Home / Security / CVE index / 2026
2026 NetApp CVEs
Showing 300 CVEs with a 2026 identifier — page 1 of 4. Sorted by CVE id.
Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 300 of 300
| CVE | Published | Severity | CVSS | Summary / Sources |
|---|---|---|---|---|
CVE-2026-0603 | 2026-01-23 | HIGH | 8.3 | A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, un NVD ↗ · NTAP-20260508-0018 |
CVE-2026-0636 | 2026-04-15 | MEDIUM | 6.5 | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (pr NVD ↗ · NTAP-20260917-0008 |
CVE-2026-0672 | — | — | — | NVD ↗ · NTAP-20260130-0007 |
CVE-2026-0846 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-0847 | 2026-03-04 | HIGH | 7.5 | A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCor NVD ↗ · NTAP-20260917-0001 |
CVE-2026-0848 | 2026-03-05 | CRITICAL | 10.0 | NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads NVD ↗ · NTAP-20260917-0001 |
CVE-2026-0861 | — | — | — | NVD ↗ · NTAP-20260320-0005 |
CVE-2026-0865 | — | — | — | NVD ↗ · NTAP-20260305-0014 |
CVE-2026-0915 | 2026-01-15 | HIGH | 7.5 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued netwo NVD ↗ · NTAP-20260313-0003 |
CVE-2026-0964 | 2026-03-26 | MEDIUM | 6.3 | A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused NVD ↗ · NTAP-20260501-0015 |
CVE-2026-0965 | 2026-03-26 | LOW | 3.3 | A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious NVD ↗ · NTAP-20260501-0015 |
CVE-2026-0966 | 2026-03-26 | HIGH | 8.2 | A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remo NVD ↗ · NTAP-20260501-0015 |
CVE-2026-0967 | 2026-03-26 | MEDIUM | 5.5 | A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processe NVD ↗ · NTAP-20260501-0015 |
CVE-2026-0968 | 2026-03-26 | LOW | 3.1 | A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH NVD ↗ · NTAP-20260501-0015 |
CVE-2026-0988 | — | — | — | NVD ↗ · NTAP-20260320-0004 |
CVE-2026-0990 | 2026-01-15 | MEDIUM | 5.9 | A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalo NVD ↗ · NTAP-20260220-0013 |
CVE-2026-0992 | — | — | — | NVD ↗ · NTAP-20260220-0012 |
CVE-2026-10109 | — | — | — | NVD ↗ · NTAP-20260626-0007 |
CVE-2026-10534 | — | — | — | NVD ↗ · NTAP-20260814-0007 |
CVE-2026-10535 | — | — | — | NVD ↗ · NTAP-20260717-0005 |
CVE-2026-10543 | — | — | — | NVD ↗ · NTAP-20260814-0008 |
CVE-2026-10649 | 2026-06-16 | HIGH | 8.6 | A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By NVD ↗ · NTAP-20260917-0003 |
CVE-2026-10695 | — | — | — | NVD ↗ · NTAP-20260717-0002 |
CVE-2026-10723 | — | — | — | NVD ↗ · NTAP-20260730-0002 |
CVE-2026-10822 | — | — | — | NVD ↗ · NTAP-20260730-0003 |
CVE-2026-10846 | — | — | — | NVD ↗ · NTAP-20260619-0016 |
CVE-2026-11331 | — | — | — | NVD ↗ · NTAP-20260730-0008 |
CVE-2026-11564 | — | — | — | NVD ↗ · NTAP-20260731-0005 |
CVE-2026-11605 | — | — | — | NVD ↗ · NTAP-20260730-0009 |
CVE-2026-11622 | — | — | — | NVD ↗ · NTAP-20260730-0007 |
CVE-2026-11721 | — | — | — | NVD ↗ · NTAP-20260730-0004 |
CVE-2026-11822 | 2026-06-09 | HIGH | 7.8 | SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exh NVD ↗ · NTAP-20260925-0015 |
