Common Vulnerabilities and Exposures (CVE)

CVE-2023-4669

May 21, 2026 11:10:06 UTC

Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. This issue affects SYSGuard 3001: before 3.2.20.0.

CVE-2026-43494

May 21, 2026 10:49:21 UTC

In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and...

CVE-2026-0393

May 21, 2026 10:44:42 UTC

The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within ...

CVE-2026-45254

May 21, 2026 09:34:37 UTC

In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" instead of being rejected. In certain scenarios, an application that had previously restrict...

CVE-2026-41999

May 21, 2026 09:27:26 UTC

Incorrect Behaviour of Views with TCP PROXY Requests

CVE-2026-45255

May 21, 2026 09:27:20 UTC

When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and use bsddialog(1) to prompt the user to select a network. This is implemented using a shell script, and the code which ha...

CVE-2026-42002

May 21, 2026 09:27:04 UTC

Concurrency and locking defects in GSS-TSIG

CVE-2026-42001

May 21, 2026 09:26:38 UTC

Insufficient Validation of Autoprimary SOA Queries

CVE-2026-42000

May 21, 2026 09:25:43 UTC

Insufficient Validation of Names During AXFR

CVE-2026-42396

May 21, 2026 09:25:03 UTC

Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

CVE-2026-39461

May 21, 2026 09:20:26 UTC

libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for data to become available. However, it does not verify that its socket descriptor fits within select(2)'s descriptor set...

CVE-2026-45253

May 21, 2026 09:17:29 UTC

ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls. As a result, a user with the ability to debug a process may trigger arbitrary code execution in the kernel, even if the targ...

CVE-2026-45252

May 21, 2026 09:08:00 UTC

When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a given file. The FUSE protocol requires the daemon to return a ...

CVE-2026-45251

May 21, 2026 09:04:52 UTC

A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. Because the blocked thread does not hold a reference to the underlying object, this closure may result in the object bein...

CVE-2023-4670

May 21, 2026 08:56:22 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Innosa Probbys allows SQL Injection. This issue affects Probbys: before 2.