Baby-faced Ivy League psychiatrist who'd never met Lindsay Clancy but prescribed her barrage of drugs takes center stage in children's horror murder trial txtify archive
More than a dozen people hospitalized following lightning strike in Ohio as officials declare mass casualty txtify archive
Huge legal win for surrogate who refuses to abort baby with heart defect despite biological parents' wishes as Texas Attorney General steps in txtify archive
Heroic Florida K-9 returns to sheriff's office days after being shot protecting 3 deputies, losing leg txtify archive
STATE OF PLAY: Highly watched Hong race remains too close to call as progressives notch key primary wins txtify archive
Five teen friends killed after vehicle plunges down Colorado cliff, leaving community shattered txtify archive
Lindsay Clancy defense wants TikToker to expose hospital ‘lies’ as judge warns ‘this is not Tripadvisor’ txtify archive
Amy Adams' nepo baby daughter Aviana, 16, called Scarlett Johansson's TWIN as fans notice striking similarity txtify archive
Left-wing progressive emerges victorious in hot Senate primary in warning sign for moderate Democrats txtify archive
Inside 'frustrated' Caitlin Clark's decision whether to QUIT the WNBA: Friends reveal 'troubling' private drama amid league's new trans feud... and more violence on the court txtify archive
Caitlin Clark admits her own fans' behavior made her 'sick' as WNBA star helps fire Fever to record win after coach's explosive rant txtify archive
Tony Romo's CBS replacement breaks silence on promotion after NFL legend's arrest forced network into reshuffle and left $180m job in doubt txtify archive
Investment guru gives a bleak update on America's retirement… but it could secretly be a good thing for the housing market txtify archive
Alessandra Ambrosio is engaged: Supermodel to wed hunky jewelry designer Buck Palmer after bikini-clad proposal txtify archive
The race to replace Lindsey Graham gets UGLY as his sister Darline comes up short... triggering a runoff txtify archive
Minnesota House speaker Lisa Demuth wins GOP gubernatorial primary to replace Tim Walz in November txtify archive
Trump's power rattled as notorious ex-crack addict LOSES by 13 points in governor race txtify archive
Pat McAfee sparks liberal meltdown by cozying up to Donald Trump at Patriot Games... despite claiming he is 'not a politics person' txtify archive
Woke Roseanne star says show was RIGHTFULLY CANCELED over racism scandal as he slams 'ignorant' fans txtify archive
Woke NYC mayor humiliated by NYPD after suggesting his 'private' wife should have taxpayer-funded police bodyguards for trip to Syria txtify archive
Dems eye pick-up in Wisconsin swing district as Rep Van Orden set for rematch in key House race txtify archive
Dad makes chilling 911 call confessing to killing his four kids and their mom before turning the gun himself at their family home txtify archive
Chris Pratt and Katherine Schwarzenegger slash $12M off lavish LA mansion in FIFTH attempt to sell the property txtify archive
North Korea launches another ballistic missile as US, South Korea prepare for military drills txtify archive
ISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048, (Wed, Aug 12th) txtify archive
4-year-old dies after suffering electrical shock from clothes dryer inside Kansas home txtify archive
Republican survives primary on Tim Walz's old congressional turf as Dems eye seat flip txtify archive
Failed presidential candidate wins Dem primary for Midwest governor amid fraud scandal fallout txtify archive
Fever coach Stephanie White erupts over latest WNBA controversy in blistering speech... amid calls for her to be fired over Sophie Cunningham race storm txtify archive
Chilling Lindsay Clancy trial question that should shake the entire nation: Top defense attorney's twist in killer mom case txtify archive
Patrick Clancy's unnerving reaction when nurse suggested wife Lindsay was 'bipolar' is revealed... as mom sat in bleak silence txtify archive
Bride's furious feminist rant at officiant mid-wedding sparks outrage: 'He married a Karen' txtify archive
I've read my husband's texts to his male 'gym buddy'. I feared I'd been betrayed... but this is almost too devastating for words: DEAR JANE txtify archive
Baywatch alum Erika Eleniak, 56, debuts OnlyFans account ahead of her cameo in the Fox reboot txtify archive
Woke music heiress, 39, has been SQUATTING in Brooklyn apartment for last four years with her refusal to pay rent driving her black landlord into foreclosure, lawsuit claims txtify archive
Meghan's Hollywood dreams dealt another blow as girl scouts film is labelled a 'reality-show ramble' by unimpressed critics and bombs at box office - with one cinema-goer advising 'Don't waste your money' txtify archive
Devastating full horror of Perez Hilton's knife livestream unravels: Friends reveal tragic life-long disfigurement... what star is admitting from hospital bed... and why he may now be locked up for YEARS txtify archive
Federal judge blocks Trump administration from restricting mail-in ballots ahead of midterms txtify archive
Ex-NBA star begins 'transition to WNBA' with shirtless workout after declaring for draft amid league's trans feud txtify archive
FBI launches crackdown after college stars are targeted with hacking and AI-doctored images in sexual exploitation scheme txtify archive
Mooving ceremony! Farmer bride turns up to church wedding on her favourite cow White Chocolate Button txtify archive
Furious HGTV stars Egypt Sherrod and Mike Jackson targeted by 'fake and malicious' rumors txtify archive
Trump ends Medicaid funding for gender-transition surgeries for minors as he vows to 'protect America's children' txtify archive
Taliban wipes out decades of progress as 2.4M Afghan girls remain locked out of school, UN agency says txtify archive
Jamie Foxx, 58, takes to the tennis court ahead of birth of his third child… three years after shock stroke that left him hospitalized txtify archive
Travel warning upgraded to highest level amid thousands of deaths in Ebola outbreak... 'avoid all travel' txtify archive
Rod Stewart, 81, reveals he's undergone heart surgery and will take four weeks off after being forced to cancel his shows due to mystery 'unforeseen' medical issue txtify archive
Cristiano Ronaldo and Georgina Rodriguez are married! Portugal star ties the knot with influencer in an 'intimate and private' civil ceremony attended by their five children txtify archive
Playtime turns deadly after four-year-old is electrocuted by DRYER inside family's home txtify archive
Syria's former ruler Bashar al-Assad is sentenced to death for crimes against humanity txtify archive
Angelina Jolie's reaction to ex Brad Pitt falling off the wagon 'revealed'... 10 years after star's alleged drunken plane attack txtify archive
Vikings coach reveals what JJ McCarthy's future holds after losing QB battle to rival Kyler Murray txtify archive
Wild theory claims Earth will lose gravity for seven seconds TOMORROW in cosmic catastrophe txtify archive
Georgia teacher, father hailed as hero after dying to save girl from Myrtle Beach rip current txtify archive
'Untouchable' Andrew and Tristan Tate had secret aliases including James Bond villain's identity to try to dodge justice...now they're binging on Doritos and Snickers in prison txtify archive
Trump's shocking two-word response after being snuck back ON the AF1 plane full of unknowing press after Iran threat txtify archive
Trump directs CMS Administrator Mehmet Oz to end Medicaid gender transition funding for minors txtify archive
Anguish of Colombian brother at rubble of building being searched for earthquake survivors txtify archive
Innocent driver had car window smashed and was dragged onto pavement before being maced in face after San Francisco cops made idiotic mistake txtify archive
Massachusetts governor passes controversial abortion bill allowing terminations up to birth txtify archive
Explosive cheating scandal erupts at ritzy country club: Humiliating texts expose disgraced golfer's betrayal... as friends declare he is 'done for' txtify archive
Mommy fugitive accused of murdering toddler daughter by hurling her against WALL is captured after 30 years on the run txtify archive
CBS boss provides update on Tony Romo job status after his arrest forces network into NFL reshuffle txtify archive
ESPN NFL analyst Matt Miller dealt legal blow over near-fatal car crash that cost him his arm... as he also faces probe into 'fantasy football scam' txtify archive
I've examined thousands of penises as a urologist and seen every size. Here's what REALLY counts as small... the true average length... and 'growing' treatment that actually works: DR ARTHUR BURNETT txtify archive
Lucrative jobs you can walk into today with NO experience and NO degree... and some pay over $100,000 txtify archive
NFL legend forced to APOLOGIZE for iconic Hall of Fame speech that included brutal Bill Belichick joke txtify archive
Suspect in off-duty Philadelphia officer’s car theft linked to killing of Penn State student: police txtify archive
Nature-loving mom, 58, identified as alligator attack victim after making terrible mistake... as family reveals ghastly new details of how crystal-clear Florida river ran red txtify archive
Trump's explosive birthright citizenship order targeting tourists and babies could be BLOCKED txtify archive
Vulnerable Dem's campaign pitch clashes with 'radical' voting record on top culture war issue txtify archive
Millions of Americans across Midwest placed under urgent tornado warning as Chicago braces for impact: 'Take cover now!' txtify archive
Child disappeared at Maine beach because parent was too busy scrolling on PHONE... what happened right after youngster was returned safely made cops furious txtify archive
Trump’s sly plane switch raises eyebrows over safety of passengers left behind on board txtify archive
Prospective Dem hopeful Gavin Newsom brands Joe Rogan an 'a**hole' - after groveling to podcaster for spot on his hit show txtify archive
Man wanted in robbery tied to Penn State student's murder now sought after off-duty cop shootout txtify archive
Missing teen, 16, found almost two weeks after haunting footage showed her sneaking out of family home before disappearing without a trace txtify archive
US Marine who was jailed by Russia looks alarmingly frail in first photo as he's released on 'humanitarian grounds' after years of abuse txtify archive
Los Angeles Rams given huge scare as superstar receiver Puka Nacua leaves practice with mystery injury txtify archive
Chiefs star Rashee Rice reveals the truth about brutal prison 'reality check' and how Patrick Mahomes supported him txtify archive
Marine vet, 44, left brain damaged and in need of round-the-clock care after eating bad oysters at swanky Chicago steakhouse, lawsuit alleges txtify archive
Parents speak out after son with autism, 6, was suspended for biting sandwich into shape of gun txtify archive
Friendly female jogger wished madman driver 'good morning', then horror ensued, cops say txtify archive
Jets star rushed to the hospital after scary collapse in joint practice marred by brawls and 'cheapshots' txtify archive
Socialist Wisconsin governor candidate referred to America as 'abundance of suffering,' resurfaced post shows txtify archive
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client txtify archive
Uncomfortable moment Mike Vrabel is quizzed on counseling sessions in wake of Dianna Russini affair scandal txtify archive
Department of War Launches the 'Golden Dome for America Hub' To Accelerate Industry Engagement, Revolutionize Homeland Missile Defense Partnerships txtify archive
Hospital worker, 32, who wanted child rape to be LEGALIZED is jailed over images cops said were worst they had ever seen txtify archive
NYPD’s legendary ‘Hip-Hop Cop' Derrick Parker, who investigated rap’s biggest stars and murders, dead at 65 txtify archive
Suspected domestic abuse victim recorded Texas cop's jaw-dropping remark about 'women' on her doorbell cam as he arrived to help her txtify archive
American Airlines banned woman, 52, with Down syndrome from flying... here's why staff say they made correct decision txtify archive
Struggling Las Vegas takes yet another hit as home prices slump and unsold inventory surges txtify archive
Unexplained heart racing? When to ignore the flutters in your chest and when it's a sign of something sinister txtify archive
Texas city scandalized as female mayor with big hair becomes first ever leader to be reprimanded over her conduct txtify archive
US guns fire on 17 civilians in dead of night tanker strike as Trump's Iran war sparks gas carnage txtify archive
NYC Mayor Mamdani takes aim at Amazon in bid to protect workers... but critics warn New Yorkers will pay the price txtify archive
Oprah says 'obesity gene' caused her to overeat as she praises GLP-1s for 80lb weight loss txtify archive
Sherrill drops head-turning voter ID declaration in wake of registration fiasco: ‘Significant shift’ txtify archive
Miss Universe Canada slams contest for letting rivals wear costumes that felt 'hurtful' to her as an Indigenous woman txtify archive
Trump cheers Alito staying for another Supreme Court term: 'One of the greatest of all time' txtify archive
Nepo baby accused of starting bride war after posting herself wearing same wedding dress as popular influencer txtify archive
The 'middle-class kinks' saving marriages: Wives reveal the eight buzzy sex trends that revived their lagging libidos - including the fantasy husbands are secretly obsessed with txtify archive
Famous NYC matchmaker reveals absurdly petty reason woman decided not to go on first date with eligible finance guy she was introduced to txtify archive
Francesca Hong asked about lack of AOC endorsement and the House Dem's remark about the 'Woke 1' era txtify archive
Trump's new attorney general issues sweeping order to protect the president's private messages if Democrats take power txtify archive
Wall Street traders fork out $100,000 a month for early access to Donald Trump's social media posts txtify archive
POWERBALL FEVER as jackpot surges to eye-watering $975million after nobody nailed Monday's drawing - could YOU be America's next winner? txtify archive
Venomous snake uncovered in football player's helmet after he practiced for an hour with it next to his head txtify archive
Minnesota Vikings make decision on starting QB after offseason battle between JJ McCarthy and Kyler Murray txtify archive
Chilling truth about Bryan Kohberger's 'lovesick' women: Leaked messages about victims' families, sick 'evidence' claims... and what their HUSBANDS really think txtify archive
More than 3,000 missing after Colombia earthquake as Trump administration provides $15.5 million in relief txtify archive
Family annihilator Chris Watts' secret prison marriage: Photos of 'smitten new wife Lizzie Watts'... sick lustful act on anniversary of murders... and her extraordinary insult txtify archive
Lonely man who almost jumped to his death from bridge shares heartwarming transformation in his fortunes after being saved by hero cop txtify archive
Crane arm collapses into Miami condo rooftop pool area as workers cling to dangling structure txtify archive
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE txtify archive
Inside the furious battle for power: Odds for a Democratic victory revealed as more Trump-backed seats added to flip list txtify archive
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt txtify archive
Arizona parents had boozy afternoon, then decided to take their young children for walk in 108F heat, cops say txtify archive
California 'in the crosshairs' of mega earthquake within months, warns scientist who predicted deadly Colombia disaster txtify archive
Tourists were squeezed on to 'overpacked' boat that 'smelled like gasoline' and 'didn't feel safe' before it blew up, killing British girl, 16, witnesses say txtify archive
Officials issue urgent warnings to beachgoers as deaths from flesh-eating bacteria in water grow txtify archive
New CCTV emerges from fatal night as British influencer battles to escape the death penalty for fatally stabbing boyfriend in Dubai txtify archive
Dutton Ranch drama leaked: Diva behavior, foul-mouthed meltdown that 'p****d off' bosses and the peacemaker who is holding 'mess of a show' together txtify archive
Sickening new details about death of boy, 7, who cops say was tortured to death by his mom and her two transgender lovers txtify archive
Disgrace for fake pilot who used slew of crafty tricks to dupe airlines into giving him 200 free flights across the world txtify archive
Andy Reid drops shock Chiefs exit hint after being confronted with Patrick Mahomes worry before NFL season txtify archive
Christian McCaffrey's sister-in-law Sophia Culpo details terrifying robbery attempt on train in France: 'I was shaking' txtify archive
Brooke Shields praised over epic clap back at 'bully' daughter Grier's jokes about her gray hair and wrinkles txtify archive
Alex Murdaugh lawyers allege ‘fabricated’ evidence was used to secure murder indictments txtify archive
New England boy, 7, had just learned to ride his bike and was 'so proud of himself,'... until he accidentally pedaled onto main street and tragedy struck txtify archive
Luigi Mangione judge says jurors will remain anonymous after threats and harassment of witnesses txtify archive
CVE-2026-50472 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-40375 Microsoft Dynamics Business Central Information Disclosure Vulnerability txtify archive
CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution Vulnerability txtify archive
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability txtify archive
CVE-2026-59128 Windows Encrypting File System (EFS) Information Disclosure Vulnerability txtify archive
CVE-2026-59133 Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability txtify archive
CVE-2026-59135 Microsoft Windows Search Component Information Disclosure Vulnerability txtify archive
CVE-2026-61348 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-61923 Windows Display Enhancement Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-61936 Windows Defender Firewall Service Security Feature Bypass Vulnerability txtify archive
CVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-62699 Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability txtify archive
CVE-2026-62707 Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability txtify archive
CVE-2026-62713 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-62783 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability txtify archive
CVE-2026-62758 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability txtify archive
CVE-2026-62772 Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-62785 Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability txtify archive
CVE-2026-62784 Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability txtify archive
CVE-2026-62795 Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability txtify archive
CVE-2026-62816 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability txtify archive
CVE-2026-62818 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability txtify archive
CVE-2026-62819 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability txtify archive
CVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability txtify archive
CVE-2026-62892 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability txtify archive
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability txtify archive
CVE-2026-54123 Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability txtify archive
CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability txtify archive
CVE-2026-63517 Microsoft Office Graphics Component Information Disclosure Vulnerability txtify archive
CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability txtify archive
CVE-2026-65664 Microsoft Office Graphics Component Remote Code Execution Vulnerability txtify archive
CVE-2026-65814 Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-70307 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-66301 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability txtify archive
CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability txtify archive
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-72971 Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability txtify archive
CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability txtify archive
CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability txtify archive
CVE-2026-59125 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability txtify archive
CVE-2026-61358 Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability txtify archive
CVE-2026-62710 Windows Device Association Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-62721 Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-62771 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-62775 Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability txtify archive
CVE-2026-62842 Microsoft Office Graphics Component Information Disclosure Vulnerability txtify archive
CVE-2026-63526 Microsoft Office Graphics Component Remote Code Execution Vulnerability txtify archive
CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability txtify archive
CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability txtify archive
CVE-2026-66809 Microsoft Office Graphics Component Information Disclosure Vulnerability txtify archive
CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability txtify archive
CVE-2026-62738 Windows Management Instrumentation Information Disclosure Vulnerability txtify archive
NFL QB makes second retirement 'official' after 'one of most gruesome injuries doctors had ever seen' txtify archive
Urgent recall issued for multiple foods sold at Target, Walmart and Trader Joe's over fears of contamination with deadly bacteria txtify archive
Mom, 2 co-parents arrested in boy’s murder after grandparents hire PI to probe ‘house of horrors’ txtify archive
Britain abandoned bid to recover lost £5.5bn treasure from a Royal Navy shipwreck near Gibraltar in case it upset Spain txtify archive
British tourist 'is killed in parasailing accident while in Benidorm with her husband' txtify archive
Is Ukraine about to destroy Putin's palace? Now drone strikes hit defences around £1bn Black Sea mansion 'leaving it unprotected' txtify archive
Death of California law student, 19, linked to popular weight loss shot, as frightening symptoms and distraught mother's three-word outburst at awful news are revealed txtify archive
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices txtify archive
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo txtify archive
Why your sudden weight gain, 'double chin' and low mood might not just be the fallout from menopause or 'middle-age spread'... it could be much more serious. But there IS a simple cure txtify archive
Oklahoma victim fights back after teen charged in rapes walks free — as feds could storm in: attorney txtify archive
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers txtify archive
Pentagon makes dramatic missile shift as repeated conflicts drain US stockpiles and more top headlines txtify archive
The Morning Risk Report: U.K. Discovers Component in Its Naval Drones Sent Signals to China txtify archive
Repeat offender accused of college student’s murder was known ‘threat’ after prior arrest: victim’s mom txtify archive
Astonishing moment a hippo chases tourists through the water and keeps up with their speeding boat txtify archive
Astonishing moment a hippo chases tourists through the water and keeps up with their speeding boat txtify archive
Miracle beneath the rubble: Moment six-month-old baby is rescued along with her mother following Colombian earthquake txtify archive
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets txtify archive
California sued over policy that could free serial killers as Laci Peterson's friend sounds alarm txtify archive
Israel vindicated by Gaza nutrition data after ‘blood libel’ starvation claims, UN envoy says txtify archive
CVE-2024-57888 workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM worker txtify archive
CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs txtify archive
CVE-2025-2308 HDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflow txtify archive
CVE-2025-21682 eth: bnxt: always recalculate features after XDP clearing, fix null-deref txtify archive
CVE-2025-37945 net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY txtify archive
CVE-2024-57898 wifi: cfg80211: clear link ID from bitmap during link delete after clean up txtify archive
CVE-2025-37852 drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create() txtify archive
CVE-2025-37861 scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue txtify archive
Deported child predator who illegally reentered US sentenced to 20 years in federal prison txtify archive
CVE-2026-64654 GitHub CLI: Terminal escape sequence injection in multiple `gh` commands txtify archive
CVE-2026-68085 Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled txtify archive
CVE-2026-68196 wifi: wilc1000: validate assoc response length before subtracting header txtify archive
CVE-2026-68093 KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug txtify archive
CVE-2026-68301 net: hsr: fix memory leak on slave unregistration by removing synced VLANs txtify archive
CVE-2026-68160 ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() txtify archive
CVE-2026-68329 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() txtify archive
CVE-2026-68164 mm/damon/core: disallow overlapping input ranges for damon_set_regions() txtify archive
CVE-2026-68309 wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() txtify archive
CVE-2026-68099 ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL txtify archive