CVE-2026-11824 | 2026-06-09 | HIGH | 7.8 | SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execut NVD ↗ · NTAP-20260925-0016 |
CVE-2026-11856 | — | — | — | NVD ↗ · NTAP-20260731-0002 |
CVE-2026-1188 | — | — | — | NVD ↗ · NTAP-20260410-0015 |
CVE-2026-11906 | — | — | — | NVD ↗ · NTAP-20260626-0010 |
CVE-2026-11972 | — | — | — | NVD ↗ · NTAP-20260903-0009 |
CVE-2026-1207 | — | — | — | NVD ↗ · NTAP-20260305-0001 |
CVE-2026-1225 | — | — | — | NVD ↗ · NTAP-20260305-0008 |
CVE-2026-1245 | — | — | — | NVD ↗ · NTAP-20260821-0002 |
CVE-2026-12617 | — | — | — | NVD ↗ · NTAP-20260730-0005 |
CVE-2026-1285 | — | — | — | NVD ↗ · NTAP-20260305-0001 |
CVE-2026-1287 | — | — | — | NVD ↗ · NTAP-20260305-0001 |
CVE-2026-1299 | — | — | — | NVD ↗ · NTAP-20260717-0014 |
CVE-2026-1312 | — | — | — | NVD ↗ · NTAP-20260305-0001 |
CVE-2026-13204 | — | — | — | NVD ↗ · NTAP-20260730-0006 |
CVE-2026-13321 | — | — | — | NVD ↗ · NTAP-20260730-0001 |
CVE-2026-1352 | — | — | — | NVD ↗ · NTAP-20260422-0014 |
CVE-2026-13757 | 2026-06-29 | MEDIUM | 6.2 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a NVD ↗ · NTAP-20261002-0019 |
CVE-2026-14164 | 2026-06-30 | HIGH | 7.5 | A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain sta NVD ↗ · NTAP-20260925-0023 |
CVE-2026-14266 | — | — | — | NVD ↗ · NTAP-20260724-0010 |
CVE-2026-14456 | — | — | — | NVD ↗ · NTAP-20260821-0003 |
CVE-2026-14457 | — | — | — | NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0003 |
CVE-2026-14742 | 2026-07-05 | LOW | 3.1 | A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_interna NVD ↗ · NTAP-20260917-0001 |
CVE-2026-1484 | — | — | — | NVD ↗ · NTAP-20260320-0003 |
CVE-2026-1485 | — | — | — | NVD ↗ · NTAP-20260320-0001 |
CVE-2026-1489 | — | — | — | NVD ↗ · NTAP-20260320-0002 |
CVE-2026-1519 | — | — | — | NVD ↗ · NTAP-20260403-0003 |
CVE-2026-15308 | — | — | — | NVD ↗ · NTAP-20260717-0016 |
CVE-2026-15370 | — | — | — | NVD ↗ · NTAP-20260807-0007 |
CVE-2026-15571 | — | — | — | NVD ↗ · NTAP-20260828-0007 |
CVE-2026-15588 | 2026-07-20 | MEDIUM | 5.3 | A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce NVD ↗ · NTAP-20260924-0030 |
CVE-2026-1561 | 2026-03-25 | MEDIUM | 5.4 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF NVD ↗ · NTAP-20260917-0001 |
CVE-2026-1577 | — | — | — | NVD ↗ · NTAP-20260422-0009 |
CVE-2026-15955 | 2026-09-14 | HIGH | 7.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file pat NVD ↗ · NTAP-20260917-0006 |
CVE-2026-15995 | — | — | — | NVD ↗ · NTAP-20260724-0014 |
CVE-2026-1642 | — | — | — | NVD ↗ · NTAP-20260313-0008 |
CVE-2026-16480 | — | — | — | NVD ↗ · NTAP-20260814-0011 |
CVE-2026-16702 | — | — | — | NVD ↗ · NTAP-20260917-0009 |
CVE-2026-17106 | — | — | — | NVD ↗ · NTAP-20260828-0017 |
CVE-2026-1718 | — | — | — | NVD ↗ · NTAP-20260529-0007 |
CVE-2026-17463 | 2026-09-14 | MEDIUM | 6.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker t NVD ↗ · NTAP-20260917-0010 |
CVE-2026-1757 | — | — | — | NVD ↗ · NTAP-20260220-0011 |
CVE-2026-18096 | — | — | — | NVD ↗ · NTAP-20260814-0012 |
CVE-2026-18097 | — | — | — | NVD ↗ · NTAP-20260814-0009 |
CVE-2026-18401 | 2026-08-04 | MEDIUM | 6.9 | The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 char NVD ↗ · NTAP-20260930-0002 |
