Common Vulnerabilities and Exposures (CVE)

CVE-2026-16313

Oct 8, 2026 20:44:18 UTC

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied...

CVE-2026-14474

Oct 8, 2026 20:44:11 UTC

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree...

CVE-2026-1933

Oct 8, 2026 20:43:55 UTC

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete repar...

CVE-2026-79842

Oct 8, 2026 20:37:57 UTC

An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713

CVE-2026-107318

Oct 8, 2026 20:32:03 UTC

@fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. In versions prior to 12.7.0, all of the built-in HTTPS transports override the secure default and set rejectUnauthorized to false, so the pr...

CVE-2026-11332

Oct 8, 2026 20:29:35 UTC

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can injec...

CVE-2026-107709

Oct 8, 2026 20:23:46 UTC

A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability located in `lib/decompress-zip.js` improperly validates archive entry paths during ZIP extraction. A crafted ZIP archive containing entri...

CVE-2026-93034

Oct 8, 2026 20:22:35 UTC

SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vu...

CVE-2026-66087

Oct 8, 2026 20:21:27 UTC

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the  * /dolphinscheduler/projects/{projectCode}/task-instance...

CVE-2026-66084

Oct 8, 2026 20:20:39 UTC

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}...

CVE-2026-66082

Oct 8, 2026 20:19:54 UTC

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, workflow definitions, and task instances in other projects. The affected endpoints chec...

CVE-2026-95209

Oct 8, 2026 20:18:43 UTC

An issue in gnutls v3.8.13 causes legitimate CA certificates to be rejected, leading to a Denial of Service (DoS).

CVE-2026-95184

Oct 8, 2026 20:17:56 UTC

Improper certificate validation in gnutls v3.8.13 causes the application to reject legitimate certificates for valid users, leading to a Denial of Service (DoS).

CVE-2026-15816

Oct 8, 2026 20:17:12 UTC

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_P...

CVE-2026-95208

Oct 8, 2026 20:16:24 UTC

An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via providing crafted Certificate Authority certificates, leading to valid certificates...