CVE-2026-68422 btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() txtify archive
CVE-2026-68205 media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() txtify archive
CVE-2026-68220 media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe txtify archive
CVE-2026-68355 wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() txtify archive
CVE-2026-68395 ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered txtify archive
CVE-2026-68130 ksmbd: defer destroy_previous_session() until after NTLM authentication txtify archive
CVE-2026-72522 libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions. txtify archive
CVE-2026-68312 cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths txtify archive
CVE-2026-68306 wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() txtify archive
CVE-2026-68197 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper txtify archive
CVE-2026-15534 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch txtify archive
CVE-2026-68362 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin txtify archive
CVE-2026-68351 wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read txtify archive
CVE-2026-68308 wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() txtify archive
CVE-2026-68353 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler txtify archive
CVE-2026-68256 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference txtify archive
CVE-2026-65819 gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParser txtify archive
CVE-2026-68363 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request txtify archive
CVE-2026-71557 go-git: Malicious reference names may modify files outside the reference storage txtify archive
CVE-2026-54332 GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS txtify archive
CVE-2026-43871 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit txtify archive
CVE-2026-55969 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable() txtify archive
CVE-2026-61477 Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection txtify archive
CVE-2026-64655 GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching txtify archive
CVE-2026-64653 GitHub CLI: Unescaped variable components in request URLs could allow path traversal txtify archive
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine txtify archive
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs txtify archive
Oklahoma Little League team gets new life with Texas judge's restraining order after 'ineligible player' ban txtify archive
ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th) txtify archive
Mamdani’s luxury-home tax rollout derailed for now as judge delivers win to NYC homeowners over massive list txtify archive
Iran installs new war chiefs as Tehran signals ‘prolonged confrontation,’ expert warns txtify archive
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications txtify archive
Trump Media & Technology Group’s Second-Quarter Loss Deepens on Decline in Value of Digital Assets txtify archive
Chris Watts' secret playbook: Deadly kink and disturbing dating photos revealed in lover's graphic account of his method: 'I hate the things I let him do to me' txtify archive
Trump bets economic pressure can squeeze Iran as regime’s own failures deepen the pain txtify archive
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors txtify archive
CVE-2024-21380 Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability txtify archive
CVE-2026-50357 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability txtify archive
CVE-2025-29821 Microsoft Dynamics Business Central Information Disclosure Vulnerability txtify archive
CVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability txtify archive
CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability txtify archive
CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors txtify archive
The Morning Risk Report: Russia’s Hottest Startup Is a State-Backed Sanctions Evasion Network txtify archive
CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service txtify archive
CVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode change txtify archive
CVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized txtify archive
CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c txtify archive
CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. txtify archive
CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. txtify archive
ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th) txtify archive
Moscow, Kyiv assassins hunt weapons bosses as Ukraine war spills beyond the battlefield txtify archive
Netanyahu rejects Board of Peace's Gaza plan: No 'withdrawal until Hamas is genuinely disarmed' txtify archive
CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi object txtify archive
CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown txtify archive
CVE-2026-64604 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode txtify archive
CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning txtify archive
CVE-2026-64580 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() txtify archive
CVE-2026-64579 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert txtify archive
CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available txtify archive
CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root txtify archive
CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. txtify archive
CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. txtify archive
CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering txtify archive
CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin txtify archive
CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service txtify archive
CVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service txtify archive
CVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return txtify archive
CVE-2026-71226 Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path txtify archive
CVE-2026-71225 Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries txtify archive
CVE-2026-68081 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state txtify archive
CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client txtify archive
CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis client txtify archive
CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack txtify archive
CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs txtify archive
CVE-2026-64676 Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory txtify archive
Nigeria's largest rescue operation frees 308 hostages held by militants in Kwara State txtify archive
CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) txtify archive
CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) txtify archive
CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations txtify archive
CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate. txtify archive
CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate. txtify archive
CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate. txtify archive
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys txtify archive
Trump ally 'El Tigre' sworn in as Colombia's new president amid continent's rightward shift txtify archive
US intel warns Russia could launch limited attack on NATO ally in effort to fragment organization: report txtify archive
Under Secretary of War for Policy Elbridge Colby and Assistant Secretary of War John Noh Travel to the Philippines, Indonesia, Thailand and Cambodia txtify archive
SpaceX on X: “The SpaceX Recovery team is still working to recover Flight 13’s Starship from the Indian Ocean. They’ve been overcoming challenging conditions and increasingly rough seas as they attempt to guide the 52m long spacecraft to port” txtify archive
Office of Strategic Capital Signs $400 Million Conditional Loan Commitment With Sunrise Energy Metals Limited to Expand Scandium Mining Operations txtify archive
The Office of Strategic Capital Signs $1.4 Billion Conditional Loan Commitment With Sila Nanotechnologies, Inc. to Enhance American Battery Production txtify archive
Department of War Announces an $85.5 Million Agreement With Strategic Bauxite USA to Secure the Critical Refractory Grade Bauxite Supply Chain txtify archive
President Trump's Department of War Announces Over $80M Investment in Mining Schools at Historic Roundtable With Mining Executives txtify archive
Office of Strategic Capital Signs $150 Million Conditional Loan Commitment With Niron Magnetics, Inc. to Scale Domestic Rare Earth-Free Magnet Production txtify archive
Space Launch Delta 45 Partners With Florida National Guard to Strengthen Hazmat Response txtify archive
Tran quoted in CNN Business on Japan’s persistently low interest rates and its relation to the yen txtify archive
Nikoladze interviewed by NPR on the importance to implement and enforce the Russia Sanctions Bill correctly txtify archive
Lipsky quoted in Politico regarding the fiscal outlook for the US and how this puts a new priority on revenues txtify archive
Department of War Publishes Fifth Release of Unidentified Anomalous Phenomena Files on WAR.GOV/UFO txtify archive
ConocoPhillips CFO to Ascend to Top Role; Fast-Food Burger Battle; Plus, New Layoff Data txtify archive
The Morning Risk Report: Prosecutors Probed Whistleblower Claims That JPMorgan Mishandled Fraud Cases txtify archive
CVE-2019-9192 In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion txtify archive
CVE-2019-9924 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell. txtify archive
CVE-2010-4052 Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD. txtify archive
CVE-2019-6706 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships. txtify archive
CVE-2018-6829 cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation. txtify archive
CVE-2018-1128 It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable. txtify archive
CVE-2018-5407 Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. txtify archive
CVE-2016-2568 pkexec, when used with --user nonpriv, allows local users to escape to the parent session txtify archive
CVE-2007-3205 The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin. txtify archive
Defense Business Brief: The enduring case for small USVs | Battleship costs balloon | Rainey joins Bain Capital txtify archive
ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th) txtify archive
The US Navy’s decision to reclassify 19 Virginia-class submarines is a breakthrough. Here’s why. txtify archive
Thousands of migrants remain in Spanish territory after border rush, death toll hits about 100: Ceuta official txtify archive
US says North Korea missile launch poses no immediate threat, 'consulting closely' with allies txtify archive
Officials hedge SpaceX aircraft-tracking satellite bet with three smaller company contracts txtify archive
Iran’s president blames foreign pressure as expert warns regime's economy nears breaking point txtify archive
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories txtify archive
SpaceX, Tesla Lock In Grimes County for Terafab, Plans $16.8 Billion First Phase comments txtify archive
CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability txtify archive
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments txtify archive
Gen Keane questions whether Pakistan, Saudi Arabia and Qatar can be trusted in Iran talks txtify archive
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access txtify archive
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model txtify archive
ISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040, (Thu, Aug 6th) txtify archive
Crowded Russian beach descends into chaos after alleged Ukrainian drone incident kills 7, including 4 children txtify archive
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th) txtify archive
Russia deploys North Korean missile unit to Ukraine; Moscow-Pyongyang axis deepens: report txtify archive
Terrifying 'human safaris' on display in shocking video that reveals depths of Russia's deadly campaign txtify archive
Havrylov in Ukrinform: For the first time in Ukraine’s history, we are launching the licensed production of a defense system on Ukrainian soil txtify archive
Inside the mind of killer dad Chris Watts: The sordid urges that drove him to 'eliminate' his wife and daughters... why he murdered them in different ways... and truth about his twisted obsession with women txtify archive
Remarks by Under Secretary of War for Policy Elbridge Colby at the 2026 United States Strategic Command Deterrence Symposium txtify archive
Killer dad Chris Watts's womanizing ways behind bars revealed in this week's The Trial USA podcast txtify archive
Killer dad Chris Watts' extreme transformation revealed: New womanizing love letters, on-his-knees confession... and his one twisted regret after slaughtering family txtify archive
SpaceX’s new Starfall program offers validation and competition for reentry startups comments txtify archive
