Common Vulnerabilities and Exposures (CVE)

CVE-2026-16971

Jul 30, 2026 09:43:51 UTC

The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.

CVE-2026-18361

Jul 30, 2026 09:42:25 UTC

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.

CVE-2025-12390

Jul 30, 2026 09:41:42 UTC

A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up pr...

CVE-2026-18360

Jul 30, 2026 09:41:18 UTC

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.

CVE-2026-16969

Jul 30, 2026 09:40:14 UTC

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.

CVE-2026-4948

Jul 30, 2026 09:27:53 UTC

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the...

CVE-2026-46579

Jul 30, 2026 09:19:26 UTC

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plai...

CVE-2022-4994

Jul 30, 2026 09:18:06 UTC

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __emulator_pio_in() directly for fast PIO instead of bouncing through emulator_pio_in() now that __emulator_pio_in() fills...

CVE-2026-15370

Jul 30, 2026 08:29:07 UTC

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficientl...

CVE-2026-52718

Jul 30, 2026 08:23:58 UTC

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchroniza...

CVE-2026-55655

Jul 30, 2026 08:22:20 UTC

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a l...

CVE-2026-55653

Jul 30, 2026 08:22:19 UTC

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group valid...

CVE-2026-52722

Jul 30, 2026 07:37:12 UTC

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds rea...

CVE-2026-52720

Jul 30, 2026 07:36:56 UTC

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends...

CVE-2026-52719

Jul 30, 2026 07:36:51 UTC

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick...