Common Vulnerabilities and Exposures (CVE)

CVE-2026-26103

Jul 15, 2026 01:15:26 UTC

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned ud...

CVE-2026-26130

Jul 15, 2026 01:15:21 UTC

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVE-2026-2614

Jul 15, 2026 01:15:19 UTC

A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue ar...

CVE-2026-26157

Jul 15, 2026 01:15:16 UTC

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directo...

CVE-2026-26158

Jul 15, 2026 01:15:14 UTC

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is ex...

CVE-2026-26171

Jul 15, 2026 01:15:11 UTC

Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.

CVE-2026-26200

Jul 15, 2026 01:15:09 UTC

HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially...

CVE-2026-26280

Jul 15, 2026 01:15:04 UTC

systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an attacker to execute arbitrary OS commands via an unsanitized net...

CVE-2026-26318

Jul 15, 2026 01:15:02 UTC

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

CVE-2026-26332

Jul 15, 2026 01:14:58 UTC

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.

CVE-2026-2635

Jul 15, 2026 01:14:56 UTC

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The ...

CVE-2026-26740

Jul 15, 2026 01:14:52 UTC

Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size.

CVE-2026-26955

Jul 15, 2026 01:14:49 UTC

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX Cl...

CVE-2026-26956

Jul 15, 2026 01:14:46 UTC

vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host coopera...

CVE-2026-26965

Jul 15, 2026 01:14:43 UTC

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE planar decode path, `planar_decompress_plane_rle()` writes into `pDstData` at `((nYDst+y) * nDstStep) + (4*nXDst) + nChannel` without verif...