CVE-2026-18798 | — | — | — | NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0004 |
CVE-2026-18963 | — | — | — | NVD ↗ · NTAP-20260828-0006 |
CVE-2026-19033 | 2026-09-16 | MEDIUM | 6.5 | For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG s NVD ↗ · NTAP-20260930-0010 |
CVE-2026-1933 | — | — | — | NVD ↗ · NTAP-20260527-0005 |
CVE-2026-1965 | 2026-03-11 | MEDIUM | 6.5 | libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recen NVD ↗ · NTAP-20260327-0002 |
CVE-2026-19662 | 2026-09-16 | MEDIUM | 5.9 | An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone NVD ↗ · NTAP-20260930-0011 |
CVE-2026-19666 | 2026-09-16 | HIGH | 7.5 | On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process wi NVD ↗ · NTAP-20260930-0003 |
CVE-2026-19667 | 2026-09-16 | HIGH | 7.5 | If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache ent NVD ↗ · NTAP-20260930-0004 |
CVE-2026-19668 | 2026-09-16 | MEDIUM | 5.3 | A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default li NVD ↗ · NTAP-20260930-0015 |
CVE-2026-19941 | 2026-09-16 | MEDIUM | 5.9 | An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream lev NVD ↗ · NTAP-20260930-0012 |
CVE-2026-2005 | — | — | — | NVD ↗ · NTAP-20260515-0001 |
CVE-2026-2006 | — | — | — | NVD ↗ · NTAP-20260515-0002 |
CVE-2026-20652 | — | — | — | NVD ↗ · NTAP-20260429-0010 |
CVE-2026-21226 | — | — | — | NVD ↗ · NTAP-20260410-0001 |
CVE-2026-21441 | — | — | — | NVD ↗ · NTAP-20260130-0010 |
CVE-2026-21636 | — | — | — | NVD ↗ · NTAP-20260311-0014 |
CVE-2026-21637 | — | — | — | NVD ↗ · NTAP-20260313-0009 |
CVE-2026-21710 | — | — | — | NVD ↗ · NTAP-20260410-0013 |
CVE-2026-21711 | 2026-03-30 | MEDIUM | 5.3 | A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all compa NVD ↗ · NTAP-20261002-0020 |
CVE-2026-21712 | — | — | — | NVD ↗ · NTAP-20260410-0010 |
CVE-2026-21713 | 2026-03-30 | MEDIUM | 5.9 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proport NVD ↗ · NTAP-20260925-0020 |
CVE-2026-21714 | — | — | — | NVD ↗ · NTAP-20260410-0012 |
CVE-2026-21717 | — | — | — | NVD ↗ · NTAP-20260410-0011 |
CVE-2026-21925 | — | — | — | NVD ↗ · NTAP-20260123-0012 |
CVE-2026-21929 | — | — | — | NVD ↗ · NTAP-20260123-0010 |
CVE-2026-21932 | — | — | — | NVD ↗ · NTAP-20260123-0012 |
CVE-2026-21933 | — | — | — | NVD ↗ · NTAP-20260123-0012 |
CVE-2026-21936 | — | — | — | NVD ↗ · NTAP-20260123-0009 |
CVE-2026-21937 | — | — | — | NVD ↗ · NTAP-20260123-0009 |
CVE-2026-21941 | — | — | — | NVD ↗ · NTAP-20260123-0009 |
CVE-2026-21945 | — | — | — | NVD ↗ · NTAP-20260123-0012 |
CVE-2026-21947 | — | — | — | NVD ↗ · NTAP-20260123-0013 |
CVE-2026-21948 | — | — | — | NVD ↗ · NTAP-20260123-0009 |
CVE-2026-21949 | — | — | — | NVD ↗ · NTAP-20260123-0010 |
CVE-2026-21950 | — | — | — | NVD ↗ · NTAP-20260123-0010 |
CVE-2026-21952 | — | — | — | NVD ↗ · NTAP-20260123-0010 |
CVE-2026-21964 | — | — | — | NVD ↗ · NTAP-20260123-0009 |
CVE-2026-21965 | — | — | — | NVD ↗ · NTAP-20260123-0010 |
CVE-2026-21968 | — | — | — | NVD ↗ · NTAP-20260123-0009 |
