Search

Search Results (396938 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-15801 1 Redhat 2 Openshift, Openshift Container Platform 2026-09-22 8 High
A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with sufficient privileges to perform unintended operations on the host filesystem. Successful exploitation requires that container checkpoint and restore functionality is enabled, which is not the default configuration. An attacker must also be able to trigger restoration of a container from untrusted checkpoint content.
CVE-2026-13087 1 Redhat 3 Enterprise Linux, Enterprise Linux For Nvidia 26, Enterprise Linux Nvidia 2026-09-22 8.8 High
A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large NFS READ request with an empty Write list and no Reply chunk, the server linearizes the entire multi-page reply into a fixed-size 4096-byte heap buffer without bounds checking, resulting in a kernel heap overflow. This can lead to denial of service via kernel crash or potential code execution through corruption of adjacent kernel heap objects.
CVE-2026-65114 1 Nvidia 1 Infrastructure Controller 2026-09-22 8.3 High
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
CVE-2026-65117 1 Nvidia 1 Infrastructure Controller 2026-09-22 5 Medium
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
CVE-2026-65127 1 Nvidia 1 Infrastructure Controller 2026-09-22 4.1 Medium
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-65124 1 Nvidia 1 Infrastructure Controller 2026-09-22 5.9 Medium
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.
CVE-2026-25265 1 Qualcomm 1 Snapdragon 2026-09-22 8.8 High
Privilege escalation due to weak configuration while temporary file handling.
CVE-2026-25254 1 Qualcomm 1 Snapdragon 2026-09-22 9.8 Critical
Improper authorization leads to Remote Code Execution via SocketIO interface.
CVE-2026-65126 1 Nvidia 1 Infrastructure Controller 2026-09-22 5 Medium
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
CVE-2026-65128 1 Nvidia 1 Infrastructure Controller 2026-09-22 8.8 High
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CVE-2026-65112 1 Nvidia 1 Infrastructure Controller 2026-09-22 6.5 Medium
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-65111 1 Nvidia 1 Nemo Speech 2026-09-22 7.8 High
NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
CVE-2026-65121 1 Nvidia 1 Infrastructure Controller 2026-09-22 8.2 High
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.
CVE-2026-65125 1 Nvidia 1 Infrastructure Controller 2026-09-22 6.6 Medium
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.
CVE-2026-25275 1 Qualcomm 753 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Aqt1000 and 750 more 2026-09-22 7.5 High
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-24075 1 Qualcomm 87 Aqt1000, Aqt1000 Firmware, Cologne and 84 more 2026-09-22 7.8 High
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
CVE-2026-95623 1 Tauri 1 Tauri-plugin-http 2026-09-22 5.6 Medium
The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally without re-checking the new target URL against the scope. This allows an attacker who controls an allowed URL (or finds an open redirect on an allowed host) to reach disallowed destinations such as cloud metadata endpoints, localhost services, or internal network hosts.
CVE-2025-59607 1 Qualcomm 29 Cologne, Cologne Firmware, Fastconnect 6900 and 26 more 2026-09-22 7.8 High
Memory Corruption when copying large input data exceeds normal allocation limits.
CVE-2026-75595 1 Netty 1 Netty 2026-09-22 9.1 Critical
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
CVE-2026-24073 1 Qualcomm 29 Cologne, Cologne Firmware, Fastconnect 6900 and 26 more 2026-09-22 7.8 High
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.