Vulnerabilities

Recent vulnerabilities

Recent vulnerabilities from
Select from 81 available sources using the dropdown above.

CSAF Microsoft 🪟

Recent vulnerabilities · 21213 entries
ID Description Published Updated
msrc_cve-2026-95520 Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages 2026-10-03T01:55:03.000Z 2026-10-03T01:55:03.000Z
msrc_cve-2026-103242 Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag 2026-10-03T01:54:38.000Z 2026-10-03T01:54:38.000Z
msrc_cve-2026-94640 Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service 2026-10-03T01:54:13.000Z 2026-10-03T01:54:13.000Z
msrc_cve-2026-67229 RabbitMQ: Admin-only atom exhaustion: atomize_keys on vhost metadata 2026-10-03T01:53:41.000Z 2026-10-03T01:53:41.000Z
msrc_cve-2026-66070 RabbitMQ: CORS * reflects Origin with Allow-Credentials 2026-10-03T01:53:23.000Z 2026-10-03T01:53:23.000Z
msrc_cve-2026-67235 RabbitMQ: AMQP 0-9-1 body assembly never validates accumulated size 2026-10-03T01:52:57.000Z 2026-10-03T01:52:57.000Z
msrc_cve-2026-67232 RabbitMQ: Web-MQTT decompression bomb 2026-10-03T01:52:31.000Z 2026-10-03T01:52:31.000Z
msrc_cve-2026-66077 RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI 2026-10-03T01:52:02.000Z 2026-10-03T01:52:02.000Z
msrc_cve-2026-67225 RabbitMQ: Stream-protocol frame length never validated against frame_max 2026-10-03T01:51:36.000Z 2026-10-03T01:51:36.000Z
msrc_cve-2026-66072 RabbitMQ: Atom table exhaustion via stream `chunk_selector` 2026-10-03T01:51:18.000Z 2026-10-03T01:51:18.000Z
msrc_cve-2026-66074 RabbitMQ: ReDoS via management API ?name= filter 2026-10-03T01:50:58.000Z 2026-10-03T01:50:58.000Z
msrc_cve-2026-67233 RabbitMQ: Monitoring-tag user can DELETE shovels 2026-10-03T01:50:40.000Z 2026-10-03T01:50:40.000Z
msrc_cve-2026-67228 RabbitMQ: Atom exhaustion: to_atom on runtime-parameter component 2026-10-03T01:50:22.000Z 2026-10-03T01:50:22.000Z
msrc_cve-2026-66069 RabbitMQ: Monitoring-tag DELETE of auth-attempt metrics 2026-10-03T01:50:04.000Z 2026-10-03T01:50:04.000Z
msrc_cve-2026-66068 RabbitMQ: Shovel DEBUG log of full state exposes decrypted URIs 2026-10-03T01:49:45.000Z 2026-10-03T01:49:45.000Z
msrc_cve-2026-67406 RabbitMQ: Federation and Shovel Gen-Servers Lack format_status Callback — Plaintext Credentials Exposed in Crash Dumps and sys:get_status 2026-10-03T01:49:25.000Z 2026-10-03T01:49:25.000Z
msrc_cve-2026-67226 RabbitMQ: Admin-only atom exhaustion: PUT /api/users tags list 2026-10-03T01:49:06.000Z 2026-10-03T01:49:06.000Z
msrc_cve-2026-66067 RabbitMQ: Stream protocol skips per vhost per user connection limits 2026-10-03T01:48:48.000Z 2026-10-03T01:48:48.000Z
msrc_cve-2026-67219 RabbitMQ: Consistent-hash exchange unbounded weight 2026-10-03T01:48:30.000Z 2026-10-03T01:48:30.000Z
msrc_cve-2026-67239 RabbitMQ: Stored XSS via TLS peer-certificate DN in stream-management UI 2026-10-03T01:48:13.000Z 2026-10-03T01:48:13.000Z
msrc_cve-2026-66075 RabbitMQ: Monitoring-tag user can restart federation links 2026-10-03T01:47:46.000Z 2026-10-03T01:47:46.000Z
msrc_cve-2026-67222 RabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_client 2026-10-03T01:47:28.000Z 2026-10-03T01:47:28.000Z
msrc_cve-2026-67405 RabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation) 2026-10-03T01:47:09.000Z 2026-10-03T01:47:09.000Z
msrc_cve-2026-66079 RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS 2026-10-03T01:46:50.000Z 2026-10-03T01:46:50.000Z
msrc_cve-2026-67415 RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Service 2026-10-03T01:45:42.000Z 2026-10-03T01:45:42.000Z
msrc_cve-2026-67221 RabbitMQ: AMQP 1.0 shovel status exposes plaintext URI passwords 2026-10-03T01:45:23.000Z 2026-10-03T01:45:23.000Z
msrc_cve-2026-15390 Out-of-bounds write in Das U-Boot 2026-10-03T01:45:05.000Z 2026-10-03T01:45:05.000Z
msrc_cve-2026-71972 U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 Decoder 2026-10-03T01:44:38.000Z 2026-10-03T01:44:38.000Z
msrc_cve-2026-71973 U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Directory Table Allocation 2026-10-03T01:44:13.000Z 2026-10-03T01:44:13.000Z
msrc_cve-2026-71971 U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly 2026-10-03T01:43:48.000Z 2026-10-03T01:43:48.000Z