2025-69646 Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis. txtify archive
CVE-2026-31428 netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD txtify archive
CVE-2026-31427 netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp txtify archive
CVE-2026-31424 netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP txtify archive
Secretary of War Hegseth Hosted Bilateral Meeting With Indonesian Defense Minister Sjafrie txtify archive
CVE-2026-39856 osslsigncode has an Out-of-Bounds Read via Unvalidated Section Bounds in PE Page Hash Calculation txtify archive
CVE-2026-39855 osslsigncode has an Integer Underflow in PE Page Hash Calculation Can Cause Out-of-Bounds Read txtify archive
CVE-2026-39853 osslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature Verification txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2026-34757 LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure txtify archive
CVE-2026-35206 Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment txtify archive
CVE-2026-4878 Libcap: libcap: privilege escalation via toctou race condition in cap_set_file() txtify archive
CVE-2026-33810 Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 txtify archive
CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile txtify archive
CVE-2026-32282 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix txtify archive
CVE-2026-27144 Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile txtify archive
CVE-2026-32283 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls txtify archive
CVE-2026-29181 OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) txtify archive
CVE-2026-39882 OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2026-35611 Addressable has a Regular Expression Denial of Service in Addressable templates txtify archive
CVE-2026-28810 Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver txtify archive
CVE-2026-39316 CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer txtify archive
CVE-2026-39314 CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported` txtify archive
CVE-2026-32241 Flannel vulnerable to cross-node remote code execution via extension backend BackendData injection txtify archive
CVE-2026-4897 Polkit: polkit: denial of service via unbounded input processing through standard input txtify archive
CVE-2026-34445 ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings. txtify archive
CVE-2026-34446 ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load txtify archive
CVE-2026-35093 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins txtify archive
CVE-2026-39314 CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported` txtify archive
CVE-2026-39316 CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer txtify archive
CVE-2026-34990 OpenPrinting CUPS: Local print admin token disclosure using temporary printers txtify archive
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network txtify archive
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) txtify archive
CVE-2026-34933 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs Air Force Gen. Dan Caine Hold a Press Briefing txtify archive
CVE-2026-4645 Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions txtify archive
CVE-2006-10003 XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack txtify archive
CVE-2026-5201 Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image txtify archive
CVE-2026-33936 python-ecdsa: Denial of Service via improper DER length validation in crafted private keys txtify archive
CVE-2026-32241 Flannel vulnerable to cross-node remote code execution via extension backend BackendData injection txtify archive
CVE-2026-27456 util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup txtify archive
CVE-2026-34990 OpenPrinting CUPS: Local print admin token disclosure using temporary printers txtify archive
CVE-2026-27447 OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup txtify archive
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) txtify archive
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network txtify archive
CVE-2026-3184 Util-linux: util-linux: access control bypass due to improper hostname canonicalization txtify archive
CVE-2026-31408 Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold txtify archive
CVE-2026-27456 util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup txtify archive
CVE-2026-34990 OpenPrinting CUPS: Local print admin token disclosure using temporary printers txtify archive
CVE-2026-27447 OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup txtify archive
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) txtify archive
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network txtify archive
CVE-2026-4897 Polkit: polkit: denial of service via unbounded input processing through standard input txtify archive
CVE-2026-2100 P11-kit: p11-kit: null dereference via c_derivekey with specific null parameters txtify archive
CVE-2026-5107 FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control txtify archive
CVE-2026-34073 cryptography has incomplete DNS name constraint enforcement on peer names txtify archive
CVE-2026-26135 Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability txtify archive
CVE-2026-33105 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-34043 Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects txtify archive
CVE-2026-33542 Incus does not verify combined fingerprint when downloading images from simplestreams servers txtify archive
CVE-2026-33936 python-ecdsa: Denial of Service via improper DER length validation in crafted private keys txtify archive
CVE-2026-33750 brace-expansion: Zero-step sequence causes process hang and memory exhaustion txtify archive
CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing txtify archive
CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling txtify archive
CVE-2026-5107 FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control txtify archive
CVE-2026-2739 This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely. txtify archive
CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` txtify archive
CVE-2026-2436 Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake txtify archive
CVE-2026-4897 Polkit: polkit: denial of service via unbounded input processing through standard input txtify archive
CVE-2026-2100 P11-kit: p11-kit: null dereference via c_derivekey with specific null parameters txtify archive
CVE-2026-5119 Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment txtify archive
CVE-2026-5121 Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing txtify archive
CVE-2026-5201 Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image txtify archive
CVE-2026-4176 Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib txtify archive
CVE-2026-33542 Incus does not verify combined fingerprint when downloading images from simplestreams servers txtify archive
CVE-2026-33750 brace-expansion: Zero-step sequence causes process hang and memory exhaustion txtify archive
CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing txtify archive
CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling txtify archive
CVE-2026-4645 Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions txtify archive
CVE-2026-34043 Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects txtify archive
