Common Vulnerabilities and Exposures (CVE)

CVE-2025-47711

Jun 25, 2026 23:38:15 UTC

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the ...

CVE-2025-1244

Jun 25, 2026 23:36:57 UTC

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially ...

CVE-2026-57455

Jun 25, 2026 23:30:00 UTC

Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. It...

CVE-2026-22879

Jun 25, 2026 23:29:39 UTC

vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability

CVE-2026-9222

Jun 25, 2026 23:29:03 UTC

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and g...

CVE-2026-57436

Jun 25, 2026 23:27:34 UTC

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Document#root= validated only that the new root was a Nokogiri::XML::Node, allowing a DTD node to be set as the document root...

CVE-2026-9221

Jun 25, 2026 23:27:26 UTC

The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between the mobile client and the backend REST API. Attackers could potentiall...

CVE-2025-7195

Jun 25, 2026 23:26:57 UTC

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/pass...

CVE-2026-10517

Jun 25, 2026 23:26:55 UTC

A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or scheme filtering. When PSK authentication is not configured (opt-in, not enforced by defau...

CVE-2026-46733

Jun 25, 2026 23:25:26 UTC

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution...

CVE-2026-12398

Jun 25, 2026 23:24:06 UTC

A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with she...

CVE-2026-54836

Jun 25, 2026 23:23:53 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5.

CVE-2026-11820

Jun 25, 2026 23:23:47 UTC

A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding API credentials (api_key and api_secret) into URL query parameters and sending them via...

CVE-2026-13083

Jun 25, 2026 23:23:42 UTC

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS)...

CVE-2026-13318

Jun 25, 2026 23:23:38 UTC

A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the target IP from vmi.Status.Interfaces[0].IP and pas...