CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-86345 CRITICAL

389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result

CVSS 9.0 EPSS n/a Oct 1, 2026
CVE-2026-86344 HIGH

389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue

CVSS 7.5 EPSS n/a Oct 1, 2026
CVE-2026-103641 MEDIUM

Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder

CVSS 5.5 EPSS n/a Oct 1, 2026
CVE-2026-103399 MEDIUM

Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body

CVSS 5.3 EPSS 0.41% Sep 30, 2026
CVE-2026-103242 HIGH

Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag

CVSS 7.1 EPSS 0.17% Sep 30, 2026
CVE-2026-102560 HIGH

Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth

CVSS 8.6 EPSS 0.30% Sep 29, 2026
CVE-2026-102559 HIGH

Libsoup: libsoup: heap buffer overflow during websocket client-frame masking

CVSS 8.6 EPSS 0.30% Sep 29, 2026
CVE-2026-102558 HIGH

Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth

CVSS 8.6 EPSS 0.30% Sep 29, 2026
CVE-2026-102555 HIGH

Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding

CVSS 8.2 EPSS 0.32% Sep 29, 2026
CVE-2026-102557 HIGH

Libsoup: libsoup: heap buffer overflow during websocket message reassembly

CVSS 8.6 EPSS 0.22% Sep 29, 2026
CVE-2026-102556 HIGH

Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion

CVSS 8.6 EPSS 0.22% Sep 29, 2026
CVE-2026-95520 HIGH

Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages

CVSS 7.1 EPSS 0.12% Sep 29, 2026
CVE-2026-97029 MEDIUM

Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group

CVSS 5.7 EPSS 0.24% Sep 29, 2026
CVE-2026-97024 HIGH

Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc

CVSS 7.1 EPSS 0.31% Sep 29, 2026
CVE-2026-97027 LOW

Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus service files

CVSS 3.6 EPSS 0.13% Sep 28, 2026
CVE-2026-97026 LOW

Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path

CVSS 3.9 EPSS 0.11% Sep 28, 2026
CVE-2026-97025 LOW

Flatpak: flatpak: world-readable oci authentication token in system-helper cache path

CVSS 3.2 EPSS 0.13% Sep 28, 2026
CVE-2026-102010 HIGH

Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in binary heap erase_if

CVSS 7.0 EPSS 0.24% Sep 28, 2026
CVE-2026-97023 HIGH

Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy directory export/bin

CVSS 7.1 EPSS 0.28% Sep 28, 2026
CVE-2026-96284 LOW

Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following

CVSS 2.5 EPSS 0.14% Sep 27, 2026
CVE-2026-96282 LOW

Flatpak: flatpak: extension metadata path traversal file existence oracle

CVSS 3.1 EPSS 0.33% Sep 27, 2026
CVE-2026-96283 LOW

Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pull

CVSS 3.3 EPSS 0.15% Sep 27, 2026
CVE-2026-96281 MEDIUM

Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes

CVSS 6.2 EPSS 0.17% Sep 27, 2026
CVE-2026-96280 HIGH

Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems

CVSS 7.5 EPSS 0.60% Sep 27, 2026
CVE-2026-96279 MEDIUM

Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks

CVSS 6.5 EPSS 0.63% Sep 27, 2026

Showing 1 to 25 CVEs · page 1 (more available)