CVE-2026-21998 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-22001 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-22002 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-22003 | — | — | — | NVD ↗ · NTAP-20260429-0009 |
CVE-2026-22004 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-22005 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-22007 | 2026-04-21 | LOW | 2.9 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versio NVD ↗ · NTAP-20260917-0001 · NTAP-20260717-0008 +1 |
CVE-2026-22008 | 2026-04-21 | LOW | 3.7 | Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability all NVD ↗ · NTAP-20260917-0001 · NTAP-20260429-0008 |
CVE-2026-22009 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-22013 | 2026-04-21 | MEDIUM | 5.3 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions t NVD ↗ · NTAP-20260917-0001 · NTAP-20260717-0008 +1 |
CVE-2026-22015 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-22016 | 2026-04-21 | HIGH | 7.5 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions t NVD ↗ · NTAP-20260917-0001 · NTAP-20260429-0012 |
CVE-2026-22017 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-22018 | 2026-04-21 | LOW | 3.7 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versi NVD ↗ · NTAP-20260917-0001 · NTAP-20260429-0012 |
CVE-2026-22021 | 2026-04-21 | MEDIUM | 5.3 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions t NVD ↗ · NTAP-20260917-0001 · NTAP-20260717-0008 +1 |
CVE-2026-22048 | — | — | — | NVD ↗ · NTAP-20260217-0001 |
CVE-2026-22049 | 2026-07-22 | HIGH | 8.8 | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID w NVD ↗ · NTAP-20260722-0001 |
CVE-2026-22050 | 2026-01-12 | MEDIUM | 4.3 | ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privil NVD ↗ · NTAP-20260112-0001 |
CVE-2026-22051 | — | — | — | NVD ↗ · NTAP-20260420-0001 |
CVE-2026-22052 | 2026-03-05 | MEDIUM | 4.3 | ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated NVD ↗ · NTAP-20260304-0001 |
CVE-2026-22054 | — | — | — | NVD ↗ · NTAP-20260603-0001 |
CVE-2026-22055 | — | — | — | NVD ↗ · NTAP-20260603-0002 |
CVE-2026-22056 | — | — | — | NVD ↗ · NTAP-20260828-0021 |
CVE-2026-22610 | — | — | — | NVD ↗ · NTAP-20260311-0001 |
CVE-2026-22695 | — | — | — | NVD ↗ · NTAP-20260821-0006 |
CVE-2026-22732 | 2026-03-19 | CRITICAL | 9.1 | When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be writt NVD ↗ · NTAP-20260501-0013 |
CVE-2026-22740 | — | — | — | NVD ↗ · NTAP-20260911-0015 |
CVE-2026-22741 | — | — | — | NVD ↗ · NTAP-20260911-0016 |
CVE-2026-22745 | — | — | — | NVD ↗ · NTAP-20260911-0015 |
CVE-2026-22795 | 2026-01-27 | MEDIUM | 5.5 | Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processin NVD ↗ · NTAP-20260204-0005 |
CVE-2026-22796 | 2026-01-27 | MEDIUM | 5.3 | Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without fir NVD ↗ · NTAP-20260204-0004 |
CVE-2026-22801 | — | — | — | NVD ↗ · NTAP-20260130-0011 |
CVE-2026-22984 | — | — | — | NVD ↗ · NTAP-20260508-0001 |
CVE-2026-22988 | — | — | — | NVD ↗ · NTAP-20260305-0017 |
CVE-2026-22990 | 2026-01-23 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() If the osdmap is (maliciou NVD ↗ · NTAP-20260508-0002 |
