Vulnerabilities (CVE)

Total 400172 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-19153 1 Google 1 Chrome 2026-08-07 N/A 8.1 HIGH
Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CVE-2026-63136 1 Elastic 1 Elasticsearch 2026-08-07 N/A 6.5 MEDIUM
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this vulnerability to cause cluster downtime requiring manual intervention to restore service.
CVE-2026-63140 1 Elastic 1 Elasticsearch 2026-08-07 N/A 6.5 MEDIUM
Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as fatal errors, this terminates the affected node process. A low-privileged authenticated user with read access to at least one index can exploit this condition with a single request to cause a node to terminate, disrupting search availability. In a single-node deployment this fully stops Elasticsearch; in a multi-node cluster it reduces cluster capacity for each affected node.
CVE-2026-67261 1 Dell 1 Virtual Storage Integrator 2026-08-07 N/A 9.8 CRITICAL
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity.
CVE-2026-54489 1 Dell 1 Virtual Storage Integrator 2026-08-07 N/A 9.1 CRITICAL
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.
CVE-2024-1086 5 Debian, Fedoraproject, Linux and 2 more 27 Debian Linux, Fedora, Linux Kernel and 24 more 2026-08-07 N/A 7.8 HIGH
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.
CVE-2026-34502 1 Apache 1 Apr-util 2026-08-07 N/A 7.5 HIGH
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
CVE-2026-34501 1 Apache 1 Apr-util 2026-08-07 N/A 7.5 HIGH
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
CVE-2026-34191 1 Apache 1 Apr-util 2026-08-07 N/A 9.1 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
CVE-2026-32327 1 Apache 1 Apr-util 2026-08-07 N/A 9.1 CRITICAL
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses theĀ apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-67592 1 Apache 1 Qpid Protonj2 2026-08-07 N/A 7.5 HIGH
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue
CVE-2026-67591 1 Apache 1 Qpid Protonj2 2026-08-07 N/A 6.5 MEDIUM
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
CVE-2026-24253 2 Linux, Nvidia 2 Linux Kernel, Dynamo 2026-08-07 N/A 8.2 HIGH
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CVE-2026-24254 2 Linux, Nvidia 2 Linux Kernel, Dynamo 2026-08-07 N/A 9.8 CRITICAL
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
CVE-2026-24255 2 Linux, Nvidia 2 Linux Kernel, Dynamo 2026-08-07 N/A 7.5 HIGH
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.
CVE-2026-47612 2 Linux, Nvidia 2 Linux Kernel, Dynamo 2026-08-07 N/A 7.5 HIGH
NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-56160 1 Microsoft 1 Azure Red Hat Openshift 2026-08-07 N/A 9.1 CRITICAL
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
CVE-2026-47613 2 Linux, Nvidia 2 Linux Kernel, Dynamo 2026-08-07 N/A 7.5 HIGH
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-62825 1 Microsoft 1 Azure Key Vault 2026-08-07 N/A 10.0 CRITICAL
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50481 1 Microsoft 1 Azure Active Directory 2026-08-07 N/A 9.9 CRITICAL
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.