Despite what Putin says, Russia and Iran are linking the wars in Ukraine and the Middle East txtify archive
Daniel B. Shapiro testifies to House Foreign Affairs Committee on wartime prospects for regional integration txtify archive
While SpaceX recovers Ship 40, Ship 41 prepares for testing ahead of Flight 14 comments txtify archive
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software txtify archive
Department of War Enhances C-UAS Marketplace to Expand Access to Validated Technologies txtify archive
ASEAN-5 in an era of geoeconomic realignment: Opportunities and risks in a fragmenting global economy txtify archive
CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates txtify archive
The crisis in the Strait of Hormuz is a heavy blow to the deteriorating maritime order txtify archive
Nikoladze quoted in Al Jazeera on India’s trade-off between energy security and US tariff risk. txtify archive
Lipsky interviewed in a CBC podcast on tariffs becoming a feature of future US economic policy txtify archive
SpaceX: “The first Starlink V3 satellites in space successfully deployed their solar arrays, fired their thrusters, established connections with the Starlink constellation using radio frequencies and laser links, and captured imagery of Starship” txtify archive
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs txtify archive
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module txtify archive
Colombia’s next president wants to work with the US. Here’s how Washington should respond. txtify archive
Boosting the Western Balkans’ digital transformation: The key role of the private sector txtify archive
CISA and Partners Unveil Updated Software Bill of Materials Resource That Improves Transparency, Security and Risk-Informed Decision Making txtify archive
I was killer dad Chris Watts' secret mistress. There's so much I never told police... his vile 'animal mode' sex... the explicit recovered texts... and obscene way he talked about his wife txtify archive
Elon Musk on X: The ship landing was precise, meaning that it would have been caught by the tower arms txtify archive
Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud txtify archive
SpaceX: “Landing burn and splashdown of Starship on Flight 13… The Starship Recovery team has continued gathering imagery of the vehicle, which is still afloat in the Indian Ocean” txtify archive
CISA Joins Australia and Others to Publish Guidance to Isolate Operational Technology and Enabling Systems in Critical Infrastructure txtify archive
What is the Future for Serbs in Kosovo? | A Debrief With Tatjana Lazarević and Dan Ilazi txtify archive
From grain to drones, the Ukraine-Turkey free trade agreement marks a milestone in bilateral cooperation txtify archive
CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting txtify archive
CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() txtify archive
Lipsky quoted in Bloomberg on the stickiness of tariffs and their role in broader trade deals txtify archive
Lipsky quoted in Bloomberg on President Donald Trump’s commitment to rebuild the tariff wall txtify archive
Ezratty and Donovan cited in Asia Times regarding Iran’s supply-chain cooperation with Russia and China txtify archive
The CBDC tracker cited in Coindesk on the number of countries actively testing or developing CBDCs txtify archive
ESI’s term, ‘Positive Economic Statecraft’, featured in National Interest article on the other half of economic statecraft txtify archive
Lipsky quoted in France 24 regarding Donald Trump’s targeting of Canada using section 338 tariffs txtify archive
Turning to Azerbaijani gas and US LNG, Turkey seeks to break its reliance on Russian energy txtify archive
Media Invitation Announced for United States v. Khalid Shaikh Mohammad et al. Pre-Trial Hearing txtify archive
CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability txtify archive
CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity txtify archive
CVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirects txtify archive
CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate. txtify archive
CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate. txtify archive
CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate. txtify archive
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys txtify archive
CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root txtify archive
CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. txtify archive
CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. txtify archive
CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering txtify archive
CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL txtify archive
CVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries txtify archive
CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread txtify archive
CVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush txtify archive
CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out txtify archive
CVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments txtify archive
CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records txtify archive
CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path txtify archive
CVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration txtify archive
CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass txtify archive
CVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash txtify archive
CVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated txtify archive
CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name txtify archive
CVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control' txtify archive
CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN txtify archive
CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin txtify archive
CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service txtify archive
CVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service txtify archive
CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service txtify archive
CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. txtify archive
CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. txtify archive
CVE-2026-50407 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50441 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability txtify archive
CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers txtify archive
CVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL values txtify archive
CVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs txtify archive
CVE-2026-59885 pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service txtify archive
CVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom txtify archive
CVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks txtify archive
CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering txtify archive
CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass txtify archive
CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS txtify archive
CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations txtify archive
CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header txtify archive
CVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode change txtify archive
CVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized txtify archive
CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c txtify archive
CVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-3842 Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write txtify archive
CVE-2026-38755 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. txtify archive
CVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. txtify archive
CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record txtify archive
CVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path index txtify archive
CVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location txtify archive
CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row txtify archive
CVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text txtify archive
CVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record txtify archive
CVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service txtify archive
CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. txtify archive
CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. txtify archive
CVE-2026-63961 usb: typec: altmodes/displayport: validate count before reading Status Update VDO txtify archive
CVE-2026-63960 usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() txtify archive
CVE-2026-63964 usb: typec: ucsi: ccg: reject firmware images without a ':' record header txtify archive
CVE-2026-63962 usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() txtify archive
CVE-2026-64138 ksmbd: validate SID in parent security descriptor during ACL inheritance txtify archive
CVE-2026-50304 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50368 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50355 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50411 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2024-35248 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability txtify archive
How to effectively monitor/scrape specific Facebook Groups for time-sensitive posts in 2026? (My current Google Dork setup is hitting limits) txtify archive
CVE-2026-45784 rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers txtify archive
CVE-2026-53385 vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write txtify archive
CVE-2026-63798 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove txtify archive
CVE-2026-63807 KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level txtify archive
CVE-2026-63806 KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() txtify archive
CVE-2026-53403 fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var txtify archive
Anyone have experience with either Open Sky Network API or ADS-B Exchange API and know what the polling request limit is? txtify archive
CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record txtify archive
CVE-2026-62309 CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS txtify archive
CVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL values txtify archive
CVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs txtify archive
CVE-2026-59885 pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service txtify archive
CVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path index txtify archive
CVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location txtify archive
CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row txtify archive
CVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text txtify archive
CVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record txtify archive
CVE-2026-15709 Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service txtify archive
CVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption txtify archive
CVE-2026-15714 Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string txtify archive
CVE-2026-15713 Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak txtify archive
CVE-2026-15711 Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation txtify archive
CVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service txtify archive
AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report txtify archive
Identifying the Crypto Entrepreneur Linked to Popular Forum Trading in ‘Leaked’ Nudes of Women txtify archive
CVE-2026-50304 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50368 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50355 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50411 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-56171 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability txtify archive
CVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace txtify archive
CISA and Partners Publish Guidance to Help Software Manufacturers and Online Service Providers Work With Security Researchers txtify archive
CVE-2026-58209 NATS Server: MQTT retained and QoS replay bypass subscribe deny filters txtify archive
CVE-2026-58250 NATS Server: Pre-auth server crash via double INFO in leafnode handshake txtify archive
CVE-2026-58208 NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled txtify archive
CVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2 txtify archive
CVE-2025-44904 hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function. txtify archive
CVE-2026-15308 Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations txtify archive
CVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom txtify archive
CVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks txtify archive
CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering txtify archive
CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass txtify archive
CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS txtify archive
CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations txtify archive
CVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace txtify archive
CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header txtify archive
CVE-2026-59875 node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records txtify archive
CVE-2026-13221 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk txtify archive
CVE-2026-57432 Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack txtify archive
CVE-2026-34346 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability txtify archive
CVE-2026-49164 Windows Active Directory Domain Services Remote Code Execution Vulnerability txtify archive
CVE-2026-49170 Windows StateRepository API Server file Elevation of Privilege Vulnerability txtify archive
CVE-2026-47282 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability txtify archive
CVE-2026-50663 Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability txtify archive
CVE-2026-54983 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50695 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-54989 Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-54111 Universal Print Management Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-54992 Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability txtify archive
CVE-2026-54109 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability txtify archive
CVE-2026-54982 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability txtify archive
CVE-2026-55003 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability txtify archive
CVE-2026-54995 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability txtify archive
CVE-2026-55144 Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability txtify archive
CVE-2026-56155 Active Directory Federation Services Elevation of Privilege Vulnerability txtify archive
CVE-2026-50694 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability txtify archive
CVE-2026-57976 Windows Active Directory Domain Services Denial of Service Vulnerability txtify archive
CVE-2026-57979 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability txtify archive
CVE-2026-58601 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability txtify archive
CVE-2026-40378 Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability txtify archive
CVE-2026-47632 Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability txtify archive
CVE-2026-49178 Windows Active Directory Domain Services Remote Code Execution Vulnerability txtify archive
CVE-2026-49180 Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability txtify archive
CVE-2026-49790 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-49791 Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-49792 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability txtify archive
CVE-2026-49793 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability txtify archive
CVE-2026-49800 Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability txtify archive
CVE-2026-49799 Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability txtify archive
CVE-2026-49803 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability txtify archive
CVE-2026-50318 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50351 Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50350 Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability txtify archive
CVE-2026-50381 Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability txtify archive
CVE-2026-50372 Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability txtify archive
CVE-2026-50304 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50368 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50407 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50331 Windows Application Model Core API Elevation of Privilege Vulnerability txtify archive
CVE-2026-50425 Windows Internal System User Profile Elevation of Privilege Vulnerability txtify archive
CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50312 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-50357 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50366 Windows Active Directory Domain Services Denial of Service Vulnerability txtify archive
CVE-2026-50355 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50428 Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability txtify archive
CVE-2026-50371 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-50401 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability txtify archive
CVE-2026-50445 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability txtify archive
CVE-2026-50365 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50421 Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability txtify archive
CVE-2026-50374 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-50451 Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50455 Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability txtify archive
CVE-2026-50441 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50439 Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability txtify archive
CVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-50432 Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability txtify archive
CVE-2026-50431 Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability txtify archive
CVE-2026-50447 Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability txtify archive
CVE-2026-50362 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability txtify archive
CVE-2026-50411 Windows Active Directory Federation Services Denial of Service Vulnerability txtify archive
CVE-2026-50444 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50476 Windows Network Connections Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-50450 Windows Network Connections Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-50470 Windows Network Policy Server SNMP Information Disclosure Vulnerability txtify archive
CVE-2026-50480 Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50498 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50505 Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability txtify archive
CVE-2026-50492 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability txtify archive
CVE-2026-50501 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability txtify archive
CVE-2026-50497 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability txtify archive
CVE-2026-50496 Windows Network Policy Server SNMP Information Disclosure Vulnerability txtify archive
CVE-2026-50509 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability txtify archive
CVE-2026-50657 Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability txtify archive
CVE-2026-50658 Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability txtify archive
CVE-2026-50667 Windows Common Log File System Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-50668 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Vulnerability txtify archive
CVE-2026-54126 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability txtify archive
CVE-2026-55944 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability txtify archive
CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability txtify archive
CVE-2026-56178 Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability txtify archive
CVE-2026-56647 Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability txtify archive
CVE-2026-57089 Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability txtify archive
CVE-2026-57093 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-57096 Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-57968 Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability txtify archive
CVE-2026-57982 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability txtify archive
CVE-2026-58530 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability txtify archive
CVE-2026-58537 Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-58536 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability txtify archive
CVE-2026-58543 Universal Print Management Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-58613 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-58529 Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability txtify archive
CISA Joins NSA, FBI, DC3 and International Partners Warning of Russian Cyber Threat Activity Targeting Communications, Energy, Government and Other Critical Infrastructure Sectors txtify archive
CVE-2026-12480 Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras txtify archive
Military Commissions Media Invitation Announced for United States v. Encep Nurjaman Pre-Trial Hearing txtify archive
CVE-2022-4543 A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems. txtify archive
CVE-2026-59874 node-tar: Negative tar entry size causes infinite loop in archive replace txtify archive
CVE-2026-15308 Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations txtify archive
Chromium: CVE-2026-13889 Insufficient validation of untrusted input in WebAuthentication txtify archive
CVE-2026-54908 Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message txtify archive
CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop txtify archive
CVE-2026-45571 go-git: Crafted repositories may modify main and submodule .git directories txtify archive
CVE-2024-7598 Network restriction bypass via race condition during namespace termination txtify archive
CVE-2026-56000 xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent() txtify archive
CVE-2026-58209 NATS Server: MQTT retained and QoS replay bypass subscribe deny filters txtify archive
CVE-2026-58250 NATS Server: Pre-auth server crash via double INFO in leafnode handshake txtify archive
CVE-2026-58208 NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled txtify archive
CVE-2026-59890 setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+ txtify archive
CVE-2026-59930 Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content txtify archive
CVE-2026-59922 Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert) txtify archive
CVE-2026-59925 inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs txtify archive
CVE-2026-59928 Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions txtify archive
CVE-2026-14740 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment txtify archive
CVE-2026-14380 DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile txtify archive
CVE-2026-14739 DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders txtify archive
CVE-2026-59998 sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. txtify archive
CVE-2026-20217 ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability txtify archive
CVE-2026-20216 ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability txtify archive
CVE-2026-20215 ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability txtify archive
CVE-2026-20214 ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability txtify archive
CVE-2026-20213 ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability txtify archive
CVE-2026-59818 etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation txtify archive
CVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl txtify archive
CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension txtify archive
CVE-2026-53345 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying txtify archive
CVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length txtify archive
CVE-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 txtify archive
CVE-2026-54908 Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message txtify archive
CVE-2026-38969 ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling. txtify archive
CVE-2026-38968 ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing. txtify archive
CVE-2026-14191 WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader txtify archive
CVE-2026-56000 xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent() txtify archive
CVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) txtify archive
CVE-2026-59999 In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. txtify archive
CVE-2026-60000 sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication. txtify archive
CVE-2026-60001 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. txtify archive
CVE-2026-59995 sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server. txtify archive
CVE-2026-59996 scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. txtify archive
CVE-2026-59997 internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection. txtify archive
CVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
CVE-2026-12480 Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras txtify archive
CVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl txtify archive
CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop txtify archive
CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension txtify archive
