| CVE-2026-13070 |
2026-07-22 |
A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabl… |
| CVE-2026-13065 |
2026-07-22 |
A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate… |
| CVE-2026-55717 |
2026-07-22 |
In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-… |
| CVE-2026-47709 |
2026-07-21 |
libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF image item ha… |
| CVE-2026-10678 |
2026-07-21 |
The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writes from an I2C bus master byte-by-byte in mctp_i2c_gpio_target_write_received() … |
| CVE-2026-47143 |
2026-07-21 |
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds … |
| CVE-2026-16353 |
2026-07-21 |
Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-47276 |
2026-07-20 |
In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attacker to crash the NanoMQ broker by sending a POST request to `/api/v4/mqtt/publis… |
| CVE-2026-47275 |
2026-07-20 |
In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicious MQTT broker to crash any connecting NanoMQ MQTTv5 client (including bridge mo… |
| CVE-2026-63762 |
2026-07-20 |
SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript scripting engine, which is enabled via the --allow-scripting capability (disabl… |
| CVE-2026-62309 |
2026-07-16 |
CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go Pa… |
| CVE-2026-62299 |
2026-07-16 |
CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two response rules, edns0SetResponseRule and edns0Repl… |
| CVE-2026-15352 |
2026-07-16 |
A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeepin… |
| CVE-2026-52865 |
2026-07-15 |
When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the N… |
| CVE-2025-56363 |
2026-07-14 |
A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, Target… |
| CVE-2026-56168 |
2026-07-14 |
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. |
| CVE-2026-50673 |
2026-07-14 |
Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2026-50366 |
2026-07-14 |
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. |
| CVE-2026-50315 |
2026-07-14 |
Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. |
| CVE-2026-57976 |
2026-07-14 |
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. |