VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2026-63495High· 7.5PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenti…

▾ Midnightlibevent · libeventEPSS 0.61%via NVD
CVE-2026-63388High· 8.4
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into buffer…

▾ Twilightlibevent · libeventEPSS 0.20%via NVD
CVE-2026-63387High· 7.0PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocat…

▾ Midnightlibevent · libeventEPSS 0.45%via NVD
CVE-2026-63379Medium· 6.3
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces evhttp_parse_headers_impl…

▾ Sunlitlibevent · libeventEPSS 0.71%via NVD
CVE-2026-73253Critical· 9.1
1mo ago

Mongoose is an embedded web server and network library

Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg…

▾ MidnightRed HatEPSS 0.35%via NVD
CVE-2026-63385High· 7.7
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause dow…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 8)EPSS 0.55%via NVD
CVE-2026-63384High· 7.5
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload…

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.52%via NVD
CVE-2026-63381Medium· 6.6
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains fre…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.16%via NVD
CVE-2026-63380Medium· 4.7
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. ev…

▾ SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.14%via NVD
CVE-2026-76957Medium· 4.9
1mo ago

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

▾ Sunlitlibexpat_project · libexpatEPSS 0.15%via NVD
CVE-2026-76956Medium· 5.9
1mo ago

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

▾ Sunlitlibexpat_project · libexpatEPSS 0.45%via NVD
CVE-2026-13097High· 8.7
1mo ago

A privilege escalation flaw was found in FreeIPA

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name…

▾ Twilightfreeipa · freeipaEPSS 0.40%via NVD
CVE-2026-71492Medium· 6.5
1mo ago

Banks generates meaningful LLM prompts using a simple template language

Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values in…

▾ Sunlitbanks · banksEPSS 0.47%via NVD
CVE-2026-54770Medium· 6.1
1mo ago

WebOb provides objects for HTTP requests and responses

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips le…

▾ SunlitRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.38%via NVD
CVE-2026-49825High· 8.2
1mo ago

lxml is a library for processing XML and HTML in the Python language

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. cont…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.43%via NVD
CVE-2026-43961High· 7.8
1mo ago

A flaw was found in Vim's netrw plugin

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be levera…

▾ Twilightvim · vimEPSS 0.22%via NVD
CVE-2026-55194Critical· 9.8PoC
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint …

▾ Abyssalfreerdp · freerdpEPSS 0.62%via NVD
CVE-2026-75593High· 7.2
1mo ago

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from …

▾ Twilightmoby · buildkitEPSS 0.72%via NVD
CVE-2026-20318Critical· 9.6
1mo ago

Cisco Secure Workload Software Security Hardening Release August 2026 - Input Validation Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that ad…

▾ MidnightCisco · Cisco Secure WorkloadEPSS 0.44%via CSAF
CVE-2026-20317Critical· 10.0
1mo ago

Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that ad…

▾ MidnightCisco · Cisco Secure WorkloadEPSS 0.56%via CSAF
CVE-2026-20315Critical· 10.0
1mo ago

Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that ad…

▾ MidnightCisco · Cisco Secure WorkloadEPSS 0.49%via CSAF
CVE-2026-20231Critical· 9.9
1mo ago

Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutralization of Special Elements Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that ad…

▾ MidnightCisco · Cisco Secure WorkloadEPSS 0.53%via CSAF
CVE-2026-63652Medium· 6.5
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing t…

▾ Sunlitfreerdp · freerdpEPSS 0.58%via NVD
CVE-2026-63633Critical· 9.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM…

▾ Midnightfreerdp · freerdpEPSS 0.62%via NVD
CVE-2026-55564Medium· 5.4
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whether index is greater than cache->number instead of greater than or equal to it. A malic…

▾ Sunlitfreerdp · freerdpEPSS 0.44%via NVD
CVE-2026-55193High· 8.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte …

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.47%via NVD
CVE-2026-55192High· 8.2
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 decoder backends can return YUV planes sized from the bitstream without comparing the decoded width and height to the RDPGFX surface dimensio…

▾ Twilightfreerdp · freerdpEPSS 0.59%via NVD
CVE-2026-55191Critical· 9.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c wit…

▾ Midnightfreerdp · freerdpEPSS 0.83%via NVD
CVE-2026-76232Medium· 6.7
1mo ago

Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login commands without proper sanitization

Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login commands without proper sanitization. Attackers with reposito…

▾ SunlitRed HatEPSS 1.0%via NVD
CVE-2026-76230Medium· 6.7
1mo ago

Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands without proper sanitization

Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands without proper sanitization. Attackers with repository…

▾ SunlitRed HatEPSS 1.0%via NVD
CVEs tagged “csaf” — page 64 · VulnSea