Between Graves and Uncertainty: The Management of the Dead After Venezuela’s Earthquake txtify archive
Chromium: CVE-2026-13921 Insufficient validation of untrusted input in DeviceBoundSessionCredentials txtify archive
Chromium: CVE-2026-14021 Insufficient validation of untrusted input in StorageAccessAPI txtify archive
CVE-2026-57918 libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker. txtify archive
CVE-2026-57231 Podman: Malformed Image can trick podman run into leaking host environment variables into the container txtify archive
CVE-2026-13322 Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service txtify archive
CVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length txtify archive
CVE-2026-3195 Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730) txtify archive
CVE-2026-56412 libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219. txtify archive
CVE-2026-56407 libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. txtify archive
CVE-2026-56406 libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. txtify archive
CVE-2026-56132 In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers. txtify archive
CVE-2026-56131 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation). txtify archive
CVE-2026-57585 MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error txtify archive
CVE-2026-13757 P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing txtify archive
CVE-2026-12912 Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image txtify archive
CVE-2026-14164 Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack() txtify archive
CVE-2026-14258 Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling txtify archive
CVE-2026-55200 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c txtify archive
CVE-2026-52944 ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE txtify archive
CVE-2026-56149 Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service txtify archive
CVE-2026-49090 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service txtify archive
CVE-2026-57100 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability txtify archive
Locked up like an animal in cage...forced to witness rape and slaughter...tortured until they prayed for death: October 7 hostages' most horrifying accounts yet of what they endured at the hands of Hamas txtify archive
CISA Announces New Advisory Council to Strengthen Partnerships and Secure Critical Infrastructure txtify archive
CVE-2026-57062 CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182. txtify archive
CVE-2026-13595 Util-linux: util-linux: heap use-after-free in libblkid nested partition probing txtify archive
CVE-2026-11625 Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes txtify archive
CVE-2026-6092 Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured txtify archive
CVE-2026-11310 X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring txtify archive
CVE-2026-10097 ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery txtify archive
CVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status txtify archive
CVE-2026-12340 Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation txtify archive
CVE-2026-10512 X25519 x86_64 assembly final reduction leaves non-canonical field element txtify archive
CVE-2026-6091 Partial-chain verification accepts untrusted intermediate as trust anchor txtify archive
CVE-2026-6325 Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list txtify archive
CVE-2026-55958 Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage txtify archive
CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData txtify archive
CVE-2026-6678 Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info txtify archive
CVE-2026-55961 wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer txtify archive
CVE-2026-11999 X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert() txtify archive
CVE-2026-55962 TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify txtify archive
CVE-2026-55967 AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse txtify archive
CVE-2026-11703 Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption txtify archive
CVE-2026-55964 Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption) txtify archive
CVE-2026-55960 Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation txtify archive
CVE-2026-7532 iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined txtify archive
CVE-2026-57918 libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker. txtify archive
CVE-2026-57231 Podman: Malformed Image can trick podman run into leaking host environment variables into the container txtify archive
CVE-2026-13325 Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces txtify archive
CVE-2026-13218 Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher txtify archive
CVE-2026-13208 Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body txtify archive
CVE-2026-13318 Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip txtify archive
CVE-2026-13322 Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service txtify archive
CVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length txtify archive
CVE-2026-58014 Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" txtify archive
CVE-2026-58013 Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" txtify archive
CVE-2026-58011 Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime txtify archive
CVE-2026-58012 Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() txtify archive
CVE-2026-58016 Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" txtify archive
CVE-2026-58015 Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive txtify archive
CVE-2026-58010 Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() txtify archive
CVE-2026-54371 attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr txtify archive
CVE-2026-42910 Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability txtify archive
Military Commissions Media Invitation Announced for United States v. Abd al-Rahim al-Nashiri Pre-Trial Hearing txtify archive
CVE-2026-54371 attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr txtify archive
CVE-2026-54369 acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions txtify archive
The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem txtify archive
CVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length txtify archive
CVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() txtify archive
CVE-2026-3196 Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation txtify archive
CVE-2026-6100 Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure txtify archive
CVE-2026-3195 Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730) txtify archive
CVE-2026-35387 OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms. txtify archive
CVE-2026-5119 Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment txtify archive
CVE-2026-9697 undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent txtify archive
CVE-2025-38585 staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int() txtify archive
CVE-2024-58266 The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection. txtify archive
CVE-2026-23383 bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing txtify archive
CVE-2026-9675 undici WebSocket client vulnerable to denial of service via cumulative fragment bypass txtify archive
CVE-2024-53201 drm/amd/display: Fix null check for pipe_ctx->plane_state in dcn20_program_pipe txtify archive
CVE-2025-13462 tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling txtify archive
CVE-2025-38269 btrfs: exit after state insertion failure at btrfs_convert_extent_bit() txtify archive
CVE-2026-3099 Libsoup: libsoup: authentication bypass via digest authentication replay attack txtify archive
CVE-2025-38279 bpf: Do not include stack ptr register in precision backtracking bookkeeping txtify archive
CVE-2026-3632 Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames txtify archive
CVE-2026-3634 Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header txtify archive
CVE-2026-12003 CPython >3.11 Insecure Input Validation resulting in privilege escalation txtify archive
CVE-2026-55653 Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service txtify archive
CVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2 txtify archive
CVE-2026-55655 Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions txtify archive
CVE-2024-26962 dm-raid456, md/raid456: fix a deadlock for dm-raid456 while io concurrent with reshape txtify archive
CVE-2026-11525 undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching txtify archive
CVE-2026-43973 gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion txtify archive
CVE-2026-56412 libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219. txtify archive
CVE-2026-49762 Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service txtify archive
CVE-2026-43059 Bluetooth: MGMT: Fix list corruption and UAF in command complete handlers txtify archive
CVE-2026-56407 libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. txtify archive
CVE-2024-36024 drm/amd/display: Disable idle reallow as part of command/gpint execution txtify archive
CVE-2026-56406 libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. txtify archive
CVE-2026-53027 fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked() txtify archive
CVE-2025-40325 md/raid10: wait barrier before returning discard request with REQ_NOWAIT txtify archive
CVE-2024-30896 InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organizations. A future release of InfluxDB 2.x will remove the ability to retrieve tokens from the API. txtify archive
CVE-2026-56132 In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers. txtify archive
CVE-2026-46275 Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths txtify archive
CVE-2025-58160 Tracing logging user input may result in poisoning logs with ANSI escape sequences txtify archive
CVE-2026-7774 tarfile.data_filter path traversal bypass allows writing outside the extraction directory txtify archive
CVE-2026-53207 mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison txtify archive
CVE-2026-56131 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation). txtify archive
CVE-2024-50217 btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids() txtify archive
CVE-2026-10275 OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow txtify archive
CVE-2024-24856 NULL pointer deference in acpi_db_convert_to_package of Linux acpi module txtify archive
CVE-2026-42507 Arbitrary inputs are included in errors without any escaping in net/textproto txtify archive
CVE-2024-57898 wifi: cfg80211: clear link ID from bitmap during link delete after clean up txtify archive
CVE-2026-57453 Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction txtify archive
CVE-2025-22115 btrfs: fix block group refcount race in btrfs_create_pending_block_groups() txtify archive
CVE-2025-21885 RDMA/bnxt_re: Fix the page details for the srq created by kernel consumers txtify archive
CVE-2024-50004 drm/amd/display: update DML2 policy EnhancedPrefetchScheduleAccelerationFinal DCN35 txtify archive
CVE-2026-52988 netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase txtify archive
CVE-2025-68190 drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked() txtify archive
CVE-2026-55895 Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename txtify archive
CVE-2024-49945 net/ncsi: Disable the ncsi work before freeing the associated structure txtify archive
CVE-2026-57455 Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument txtify archive
CVE-2026-8643 pip can extract console_scripts and gui_scripts outside installation directory txtify archive
CVE-2024-49970 drm/amd/display: Implement bounds check for stream encoder creation in DCN401 txtify archive
CVE-2026-6324 Libsoup: libsoup: http request smuggling via unsigned to signed conversion error txtify archive
CVE-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 txtify archive
CVE-2026-52947 net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove txtify archive
CVE-2026-53143 drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 txtify archive
CVE-2024-49918 drm/amd/display: Add null check for head_pipe in dcn32_acquire_idle_pipe_for_head_pipe_in_layer txtify archive
CVE-2026-46147 KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu() txtify archive
CVE-2024-47702 bpf: Fail verification for sign-extension of packet data/data_end/data_meta txtify archive
CVE-2024-49916 drm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs in dcn401_init_hw txtify archive
CVE-2026-53247 net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown txtify archive
CVE-2026-55200 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c txtify archive
CVE-2024-49908 drm/amd/display: Add null check for 'afb' in amdgpu_dm_update_cursor (v2) txtify archive
CVE-2024-49910 drm/amd/display: Add NULL check for function pointer in dcn401_set_output_transfer_func txtify archive
