Currently trending CVE - Hype Score: 15 - Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
Currently trending CVE - Hype Score: 13 - In the Linux kernel, the following vulnerability has been resolved:
can: raw: fix ro->uniq use-after-free in raw_rcv()
raw_release() unregisters raw CAN receive filters via can_rx_unregister(),
but receiver deletion is deferred with call_rcu(). This leaves a window
where ...
Currently trending CVE - Hype Score: 13 - In the Linux kernel, the following vulnerability has been resolved:
fuse: reject oversized dirents in page cache
fuse_add_dirent_to_cache() computes a serialized dirent size from the
server-controlled namelen field and copies the dirent into a single
page-cache page. The ...
Currently trending CVE - Hype Score: 1 - A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in ...
Currently trending CVE - Hype Score: 1 - Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into ...
A vulnerability, which was classified as problematic, has been found in memcached up to 1.6.41. Affected by this issue is the function sasl_server_userdb_checkpass. Performing a manipulation results in observable timing discrepancy.
This vulnerability is reported as CVE-2026-47783. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability labeled as problematic has been found in MongoDB Compass. This vulnerability affects unknown code. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.
This vulnerability is handled as CVE-2026-9101. The attack can be executed remotely. There is not any exploit available.
A vulnerability marked as problematic has been reported in Keycloak on Red Hat. This issue affects some unknown processing. The manipulation leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2026-9087. Local access is required to approach this attack. No exploit exists.
A vulnerability was found in CODESYS Visualization 4.2.0.0/4.8.0.0. It has been rated as problematic. This affects an unknown part of the component Concurrent Login. The manipulation leads to insufficiently protected credentials.
This vulnerability is referenced as CVE-2026-0393. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, has been found in Splunk Enterprise and Cloud Platform. This affects an unknown function. Performing a manipulation results in sensitive information in log files.
This vulnerability is identified as CVE-2026-20239. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.18.18/6.19.8. It has been declared as problematic. This issue affects the function vma_lookup. The manipulation results in privilege escalation.
This vulnerability is identified as CVE-2026-43434. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.19.11. Impacted is the function check_mem_access. This manipulation causes null pointer dereference.
This vulnerability is registered as CVE-2026-43333. The attack requires access to the local network. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.18.18/6.19.8. This affects the function try_release_subpage_extent_buffer. Such manipulation leads to infinite loop.
This vulnerability is documented as CVE-2026-43358. The attack requires being on the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability labeled as critical has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability appears as CVE-2026-8212. The attack requires local access. In addition, an exploit is available.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.18.18/6.19.8. Affected by this vulnerability is an unknown functionality. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2026-43356. Access to the local network is required for this attack to succeed. There is no exploit available.
It is suggested to upgrade the affected component.