VulnSea

CWE-1288

CVEs classified under CWE-1288, newest first.

12 CVEsRSS

CVE-2026-89584High· 7.0⚖ disputed
1w ago

kernel: block: validate user space vectors during extraction (CVE-2026-89584)

A flaw was found in the Linux kernel's block layer. This vulnerability arises from insufficient validation of user-space data structures (vectors) against the device's Direct Memory Access (DMA) alignment requirements. A local attacker cou…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.15%via CSAF
CVE-2026-69793High· 7.5
2w ago

Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network.

Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.79%via NVD
CVE-2026-18238Medium· 5.0
2w ago

The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers

The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process…

SunlitThe Tcpdump Group · libpcapEPSS 0.18%via NVD
CVE-2026-73219None
1mo ago

CVAT is an open source interactive video and image annotation tool for computer vision

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with write access to a CVAT job can submit a batch automatic annotation request to RequestViewSet.create with incons…

SunlitEPSS 0.34%via NVD
CVE-2026-18209Low· 3.4
1mo ago

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query p…

Sunlitredhat · build_of_keycloakEPSS 0.23%via NVD
CVE-2026-15943Medium· 5.5
2mo ago

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel val…

Sunlitredhat · build_of_keycloakEPSS 0.34%via NVD
CVE-2026-42982High· 7.8
2mo ago

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-46117High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() Sashiko points out that the user can specify WQs sharing the same CQ as a part of the uAPI and …

In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() Sashiko points out that the user can specify WQs sharing the same CQ as a part of the uAPI and …

Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-9689Medium· 4.2
3mo ago

A flaw was found in Keycloak, an open-source identity and access management solution

A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authenticati…

Sunlitredhat · build_of_keycloakEPSS 0.32%via NVD
CVE-2026-43001High· 8.0
4mo ago

OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation (CVE-2026-4…

A flaw was found in OpenStack Keystone. An attacker holding an unrestricted application credential could exploit a vulnerability in the POST /v3/credentials endpoint where the caller-supplied project_id for an EC2-type credential was not v…

TwilightRed Hat · Red Hat OpenStack Platform 17.1EPSS 0.47%via CSAF
CVE-2026-31488High· 7.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not skip unrelated mode changes in DSC validation Starting with commit 17ce8a6907f7 ("drm/amd/display: Add dsc pre-validation in atomic check"), am…

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not skip unrelated mode changes in DSC validation Starting with commit 17ce8a6907f7 ("drm/amd/display: Add dsc pre-validation in atomic check"), am…

Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-31431High· 7.8CISA KEVPoC
5mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…

Abyssalredhat · openshift_container_platformEPSS 100%via NVD
CWE-1288 vulnerabilities (CVEs) · VulnSea