CVE-2024-47662 drm/amd/display: Remove register from DCN35 DMCUB diagnostic collection txtify archive
CVE-2026-45571 go-git: Crafted repositories may modify main and submodule .git directories txtify archive
CVE-2024-46834 ethtool: fail closed if we can't get max channel used in indirection tables txtify archive
CVE-2025-58186 Lack of limit when parsing cookies can cause memory exhaustion in net/http txtify archive
CVE-2024-46808 drm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range txtify archive
CVE-2024-46727 drm/amd/display: Add otg_master NULL check within resource_log_pipe_topology_update txtify archive
CVE-2025-37861 scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue txtify archive
CVE-2026-53242 ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams txtify archive
CVE-2025-4035 Libsoup: cookie domain validation bypass via uppercase characters in libsoup txtify archive
CVE-2024-1151 Kernel: stack overflow problem in open vswitch kernel module leading to dos txtify archive
CVE-2025-46327 Go Snowflake Driver has race condition when checking access to Easy Logging configuration file txtify archive
CVE-2025-39932 smb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work) txtify archive
CVE-2024-43824 PCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init() txtify archive
CVE-2026-53239 xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() txtify archive
CVE-2025-39905 net: phylink: add lock for serializing concurrent pl->phydev writes with resolver txtify archive
CVE-2024-26672 drm/amdgpu: Fix variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()' txtify archive
CVE-2026-45934 btrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation txtify archive
CVE-2025-29923 go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment txtify archive
CVE-2026-53166 futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock txtify archive
CVE-2026-53080 net/sched: cls_fw: fix NULL dereference of "old" filters before change() txtify archive
CVE-2026-53198 ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL txtify archive
CVE-2026-45859 netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation txtify archive
CVE-2019-11254 Kubernetes API Server denial of service vulnerability from malicious YAML payloads txtify archive
CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent txtify archive
CVE-2024-58089 btrfs: fix double accounting race when btrfs_run_delalloc_range() failed txtify archive
CVE-2013-1633 easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product. txtify archive
CVE-2026-9149 Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file txtify archive
CVE-2026-53178 staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction txtify archive
CVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums txtify archive
CVE-2024-25740 A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released. txtify archive
CVE-2024-24864 Race condition vulnerability in Linux kernel media/dvb-core in dvbdmx_write() txtify archive
CVE-2024-23848 In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c. txtify archive
CVE-2022-4543 A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems. txtify archive
CVE-2026-53655 node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling) txtify archive
CVE-2026-44889 WebOb: Location header normalization during redirect leads to open redirect txtify archive
'I survived, but I lost my life. I wish I died that day': Chef, 28, applies to be euthanised two years after 'ex-boyfriend beat her up so badly she lost her sense of smell and taste' txtify archive
Heartbreaking final moments of 'Sleeping Beauty of Everest' who begged climber 'don't leave me here to die' before her body froze in time in mountain 'death zone' txtify archive
Chromium: CVE-2026-13021 Inappropriate implementation in DeviceBoundSessionCredentials txtify archive
CVE-2026-4367 Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing txtify archive
CVE-2026-41086 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability txtify archive
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus txtify archive
CVE-2026-4367 Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing txtify archive
New CISA Guide Assists Federal Agencies with Transitioning to Modernized Zero Trust Architectures txtify archive
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager txtify archive
CVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes txtify archive
CVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() txtify archive
CVE-2026-10275 OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow txtify archive
CVE-2026-8376 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds txtify archive
CVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2 txtify archive
CVE-2026-47645 Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability txtify archive
Remarks by Secretary of War Pete Hegseth at the 2026 NATO Defense Ministerial in Brussels (As Delivered) txtify archive
CVE-2026-46293 clk: microchip: mpfs-ccc: fix out of bounds access during output registration txtify archive
CVE-2026-43308 btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html txtify archive
CVE-2026-48854 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc txtify archive
Secretary of War Pete Hegseth Hosted Bilateral Meeting With the Italian Republic Defense Minister His Excellency Guido Crosetto at the Pentagon txtify archive
CVE-2026-40371 Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability txtify archive
CVE-2026-45602 Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability txtify archive
CVE-2026-54411 Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext. txtify archive
Secretary of War Pete Hegseth Greets His Excellency Daniel Noboa, the President of the Republic of Ecuador txtify archive
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research txtify archive
CVE-2026-49762 Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service txtify archive
CVE-2026-7774 tarfile.data_filter path traversal bypass allows writing outside the extraction directory txtify archive
CVE-2026-11526 GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle txtify archive
CVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() txtify archive
CVE-2026-40034 gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule txtify archive
CVE-2026-5223 Crates in third party registries can override the cached source of other crates txtify archive
CVE-2023-5678 Excessive time spent in DH check / generation with large Q parameter value txtify archive
CVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes txtify archive
CVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() txtify archive
CVE-2026-44705 tmp: Path Traversal via unsanitized prefix/postfix enables directory escape txtify archive
CVE-2026-47162 Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name txtify archive
CVE-2026-47167 Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex txtify archive
CVE-2026-46643 Snappy: Binary path is never shell-escaped due to an inverted is_executable check txtify archive
CVE-2026-8829 HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities txtify archive
CVE-2026-5419 Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal txtify archive
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution txtify archive
CVE-2026-42012 Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans txtify archive
CVE-2026-5260 Gnutls: gnutls: information disclosure via heap overread in rsa key exchange txtify archive
CVE-2026-42015 Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling txtify archive
CVE-2026-42013 Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name txtify archive
CVE-2026-50263 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow() txtify archive
CVE-2026-50258 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels txtify archive
CVE-2026-50257 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence() txtify archive
CVE-2026-50259 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing txtify archive
CVE-2026-50260 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter() txtify archive
CVE-2026-50262 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes txtify archive
CVE-2026-50256 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch txtify archive
CVE-2026-50261 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter() txtify archive
CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders txtify archive
CVE-2026-43958 Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service txtify archive
CVE-2026-44185 Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` txtify archive
CVE-2026-44631 Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow txtify archive
CVE-2026-43951 Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash txtify archive
CVE-2026-44119 Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules txtify archive
CVE-2026-48913 Apache HTTP Server: mod_http2 memory corruption when file handles exhausted txtify archive
CVE-2026-45482 Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability txtify archive
CVE-2026-40371 Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-49762 Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service txtify archive
CVE-2026-43059 Bluetooth: MGMT: Fix list corruption and UAF in command complete handlers txtify archive
CVE-2026-46293 clk: microchip: mpfs-ccc: fix out of bounds access during output registration txtify archive
CVE-2026-46280 lib: test_hmm: evict device pages on file close to avoid use-after-free txtify archive
CVE-2026-46275 Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths txtify archive
CVE-2025-10263 ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel] txtify archive
CVE-2026-40409 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-40404 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-33828 Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability txtify archive
CVE-2026-34335 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45487 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-45639 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability txtify archive
CVE-2026-45606 Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability txtify archive
CVE-2026-45642 Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability txtify archive
CVE-2026-45648 Windows Active Directory Domain Services Remote Code Execution Vulnerability txtify archive
CVE-2026-40371 Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability txtify archive
CVE-2026-45482 Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability txtify archive
CVE-2026-45586 Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability txtify archive
CVE-2026-45594 Windows Application Identity (AppID) Information Disclosure Vulnerability txtify archive
CVE-2026-45597 Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-45601 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45598 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45596 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45602 Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability txtify archive
CVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45603 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-45647 Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability txtify archive
CVE-2026-42910 Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-42836 Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-42908 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability txtify archive
CVE-2026-42911 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-44809 Windows Common Log File System Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-44805 Windows Network Controller (NC) Host Agent Denial of Service Vulnerability txtify archive
CVE-2020-17103 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-7774 tarfile.data_filter path traversal bypass allows writing outside the extraction directory txtify archive
CVE-2026-8643 pip can extract console_scripts and gui_scripts outside installation directory txtify archive
CVE-2026-43958 Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service txtify archive
CVE-2026-10722 cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow txtify archive
CVE-2026-37460 Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. txtify archive
CVE-2026-50219 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, txtify archive
CVE-2026-50292 In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution txtify archive
CVE-2026-42507 Arbitrary inputs are included in errors without any escaping in net/textproto txtify archive
CVE-2026-50031 ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands "ipmi-oem dell get-active-directory-config" and "ipmi-oem fujitsu get-sel-entry-long-text" were found to have exploitable buffer overflows on response messages. txtify archive
CVE-2026-48959 IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward txtify archive