CVE-2026-22991 | 2026-01-23 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: libceph: make free_choose_arg_map() resilient to partial allocation free_choose_arg_map() ma NVD ↗ · NTAP-20260508-0006 |
CVE-2026-22992 | 2026-01-23 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_auth_done() Currently any error from ceph_ NVD ↗ · NTAP-20260508-0005 |
CVE-2026-22997 | — | — | — | NVD ↗ · NTAP-20260508-0003 |
CVE-2026-22998 | 2026-01-25 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec Commit efa56305908b ("n NVD ↗ · NTAP-20260424-0019 |
CVE-2026-23001 | — | — | — | NVD ↗ · NTAP-20260305-0018 |
CVE-2026-23003 | — | — | — | NVD ↗ · NTAP-20260508-0004 |
CVE-2026-23016 | — | — | — | NVD ↗ · NTAP-20260305-0019 |
CVE-2026-2303 | — | — | — | NVD ↗ · NTAP-20260626-0017 |
CVE-2026-23066 | — | — | — | NVD ↗ · NTAP-20260911-0019 |
CVE-2026-23095 | — | — | — | NVD ↗ · NTAP-20260424-0020 |
CVE-2026-23098 | 2026-02-04 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: netrom: fix double-free in nr_route_frame() In nr_route_frame(), old_skb is immediately free NVD ↗ · NTAP-20260424-0015 |
CVE-2026-23112 | 2026-02-13 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could NVD ↗ · NTAP-20260424-0013 |
CVE-2026-23193 | — | — | — | NVD ↗ · NTAP-20260305-0020 |
CVE-2026-23230 | 2026-02-18 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid shared-byte RMW races is_open, has_lease an NVD ↗ · NTAP-20260424-0014 |
CVE-2026-23231 | 2026-03-04 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publis NVD ↗ · NTAP-20260320-0013 |
CVE-2026-23255 | 2026-03-18 | MEDIUM | 5.5 | In the Linux kernel, the following vulnerability has been resolved: net: add proper RCU protection to /proc/net/ptype Yin Fengwei reported an RCU stall in ptype NVD ↗ · NTAP-20260925-0014 |
CVE-2026-23310 | 2026-03-25 | MEDIUM | 5.5 | In the Linux kernel, the following vulnerability has been resolved: bpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is loaded bond_option_mode_ NVD ↗ · NTAP-20260918-0015 |
CVE-2026-23389 | 2026-03-25 | MEDIUM | 5.5 | In the Linux kernel, the following vulnerability has been resolved: ice: Fix memory leak in ice_set_ringparam() In ice_set_ringparam, tx_rings and xdp_rings are NVD ↗ · NTAP-20260918-0016 |
CVE-2026-23399 | 2026-03-28 | MEDIUM | 5.5 | In the Linux kernel, the following vulnerability has been resolved: nf_tables: nft_dynset: fix possible stateful expression memleak in error path If cloning the NVD ↗ · NTAP-20260918-0017 |
CVE-2026-2340 | — | — | — | NVD ↗ · NTAP-20260527-0006 |
CVE-2026-23442 | 2026-04-03 | MEDIUM | 5.5 | In the Linux kernel, the following vulnerability has been resolved: ipv6: add NULL checks for idev in SRv6 paths __in6_dev_get() can return NULL when the device NVD ↗ · NTAP-20260918-0018 |
CVE-2026-23444 | 2026-04-03 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure ieee80211_tx_prepare_s NVD ↗ · NTAP-20260918-0019 |
CVE-2026-23468 | 2026-04-03 | MEDIUM | 5.5 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Userspace can pass an a NVD ↗ · NTAP-20260918-0020 |
CVE-2026-23865 | 2026-03-02 | MEDIUM | 5.3 | An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read o NVD ↗ · NTAP-20260917-0001 · NTAP-20260429-0007 |
