CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-86345 CRITICAL

389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result

CVSS 9.0 EPSS n/a Oct 1, 2026
CVE-2026-86344 HIGH

389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue

CVSS 7.5 EPSS n/a Oct 1, 2026
CVE-2026-103884 MEDIUM

Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read

CVSS 6.5 EPSS n/a Oct 1, 2026
CVE-2026-56098 MEDIUM

Rubygem-katello: improper authorization logic allows resource enumeration

CVSS 4.3 EPSS n/a Oct 1, 2026
CVE-2026-56097 MEDIUM

Rubygem-katello: sql injection in registry proxy via labels

CVSS 6.5 EPSS n/a Oct 1, 2026
CVE-2026-12542 MEDIUM

Foreman: command injection in foreman-tail

CVSS 5.3 EPSS n/a Oct 1, 2026
CVE-2026-12545 MEDIUM

Rubygem-hammer_cli: command injection via insecure editor invocation

CVSS 6.7 EPSS n/a Oct 1, 2026
CVE-2026-12544 HIGH

Foreman: ssti and insecure deserialization in foreman-rake configuration

CVSS 7.7 EPSS n/a Oct 1, 2026
CVE-2026-12541 HIGH

Foreman: command injection in foreman-rake database tasks

CVSS 8.2 EPSS n/a Oct 1, 2026
CVE-2026-12540 HIGH

Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter

CVSS 8.2 EPSS n/a Oct 1, 2026
CVE-2026-12423 HIGH

Foreman: unauthenticated information disclosure via provisioning token validation flaw

CVSS 7.5 EPSS n/a Oct 1, 2026
CVE-2026-12405 HIGH

Rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter

CVSS 8.8 EPSS n/a Oct 1, 2026
CVE-2026-103754 MEDIUM

Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directory

CVSS 5.9 EPSS n/a Oct 1, 2026
CVE-2026-96577 HIGH

Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled

CVSS 7.1 EPSS n/a Oct 1, 2026
CVE-2026-83589 MEDIUM

Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect

CVSS 6.1 EPSS n/a Oct 1, 2026
CVE-2026-103641 MEDIUM

Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder

CVSS 5.5 EPSS n/a Oct 1, 2026
CVE-2026-103399 MEDIUM

Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body

CVSS 5.3 EPSS 0.41% Sep 30, 2026
CVE-2026-103242 HIGH

Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag

CVSS 7.1 EPSS 0.17% Sep 30, 2026
CVE-2026-62146 HIGH

Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket

CVSS 7.8 EPSS 0.15% Sep 30, 2026
CVE-2026-102560 HIGH

Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth

CVSS 8.6 EPSS 0.30% Sep 29, 2026
CVE-2026-102559 HIGH

Libsoup: libsoup: heap buffer overflow during websocket client-frame masking

CVSS 8.6 EPSS 0.30% Sep 29, 2026
CVE-2026-102558 HIGH

Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth

CVSS 8.6 EPSS 0.30% Sep 29, 2026
CVE-2026-102555 HIGH

Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding

CVSS 8.2 EPSS 0.32% Sep 29, 2026
CVE-2026-102623 MEDIUM

Kubevirt: kubevirt: virt-controller nil-pointer dereference via malformed ephemeral volume

CVSS 6.5 EPSS 0.31% Sep 29, 2026
CVE-2026-102557 HIGH

Libsoup: libsoup: heap buffer overflow during websocket message reassembly

CVSS 8.6 EPSS 0.22% Sep 29, 2026

Showing 1 to 25 CVEs · page 1 (more available)