CVE-2025-15649 IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date txtify archive
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob txtify archive
CVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification txtify archive
CVE-2026-42789 Non-CA certificate accepted as intermediate issuer in public_key path validation txtify archive
CVE-2026-40510 OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c txtify archive
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent txtify archive
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
CVE-2026-23479 redis-server use-after-free in unblock client flow may allow remote code execution txtify archive
CVE-2026-25243 redis-server RESTORE invalid memory access may allow remote code execution txtify archive
CVE-2026-27144 Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile txtify archive
CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile txtify archive
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template txtify archive
CVE-2026-50263 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow() txtify archive
CVE-2026-50258 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels txtify archive
CVE-2026-50257 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence() txtify archive
CVE-2026-50259 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing txtify archive
CVE-2026-50260 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter() txtify archive
CVE-2026-50262 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes txtify archive
CVE-2026-50256 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch txtify archive
CVE-2026-50261 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter() txtify archive
CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders txtify archive
CVE-2026-40930 LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body txtify archive
CVE-2026-50265 Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292 txtify archive
The women raped by the Taliban: Victims describe horrific sexual abuse at the hands of multiple men as punishment for getting a job or posting on social media txtify archive
CVE-2026-7774 tarfile.data_filter path traversal bypass allows writing outside the extraction directory txtify archive
CVE-2026-8643 pip can extract console_scripts and gui_scripts outside installation directory txtify archive
CVE-2026-8829 HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities txtify archive
CVE-2026-43958 Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service txtify archive
CVE-2026-5419 Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal txtify archive
CVE-2026-42507 Arbitrary inputs are included in errors without any escaping in net/textproto txtify archive
CVE-2026-37460 Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. txtify archive
CVE-2026-10722 cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow txtify archive
CVE-2026-50219 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, txtify archive
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution txtify archive
Inside the Russian resistance looking to bring down Putin: Exclusive footage shows pro-Ukraine 'Black Spark' rebels 'carrying out bomb attacks on strategic targets' txtify archive
Inside South Africa's whites-only enclave where young people are flocking after deciding 'it's not so wonderful elsewhere' and it's nicer to be 'the majority' txtify archive
CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html txtify archive
CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
CVE-2026-9149 Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file txtify archive
CVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums txtify archive
CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent txtify archive
CVE-2026-42506 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh txtify archive
CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-43964 Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number. txtify archive
CVE-2026-41140 Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4 txtify archive
CVE-2026-35414 OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters. txtify archive
CVE-2026-42151 Prometheus Azure AD remote write OAuth client secret exposed via config API txtify archive
CVE-2026-8177 XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences txtify archive
CVE-2026-43895 jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts txtify archive
CVE-2026-43894 jq: Wild stack write via signed-integer overflow in decNumber D2U() macro txtify archive
CVE-2026-40226 In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. txtify archive
CVE-2026-5223 Crates in third party registries can override the cached source of other crates txtify archive
CVE-2026-27144 Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile txtify archive
CVE-2026-41889 pgx: SQL Injection via placeholder confusion with dollar quoted string literals txtify archive
CVE-2026-8466 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy txtify archive
CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile txtify archive
CVE-2026-39834 Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh txtify archive
CVE-2026-42506 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html txtify archive
CVE-2026-32283 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls txtify archive
CVE-2026-39829 Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-39825 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil txtify archive
CVE-2026-46597 Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh txtify archive
CVE-2026-39830 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh txtify archive
CVE-2026-32282 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix txtify archive
CVE-2026-39819 Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go txtify archive
CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna txtify archive
CVE-2026-29181 OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) txtify archive
CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net txtify archive
CVE-2026-39882 OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies txtify archive
CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent txtify archive
CVE-2025-13462 tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling txtify archive
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html txtify archive
CVE-2026-33846 Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly txtify archive
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template txtify archive
CVE-2026-23479 redis-server use-after-free in unblock client flow may allow remote code execution txtify archive
CVE-2026-25243 redis-server RESTORE invalid memory access may allow remote code execution txtify archive
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh txtify archive
CVE-2026-6383 Kubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluation txtify archive
CVE-2025-58160 Tracing logging user input may result in poisoning logs with ANSI escape sequences txtify archive
CVE-2026-3832 Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response txtify archive
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh txtify archive
CVE-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 txtify archive
CVE-2026-37457 An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component. txtify archive
CVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 txtify archive
CVE-2026-6842 Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions txtify archive
CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html txtify archive
CVE-2025-60876 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). txtify archive
CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html txtify archive
CVE-2025-58186 Lack of limit when parsing cookies can cause memory exhaustion in net/http txtify archive
CVE-2026-4948 Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization txtify archive
CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs txtify archive
CVE-2026-40356 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message. txtify archive
CVE-2025-55554 pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long(). txtify archive
CVE-2026-40355 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message. txtify archive
CVE-2025-55551 An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation. txtify archive
CVE-2026-41526 In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection. txtify archive
CVE-2026-42009 Gnutls: gnutls: denial of service via dtls packet reordering vulnerability txtify archive
CVE-2024-58266 The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection. txtify archive
CVE-2026-45803 gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection txtify archive
CVE-2026-6357 pip self-update functionality can import newly installed modules after wheel installation txtify archive
CVE-2025-46327 Go Snowflake Driver has race condition when checking access to Easy Logging configuration file txtify archive
CVE-2026-8328 FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address txtify archive
CVE-2025-46394 In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences. txtify archive
CVE-2026-8368 LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects txtify archive
CVE-2024-58251 In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim. txtify archive
CVE-2026-43968 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1 txtify archive
CVE-2025-29923 go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment txtify archive
CVE-2026-7790 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS txtify archive
CVE-2026-43969 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1 txtify archive
CVE-2024-7598 Network restriction bypass via race condition during namespace termination txtify archive
CVE-2026-40225 In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output. txtify archive
CVE-2026-7210 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection txtify archive
CVE-2026-34956 Openvswitch: open vswitch: denial of service via malformed ftp epasv command txtify archive
CVE-2025-1180 GNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruption txtify archive
CVE-2024-30896 InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organizations. A future release of InfluxDB 2.x will remove the ability to retrieve tokens from the API. txtify archive
CVE-2026-42304 Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains txtify archive
CVE-2019-11254 Kubernetes API Server denial of service vulnerability from malicious YAML payloads txtify archive
CVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() txtify archive
CVE-2013-1633 easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product. txtify archive
CVE-2026-6100 Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure txtify archive
CVE-2023-27043 The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python. txtify archive
CVE-2025-15649 IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date txtify archive
CVE-2026-25833 Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function txtify archive
CVE-2026-34873 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. txtify archive
CVE-2026-34874 An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0. txtify archive
CVE-2025-15504 lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference txtify archive
CVE-2026-34875 An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. txtify archive
CVE-2026-34871 An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). txtify archive
CVE-2026-21711 A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose local IPC endpoints, allowing communication with other processes on the same host outside of the intended network restriction boundary. This vulnerability affects Node.js **25.x** processes using the Permission Model where `--allow-net` is intentionally omitted to restrict network access. Note that `--allow-net` is currently an experimental feature. txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2026-25835 Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). txtify archive
CVE-2026-33672 Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching txtify archive
CVE-2026-34872 An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle). txtify archive
CVE-2017-3736 There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen. txtify archive
CVE-2025-66442 In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. txtify archive
CVE-2026-34876 An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API. txtify archive
CVE-2026-42015 Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling txtify archive
CVE-2026-9538 Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header txtify archive
CVE-2026-7259 Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() txtify archive
CVE-2026-7262 NULL pointer dereference in SOAP apache:Map decoder with missing <value> txtify archive
CVE-2026-46121 mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock txtify archive