CVE-2026-2391 | — | — | — | NVD ↗ · NTAP-20260515-0010 |
CVE-2026-23918 | — | — | — | NVD ↗ · NTAP-20260508-0008 |
CVE-2026-23941 | 2026-03-13 | CRITICAL | 9.4 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vul NVD ↗ · NTAP-20260703-0005 |
CVE-2026-23942 | 2026-03-13 | MEDIUM | 5.4 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. This vulner NVD ↗ · NTAP-20260703-0005 |
CVE-2026-23943 | 2026-03-13 | MEDIUM | 5.3 | Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Dep NVD ↗ · NTAP-20260703-0005 |
CVE-2026-23949 | 2026-01-20 | HIGH | 8.6 | jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `j NVD ↗ · NTAP-20260327-0011 |
CVE-2026-23950 | — | — | — | NVD ↗ · NTAP-20260417-0003 |
CVE-2026-24051 | 2026-02-02 | HIGH | 7.0 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search NVD ↗ · NTAP-20260917-0001 · NTAP-20260612-0010 |
CVE-2026-24061 | — | — | — | NVD ↗ · NTAP-20260206-0001 |
CVE-2026-24072 | — | — | — | NVD ↗ · NTAP-20260508-0013 |
CVE-2026-24281 | — | — | — | NVD ↗ · NTAP-20260605-0007 |
CVE-2026-24308 | — | — | — | NVD ↗ · NTAP-20260508-0019 |
CVE-2026-24733 | — | — | — | NVD ↗ · NTAP-20260227-0002 |
CVE-2026-24734 | — | — | — | NVD ↗ · NTAP-20260227-0003 |
CVE-2026-24842 | — | — | — | NVD ↗ · NTAP-20260422-0018 |
CVE-2026-24880 | 2026-04-09 | HIGH | 7.5 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects NVD ↗ · NTAP-20260501-0014 |
CVE-2026-25639 | 2026-02-09 | HIGH | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeErro NVD ↗ · NTAP-20260917-0001 · NTAP-20260313-0010 |
CVE-2026-25646 | 2026-02-10 | HIGH | 8.1 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an NVD ↗ · NTAP-20260917-0001 |
CVE-2026-25679 | 2026-03-06 | HIGH | 7.5 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. NVD ↗ · NTAP-20260422-0007 |
CVE-2026-25680 | — | — | — | NVD ↗ · NTAP-20260626-0012 |
CVE-2026-25681 | — | — | — | NVD ↗ · NTAP-20260626-0012 |
CVE-2026-25749 | — | — | — | NVD ↗ · NTAP-20260320-0010 |
CVE-2026-25854 | — | — | — | NVD ↗ · NTAP-20260522-0004 |
CVE-2026-25896 | — | — | — | NVD ↗ · NTAP-20260311-0006 |
CVE-2026-26007 | 2026-02-10 | MEDIUM | 6.5 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or Ellipti NVD ↗ · NTAP-20260917-0001 · NTAP-20260311-0010 |
CVE-2026-26143 | — | — | — | NVD ↗ · NTAP-20260731-0016 |
CVE-2026-26157 | — | — | — | NVD ↗ · NTAP-20260305-0006 |
CVE-2026-26158 | — | — | — | NVD ↗ · NTAP-20260305-0007 |
CVE-2026-26278 | — | — | — | NVD ↗ · NTAP-20260311-0007 |
CVE-2026-2673 | 2026-03-13 | MEDIUM | 6.5 | Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the NVD ↗ · NTAP-20260320-0015 |
CVE-2026-26996 | 2026-02-20 | HIGH | 7.5 | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expr NVD ↗ · NTAP-20260917-0001 |
CVE-2026-27024 | 2026-02-20 | MEDIUM | 5.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop NVD ↗ · NTAP-20260917-0001 |
CVE-2026-27025 | 2026-02-20 | MEDIUM | 5.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes an NVD ↗ · NTAP-20260917-0001 |
CVE-2026-27026 | 2026-02-20 | MEDIUM | 5.5 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. T NVD ↗ · NTAP-20260917-0001 |
