Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.0
CVE-2026-6387
A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary…
No fix yet
HIGH 8.8
CVE-2026-68454
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: pci: Fix handling of AIF enable without AISB
When a guest seeks to r…
No fix yet
HIGH 7.1
CVE-2026-68453
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
Add validation of both …
No fix yet
HIGH 7.8
CVE-2026-68452
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: Validate length for CCA AES cipher key requests
cca_cipher2protkey…
No fix yet
HIGH 7.8
CVE-2026-68451
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: Validate length for CCA ECC private key requests
cca_ecc2protkey()…
No fix yet
HIGH 7.2
CVE-2026-66256
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig.
This issue affects Apache Shindig: all versions.
…
No fix yet
MEDIUM 5.3
CVE-2026-65936
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information.
See vulnerability B-E4 in …
No fix yet
HIGH 7.6
CVE-2026-65935
Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.
See vulnerability B-E3…
No fix yet
HIGH 7.1
CVE-2026-65934
An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module.
See vulnerability B-E10 in the related paper below.
No fix yet
MEDIUM 5.3
CVE-2026-65933
A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related…
No fix yet
MEDIUM 5.3
CVE-2026-65932
The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerabili…
No fix yet
HIGH 7.1
CVE-2026-63426
During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user …
No fix yet
HIGH 7.8
CVE-2026-63425
During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local…
No fix yet
HIGH 7.3
CVE-2026-63424
During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user…
No fix yet
HIGH 7.8
CVE-2026-63423
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows…
No fix yet
HIGH 7.8
CVE-2026-53803
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a pred…
No fix yet
HIGH 7.1
CVE-2026-53802
rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploi…
No fix yet
MEDIUM 5.9
CVE-2026-53801
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender…
No fix yet
MEDIUM 6.3
CVE-2026-53799
rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended att…
No fix yet
MEDIUM 5.3
CVE-2026-53798
rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause…
No fix yet
MEDIUM 6.3
CVE-2026-53796
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory h…
No fix yet
HIGH 8.1
CVE-2026-53795
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by speci…
No fix yet
MEDIUM 5.3
CVE-2026-53794
rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation s…
No fix yet
HIGH 7.4
CVE-2026-53793
rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement b…
No fix yet
MEDIUM 6.5
CVE-2026-53792
rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger m…
No fix yet
CRITICAL 9.1
CVE-2026-53791
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access contro…
No fix yet
HIGH 8.1
CVE-2026-53790
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying m…
No fix yet
MEDIUM 6.5
CVE-2026-53789
rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond …
No fix yet
MEDIUM 6.5
CVE-2026-53788
rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge pr…
No fix yet
MEDIUM 6.5
CVE-2026-53786
rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supp…
No fix yet