Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.0 CVE-2026-6387 A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-68454 In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to r… No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-68453 In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both … No fix yet Fix from $4,9002026-08-13 HIGH 7.8 CVE-2026-68452 In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key requests cca_cipher2protkey… No fix yet Fix from $4,9002026-08-13 HIGH 7.8 CVE-2026-68451 In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA ECC private key requests cca_ecc2protkey()… No fix yet Fix from $4,9002026-08-13 HIGH 7.2 CVE-2026-66256 ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. … No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-65936 A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information.  See vulnerability B-E4 in … No fix yet Fix from $4,0002026-08-13 HIGH 7.6 CVE-2026-65935 Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.  See vulnerability B-E3… No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-65934 An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module.  See vulnerability B-E10 in the related paper below. No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-65933 A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-65932 The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerabili… No fix yet Fix from $4,0002026-08-13 HIGH 7.1 CVE-2026-63426 During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user … No fix yet Fix from $4,9002026-08-13 HIGH 7.8 CVE-2026-63425 During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local… No fix yet Fix from $4,9002026-08-13 HIGH 7.3 CVE-2026-63424 During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user… No fix yet Fix from $4,9002026-08-13 HIGH 7.8 CVE-2026-63423 During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows… No fix yet Fix from $4,9002026-08-13 HIGH 7.8 CVE-2026-53803 rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a pred… No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-53802 rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploi… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.9 CVE-2026-53801 rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-53799 rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended att… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-53798 rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-53796 rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory h… No fix yet Fix from $4,0002026-08-13 HIGH 8.1 CVE-2026-53795 rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by speci… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-53794 rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation s… No fix yet Fix from $4,0002026-08-13 HIGH 7.4 CVE-2026-53793 rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement b… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-53792 rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger m… No fix yet Fix from $4,0002026-08-13 CRITICAL 9.1 CVE-2026-53791 rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access contro… No fix yet Fix from $5,7502026-08-13 HIGH 8.1 CVE-2026-53790 rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying m… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-53789 rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond … No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-53788 rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge pr… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-53786 rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supp… No fix yet Fix from $4,0002026-08-13