CVE-2026-27135 | 2026-03-18 | HIGH | 7.5 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data whe NVD ↗ · NTAP-20260717-0011 |
CVE-2026-27136 | — | — | — | NVD ↗ · NTAP-20260626-0012 |
CVE-2026-27137 | 2026-03-06 | HIGH | 7.5 | When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different do NVD ↗ · NTAP-20260508-0020 |
CVE-2026-27139 | — | — | — | NVD ↗ · NTAP-20260619-0012 |
CVE-2026-27140 | 2026-04-08 | HIGH | 8.8 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass. NVD ↗ · NTAP-20260424-0001 |
CVE-2026-27141 | — | — | — | NVD ↗ · NTAP-20260320-0012 |
CVE-2026-27142 | 2026-03-06 | MEDIUM | 6.1 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with NVD ↗ · NTAP-20260422-0006 |
CVE-2026-27143 | 2026-04-08 | CRITICAL | 9.8 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to NVD ↗ · NTAP-20260424-0001 |
CVE-2026-27144 | 2026-04-08 | HIGH | 7.1 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct de NVD ↗ · NTAP-20260424-0001 |
CVE-2026-27145 | — | — | — | NVD ↗ · NTAP-20260619-0006 |
CVE-2026-27171 | — | — | — | NVD ↗ · NTAP-20260311-0015 |
CVE-2026-27205 | 2026-02-21 | MEDIUM | 4.3 | Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the NVD ↗ · NTAP-20260917-0001 |
CVE-2026-27446 | — | — | — | NVD ↗ · NTAP-20260320-0011 |
CVE-2026-27448 | — | — | — | NVD ↗ · NTAP-20260717-0013 |
CVE-2026-27456 | — | — | — | NVD ↗ · NTAP-20260612-0012 |
CVE-2026-27699 | — | — | — | NVD ↗ · NTAP-20260424-0008 |
CVE-2026-27903 | 2026-02-26 | HIGH | 7.5 | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1 NVD ↗ · NTAP-20260917-0001 |
CVE-2026-27904 | 2026-02-26 | HIGH | 7.5 | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1 NVD ↗ · NTAP-20260917-0001 |
CVE-2026-28367 | — | — | — | NVD ↗ · NTAP-20260501-0009 |
CVE-2026-28368 | — | — | — | NVD ↗ · NTAP-20260501-0010 |
CVE-2026-28369 | — | — | — | NVD ↗ · NTAP-20260501-0011 |
CVE-2026-28386 | — | — | — | NVD ↗ · NTAP-20260417-0016 |
CVE-2026-28387 | — | — | — | NVD ↗ · NTAP-20260417-0015 |
CVE-2026-28388 | — | — | — | NVD ↗ · NTAP-20260417-0014 |
CVE-2026-28389 | — | — | — | NVD ↗ · NTAP-20260417-0013 |
CVE-2026-28390 | 2026-04-07 | HIGH | 7.5 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Ap NVD ↗ · NTAP-20260417-0012 |
CVE-2026-28780 | — | — | — | NVD ↗ · NTAP-20260508-0007 |
CVE-2026-28808 | — | — | — | NVD ↗ · NTAP-20260626-0015 |
CVE-2026-29036 | — | — | — | NVD ↗ · NTAP-20260821-0004 |
CVE-2026-29145 | — | — | — | NVD ↗ · NTAP-20260522-0003 |
CVE-2026-29167 | 2026-06-08 | CRITICAL | 9.8 | Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67 NVD ↗ · NTAP-20260610-0001 |
CVE-2026-29168 | — | — | — | NVD ↗ · NTAP-20260508-0011 |
CVE-2026-29169 | — | — | — | NVD ↗ · NTAP-20260508-0009 |
CVE-2026-29170 | — | — | — | NVD ↗ · NTAP-20260610-0005 |
CVE-2026-29181 | — | — | — | NVD ↗ · NTAP-20260513-0010 |
CVE-2026-2950 | 2026-03-31 | MEDIUM | 6.5 | Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://gith NVD ↗ · NTAP-20260917-0001 |
CVE-2026-29518 | — | — | — | NVD ↗ · NTAP-20260917-0013 |
CVE-2026-3012 | — | — | — | NVD ↗ · NTAP-20260527-0003 |
CVE-2026-3039 | — | — | — | NVD ↗ · NTAP-20260529-0001 |
