Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
| ID | Description | Published | Updated |
|---|---|---|---|
| msrc_cve-2026-95520 | Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages | 2026-10-03T01:55:03.000Z | 2026-10-03T01:55:03.000Z |
| msrc_cve-2026-103242 | Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag | 2026-10-03T01:54:38.000Z | 2026-10-03T01:54:38.000Z |
| msrc_cve-2026-94640 | Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service | 2026-10-03T01:54:13.000Z | 2026-10-03T01:54:13.000Z |
| msrc_cve-2026-67229 | RabbitMQ: Admin-only atom exhaustion: atomize_keys on vhost metadata | 2026-10-03T01:53:41.000Z | 2026-10-03T01:53:41.000Z |
| msrc_cve-2026-66070 | RabbitMQ: CORS * reflects Origin with Allow-Credentials | 2026-10-03T01:53:23.000Z | 2026-10-03T01:53:23.000Z |
| msrc_cve-2026-67235 | RabbitMQ: AMQP 0-9-1 body assembly never validates accumulated size | 2026-10-03T01:52:57.000Z | 2026-10-03T01:52:57.000Z |
| msrc_cve-2026-67232 | RabbitMQ: Web-MQTT decompression bomb | 2026-10-03T01:52:31.000Z | 2026-10-03T01:52:31.000Z |
| msrc_cve-2026-66077 | RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI | 2026-10-03T01:52:02.000Z | 2026-10-03T01:52:02.000Z |
| msrc_cve-2026-67225 | RabbitMQ: Stream-protocol frame length never validated against frame_max | 2026-10-03T01:51:36.000Z | 2026-10-03T01:51:36.000Z |
| msrc_cve-2026-66072 | RabbitMQ: Atom table exhaustion via stream `chunk_selector` | 2026-10-03T01:51:18.000Z | 2026-10-03T01:51:18.000Z |
| msrc_cve-2026-66074 | RabbitMQ: ReDoS via management API ?name= filter | 2026-10-03T01:50:58.000Z | 2026-10-03T01:50:58.000Z |
| msrc_cve-2026-67233 | RabbitMQ: Monitoring-tag user can DELETE shovels | 2026-10-03T01:50:40.000Z | 2026-10-03T01:50:40.000Z |
| msrc_cve-2026-67228 | RabbitMQ: Atom exhaustion: to_atom on runtime-parameter component | 2026-10-03T01:50:22.000Z | 2026-10-03T01:50:22.000Z |
| msrc_cve-2026-66069 | RabbitMQ: Monitoring-tag DELETE of auth-attempt metrics | 2026-10-03T01:50:04.000Z | 2026-10-03T01:50:04.000Z |
| msrc_cve-2026-66068 | RabbitMQ: Shovel DEBUG log of full state exposes decrypted URIs | 2026-10-03T01:49:45.000Z | 2026-10-03T01:49:45.000Z |
| msrc_cve-2026-67406 | RabbitMQ: Federation and Shovel Gen-Servers Lack format_status Callback — Plaintext Credentials Exposed in Crash Dumps and sys:get_status | 2026-10-03T01:49:25.000Z | 2026-10-03T01:49:25.000Z |
| msrc_cve-2026-67226 | RabbitMQ: Admin-only atom exhaustion: PUT /api/users tags list | 2026-10-03T01:49:06.000Z | 2026-10-03T01:49:06.000Z |
| msrc_cve-2026-66067 | RabbitMQ: Stream protocol skips per vhost per user connection limits | 2026-10-03T01:48:48.000Z | 2026-10-03T01:48:48.000Z |
| msrc_cve-2026-67219 | RabbitMQ: Consistent-hash exchange unbounded weight | 2026-10-03T01:48:30.000Z | 2026-10-03T01:48:30.000Z |
| msrc_cve-2026-67239 | RabbitMQ: Stored XSS via TLS peer-certificate DN in stream-management UI | 2026-10-03T01:48:13.000Z | 2026-10-03T01:48:13.000Z |
| msrc_cve-2026-66075 | RabbitMQ: Monitoring-tag user can restart federation links | 2026-10-03T01:47:46.000Z | 2026-10-03T01:47:46.000Z |
| msrc_cve-2026-67222 | RabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_client | 2026-10-03T01:47:28.000Z | 2026-10-03T01:47:28.000Z |
| msrc_cve-2026-67405 | RabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation) | 2026-10-03T01:47:09.000Z | 2026-10-03T01:47:09.000Z |
| msrc_cve-2026-66079 | RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS | 2026-10-03T01:46:50.000Z | 2026-10-03T01:46:50.000Z |
| msrc_cve-2026-67415 | RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Service | 2026-10-03T01:45:42.000Z | 2026-10-03T01:45:42.000Z |
| msrc_cve-2026-67221 | RabbitMQ: AMQP 1.0 shovel status exposes plaintext URI passwords | 2026-10-03T01:45:23.000Z | 2026-10-03T01:45:23.000Z |
| msrc_cve-2026-15390 | Out-of-bounds write in Das U-Boot | 2026-10-03T01:45:05.000Z | 2026-10-03T01:45:05.000Z |
| msrc_cve-2026-71972 | U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 Decoder | 2026-10-03T01:44:38.000Z | 2026-10-03T01:44:38.000Z |
| msrc_cve-2026-71973 | U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Directory Table Allocation | 2026-10-03T01:44:13.000Z | 2026-10-03T01:44:13.000Z |
| msrc_cve-2026-71971 | U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly | 2026-10-03T01:43:48.000Z | 2026-10-03T01:43:48.000Z |