CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-42007
9.1 CRITICAL

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and …

Aug 28, 2026
CVE-2026-40205
5.9 MEDIUM

An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in …

Aug 28, 2026
CVE-2026-40204
3.1 LOW

None None None No publicly available exploits are known.

Aug 28, 2026
CVE-2026-40203
3.7 LOW

When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and …

Aug 28, 2026
CVE-2026-40019
5.9 MEDIUM

An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This …

Aug 28, 2026
CVE-2026-40018
7.4 HIGH

None None None No publicly available exploits are known.

Aug 28, 2026
CVE-2026-40017
6.5 MEDIUM

An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, …

Aug 28, 2026
CVE-2026-40015
4.3 MEDIUM

An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read …

Aug 28, 2026
CVE-2026-40014
6.5 MEDIUM

An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the …

Aug 28, 2026
CVE-2026-40013
4.3 MEDIUM

An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service …

Aug 28, 2026
CVE-2026-33607
4.3 MEDIUM

An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor …

Aug 28, 2026
CVE-2026-33606
4.8 MEDIUM

Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with …

Aug 28, 2026
CVE-2026-33605
7.5 HIGH

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community …

Aug 28, 2026
CVE-2026-33604
5.9 MEDIUM

An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafted line ending in …

Aug 28, 2026
CVE-2026-33263
4.3 MEDIUM

When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode …

Aug 28, 2026
CVE-2026-27852
7.5 HIGH

An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME …

Aug 28, 2026
CVE-2026-18918

In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those …

Aug 28, 2026
CVE-2026-18393
5.4 MEDIUM

A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote …

Aug 28, 2026
CVE-2026-9548
6.5 MEDIUM

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, …

Aug 28, 2026
CVE-2026-9491
4.3 MEDIUM

A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information.

Aug 28, 2026
CVE-2026-82123
6.5 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & Logic.

Aug 28, 2026
CVE-2026-80724
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming writable vmclock_miscdev_mmap() rejects writable mappings of the shared …

Aug 28, 2026
CVE-2026-80723
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: of: reserved_mem: prevent OOB when too many dynamic regions are defined On boot, fdt_scan_reserved_mem() saves …

Aug 28, 2026
CVE-2026-80722
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params before driver setup ieee80211_process_rx_twt_action() only partially validates a received …

Aug 28, 2026
CVE-2026-80721
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon references in iso_conn After iso_conn_del(), ISO sockets should not …

Aug 28, 2026
CVE-2026-80720
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: iomap: add a separate bio_set for iomap_split_ioend iomap_split_ioend can split bios that already come from …

Aug 28, 2026
CVE-2026-80719

In the Linux kernel, the following vulnerability has been resolved: mm: mglru: fix stale batch updates after memcg reparenting The mglru page table walker batches …

Aug 28, 2026
CVE-2026-80718
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() In pcpu_create_chunk(), nr_pages is the total contiguous …

Aug 28, 2026
CVE-2026-80717
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: sctp: validate Adaptation Indication parameter length The Adaptation Layer Indication parameter contains a fixed 32-bit …

Aug 28, 2026
CVE-2026-80716
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: wake linked drain waiters on unlink snd_pcm_drain() on a linked stream parks an …

Aug 28, 2026
CVE-2026-80715

In the Linux kernel, the following vulnerability has been resolved: igc: remove napi_synchronize() in igc_down() When an AF_XDP zero-copy application is killed abruptly, the XSK …

Aug 28, 2026
CVE-2026-80714
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before …

Aug 28, 2026
CVE-2026-80713
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: io_uring: preserve task restrictions across exec Per-task restrictions apply to all rings created by a …

Aug 28, 2026
CVE-2026-80712
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: write the feature value before executing SET_FEATURE qcom_spi_send_cmdaddr() programs NAND_FLASH_CMD/NAND_EXEC_CMD and submits the …

Aug 28, 2026
CVE-2026-80711

In the Linux kernel, the following vulnerability has been resolved: power: supply: max17040: handle missing status supplier MAX17040 does not report charger state itself, so …

Aug 28, 2026
CVE-2026-80710
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Fix undersized format-check buffer fmt_buffer_size in dasd_eckd_check_device_format() is declared as int, even though one …

Aug 28, 2026
CVE-2026-80709
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs There is a wrong upper limit …

Aug 28, 2026
CVE-2026-80708

In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() The helper function _ip_cprb_helper() …

Aug 28, 2026
CVE-2026-80707
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer Zero the allocated buffer in j1939_session_fresh_new() to ensure …

Aug 28, 2026
CVE-2026-80706
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: can: softing: fw_parse(): validate firmware record spans fw_parse() reads a fixed record header, a firmware-provided …

Aug 28, 2026
CVE-2026-80705

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check if dml21_add_phantom_plane() is successful Verify that the phantom plane was allocated to avoid …

Aug 28, 2026
CVE-2026-80704

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: use proper context for logging The same as the rest of the code, get_ss_info_from_atombios() …

Aug 28, 2026
CVE-2026-80703

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE Prevent unauthorized termination of active GPU debug sessions. …

Aug 28, 2026
CVE-2026-80702
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size Two sites in vmwgfx_resource.c assign boolean literals to …

Aug 28, 2026
CVE-2026-80701

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: enforce cursor size limits for MOB cursors vmw_cursor_plane_atomic_check() bounds cursor width and height only …

Aug 28, 2026
CVE-2026-80700
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate external BO copy bounds for both stride paths vmw_external_bo_copy() trusts caller-supplied offsets, strides, …

Aug 28, 2026
CVE-2026-80699

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context In the nested state, …

Aug 28, 2026
CVE-2026-80698

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix double free of wq, engine, and group structs The release callbacks for …

Aug 28, 2026
CVE-2026-80697

In the Linux kernel, the following vulnerability has been resolved: erofs: ensure valid f_path for page cache sharing Previously, backing files for page cache sharing …

Aug 28, 2026
CVE-2026-80696
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Fix reading the minimum alarm voltage Coverity reports an out-of-bounds access when reading …

Aug 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.