CVE-2026-4176 Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs Air Force Gen. Dan Caine Hold a Press Briefing txtify archive
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack txtify archive
CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` txtify archive
CVE-2026-25645 Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function txtify archive
CVE-2026-33940 Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial txtify archive
CVE-2026-33939 Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation txtify archive
CVE-2026-33916 Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection txtify archive
CVE-2026-33941 Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options txtify archive
CVE-2026-33938 Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block txtify archive
CVE-2026-33542 Incus does not verify combined fingerprint when downloading images from simplestreams servers txtify archive
CVE-2026-33936 python-ecdsa: Denial of Service via improper DER length validation in crafted private keys txtify archive
CVE-2026-33891 Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input txtify archive
CVE-2026-33896 Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation) txtify archive
CVE-2026-33750 brace-expansion: Zero-step sequence causes process hang and memory exhaustion txtify archive
CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing txtify archive
CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling txtify archive
CVE-2026-33672 Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching txtify archive
CVE-2026-23399 nf_tables: nft_dynset: fix possible stateful expression memleak in error path txtify archive
CVE-2026-25645 Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function txtify archive
CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` txtify archive
CVE-2026-3591 A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass txtify archive
CVE-2026-3119 Authenticated query containing a TKEY record may cause named to terminate unexpectedly txtify archive
CVE-2026-33936 python-ecdsa: Denial of Service via improper DER length validation in crafted private keys txtify archive
CVE-2026-32241 Flannel vulnerable to cross-node remote code execution via extension backend BackendData injection txtify archive
CVE-2026-1519 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation txtify archive
CVE-2026-4645 Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions txtify archive
CVE-2026-2369 Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources txtify archive
CVE-2026-3547 wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation txtify archive
CVE-2026-23227 drm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free txtify archive
CVE-2026-27135 nghttp2 Denial of service: Assertion failure due to the missing state validation txtify archive
CVE-2026-23267 f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic commit and checkpoint writes txtify archive
CVE-2025-66413 Git for Windows leaks NTLM hash when cloning from an attacker-controlled server txtify archive
CVE-2026-23327 cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() txtify archive
CVE-2026-23386 gve: fix incorrect buffer cleanup in gve_tx_clean_pending_packets for QPL txtify archive
CVE-2026-23325 wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211() txtify archive
CVE-2026-4645 Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions txtify archive
CVE-2026-4775 Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing txtify archive
CVE-2026-4647 Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library txtify archive
CVE-2025-71109 MIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits txtify archive
CVE-2026-3381 Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib txtify archive
CVE-2025-66413 Git for Windows leaks NTLM hash when cloning from an attacker-controlled server txtify archive
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template txtify archive
CVE-2024-45336 Sensitive headers incorrectly sent after cross-domain redirect in net/http txtify archive
CVE-2026-23284 net: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup() txtify archive
CVE-2026-23324 can: usb: etas_es58x: correctly anchor the urb in the read bulk callback txtify archive
CVE-2026-23327 cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() txtify archive
CVE-2026-23310 bpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is loaded txtify archive
CVE-2026-23386 gve: fix incorrect buffer cleanup in gve_tx_clean_pending_packets for QPL txtify archive
CVE-2026-23340 net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs txtify archive
CVE-2026-23307 can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message txtify archive
CVE-2026-23383 bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing txtify archive
CVE-2026-23390 tracing/dma: Cap dma_map_sg tracepoint arrays to prevent buffer overflow txtify archive
CVE-2026-23368 net: phy: register phy led_triggers during probe to avoid AB-BA deadlock txtify archive
CVE-2026-23325 wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211() txtify archive
CVE-2026-23392 netfilter: nf_tables: release flowtable after rcu grace period on error txtify archive
CVE-2026-23315 wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() txtify archive
CVE-2026-2443 Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure txtify archive
CVE-2025-58160 Tracing logging user input may result in poisoning logs with ANSI escape sequences txtify archive
CVE-2025-13462 tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling txtify archive
CVE-2026-2646 Heap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function txtify archive
CVE-2026-3547 wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation txtify archive
CVE-2026-2645 Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2 txtify archive
CVE-2026-1005 Integer underflow leads to out-of-bounds access in sniffer AES-GCM/CCM/ARIA-GCM decrypt path txtify archive
CVE-2026-0819 Stack buffer overflow in PKCS7 SignedData encoding with custom signed attributes txtify archive
CVE-2026-2369 Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources txtify archive
CVE-2026-3099 Libsoup: libsoup: authentication bypass via digest authentication replay attack txtify archive
CVE-2026-4424 Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing txtify archive
CVE-2026-4426 Libarchive: libarchive: denial of service via malformed iso file processing txtify archive
CVE-2026-33056 tar-rs: unpack_in can chmod arbitrary directories by following symlinks txtify archive
CVE-2026-3381 Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib txtify archive
How Iran's ruthless enforcers use rape to crush dissent: Brutal sex attacks on victims as young as 12 used to strike fear into protesters, rights groups reveal amid fury over sickening nurse gang rape txtify archive
Stripped, electrocuted and forced to fight each other to the death on camera: New evidence shows how Putin's commanders are torturing their own men txtify archive
CVE-2026-27135 nghttp2 Denial of service: Assertion failure due to the missing state validation txtify archive
CVE-2026-27448 pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback txtify archive
CVE-2026-3632 Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames txtify archive
CVE-2026-3634 Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header txtify archive