Vulnerabilities

Summary — last 7 days

New vulnerabilities3,332▲ 359 vs. last week
Critical / high1,490▲ 132 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
–

5,544 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisHigh (7.1)0.10%—PackagekitAIFedoraproject Dnf5AI9/14/20269/18/2026
A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is…
Awaiting AnalysisMedium (5.5)0.16%—Fedora DNFAISuse ZypperAIRedhat YUMAIOpensuse LibsolvAI8/28/20268/28/2026
A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the…
AnalyzedHigh (7.1)0.13%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux8/4/20268/31/2026
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process…
AnalyzedLow (3.3)0.13%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux8/4/20268/31/2026
A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached…
AnalyzedMedium (5.5)0.13%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux8/3/20268/31/2026
A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash,…
Undergoing AnalysisMedium (6.4)0.12%—Fedoraproject SssdRedhat Enterprise Linux6/30/20268/31/2026
A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts…
ModifiedMedium (5.5)0.19%—Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux6/13/20269/21/2026
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject…
ModifiedHigh (7.8)0.23%—Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux6/13/20269/21/2026
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the…
AnalyzedMedium (5.5)0.15%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux4/15/20269/1/2026
A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit termination, it results in an out-of-bounds read…
AnalyzedMedium (5.5)0.17%—Freedesktop LibinputFedoraproject Fedora4/1/20266/17/2026
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose…
ModifiedHigh (8.8)0.21%—Freedesktop LibinputFedoraproject Fedora4/1/20267/15/2026
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical…
AnalyzedMedium (6.1)0.27%—Fedoralovespython Lxml Html Clean3/5/20266/17/2026
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, head, and title tags, there is no specific handling for <base>, allowing an attacker to inject…
AnalyzedMedium (6.1)0.28%—Fedoralovespython Lxml Html Clean3/5/20266/17/2026
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This causes CSS Unicode escape sequences to bypass the @import and expression() filters, allowing…
DeferredHigh (7.7)0.24%—Fedora LinuxAILinux KernelAI2/18/20266/17/2026
The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode disabled without any warning. This may allow an attacker to gain access to sensitive information such kernel memory mappings, I/O ports, BPF and kprobes. Additionally unsigned modules can be loaded,…
DeferredMedium (4.1)0.08%—Fedora ShimAI8/14/20256/17/2026
The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded.
DeferredLow (2.1)0.18%—ZincatiAIFedora CoreosAIProjectatomic Rpm-ostreeAI3/17/20256/17/2026
Zincati is an auto-update agent for Fedora CoreOS hosts. Zincati ships a polkit rule which allows the `zincati` system user to use the actions `org.projectatomic.rpmostree1.deploy` to deploy updates to the system and `org.projectatomic.rpmostree1.finalize-deployment` to reboot the system into the deployed update.…
AnalyzedHigh (8.7)0.43%—Fedorarepository Fcrepo1/23/20256/17/2026
Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).
AnalyzedHigh (8.7)0.74%—Fedorarepository Fcrepo1/23/20256/17/2026
Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted archive that will extract an arbitrary JSP file to a location that can be executed by an unauthenticated GET request. Fedora Repository 3.8.1 was released on…
AnalyzedMedium (6.1)0.48%—Fedoralovespython Lxml Html Clean11/19/20246/17/2026
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, the HTML Parser in lxml does not properly handle context-switching for special HTML tags such as `<svg>`, `<math>` and `<noscript>`. This behavior deviates from how web browsers parse and interpret…
AnalyzedMedium (5.5)0.20%—Linux KernelFedoraproject Fedora11/14/20246/17/2026
A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device cleanup routine due to a possible rearming of the watchdog_timer from the workqueue. This could allow a local user to crash the system, causing a denial of service.
ModifiedMedium (4.8)0.55%—Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora8/2/20246/17/2026
A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious container will continue to exhaust resources until it is…
AnalyzedHigh (8.8)0.62%—Google ChromeFedoraproject Fedora6/24/20246/17/2026
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalyzedHigh (8.8)0.61%—Google ChromeFedoraproject Fedora6/24/20246/17/2026
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalyzedHigh (8.8)0.66%—Google ChromeFedoraproject Fedora6/24/20246/17/2026
Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalyzedHigh (8.8)0.62%—Google ChromeFedoraproject Fedora6/24/20246/17/2026
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)