CVE-2026-30922 | 2026-03-18 | HIGH | 7.5 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recu NVD ↗ · NTAP-20260917-0001 |
CVE-2026-3104 | — | — | — | NVD ↗ · NTAP-20260403-0004 |
CVE-2026-3119 | — | — | — | NVD ↗ · NTAP-20260403-0002 |
CVE-2026-31402 | 2026-04-03 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 1 NVD ↗ · NTAP-20260417-0008 |
CVE-2026-31407 | 2026-04-06 | HIGH | 7.1 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: add missing netlink policy validations Hyunwoo Kim reports out-of-boun NVD ↗ · NTAP-20260918-0014 |
CVE-2026-31431 | — | — | — | NVD ↗ · NTAP-20260501-0001 |
CVE-2026-31589 | — | — | — | NVD ↗ · NTAP-20260814-0001 |
CVE-2026-31607 | — | — | — | NVD ↗ · NTAP-20260605-0014 |
CVE-2026-31633 | — | — | — | NVD ↗ · NTAP-20260731-0001 |
CVE-2026-31718 | — | — | — | NVD ↗ · NTAP-20260703-0001 |
CVE-2026-31789 | — | — | — | NVD ↗ · NTAP-20260417-0011 |
CVE-2026-31790 | — | — | — | NVD ↗ · NTAP-20260417-0017 |
CVE-2026-3184 | — | — | — | NVD ↗ · NTAP-20260612-0011 |
CVE-2026-31958 | 2026-03-11 | HIGH | 7.5 | Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart NVD ↗ · NTAP-20260917-0001 |
CVE-2026-32280 | 2026-04-08 | HIGH | 7.5 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Int NVD ↗ · NTAP-20260424-0001 |
CVE-2026-32281 | 2026-04-08 | HIGH | 7.5 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, poss NVD ↗ · NTAP-20260424-0001 |
CVE-2026-32282 | 2026-04-08 | MEDIUM | 6.4 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even NVD ↗ · NTAP-20260424-0001 |
CVE-2026-32283 | 2026-04-08 | HIGH | 7.5 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consum NVD ↗ · NTAP-20260424-0001 |
CVE-2026-32288 | 2026-04-08 | MEDIUM | 5.5 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old NVD ↗ · NTAP-20260424-0001 |
CVE-2026-32289 | 2026-04-08 | MEDIUM | 6.1 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. A NVD ↗ · NTAP-20260424-0001 |
CVE-2026-32316 | 2026-04-13 | HIGH | 8.2 | jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_b NVD ↗ · NTAP-20260918-0001 |
CVE-2026-3238 | — | — | — | NVD ↗ · NTAP-20260527-0004 |
CVE-2026-32597 | — | — | — | NVD ↗ · NTAP-20260417-0010 |
CVE-2026-3260 | — | — | — | NVD ↗ · NTAP-20260403-0015 |
CVE-2026-32710 | — | — | — | NVD ↗ · NTAP-20260527-0015 |
CVE-2026-32746 | — | — | — | NVD ↗ · NTAP-20260422-0004 |
CVE-2026-3276 | — | — | — | NVD ↗ · NTAP-20260731-0013 |
CVE-2026-32772 | — | — | — | NVD ↗ · NTAP-20260424-0009 |
CVE-2026-32792 | — | — | — | NVD ↗ · NTAP-20260626-0001 |
CVE-2026-32990 | — | — | — | NVD ↗ · NTAP-20260522-0005 |
CVE-2026-33006 | — | — | — | NVD ↗ · NTAP-20260508-0017 |
CVE-2026-33007 | — | — | — | NVD ↗ · NTAP-20260508-0014 |
CVE-2026-33056 | — | — | — | NVD ↗ · NTAP-20260422-0017 |
CVE-2026-33186 | 2026-03-20 | CRITICAL | 9.1 | gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 NVD ↗ · NTAP-20260422-0005 |
CVE-2026-33227 | — | — | — | NVD ↗ · NTAP-20260417-0002 |
CVE-2026-33228 | — | — | — | NVD ↗ · NTAP-20260501-0008 |
CVE-2026-33230 | 2026-03-20 | MEDIUM | 6.1 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Proce NVD ↗ · NTAP-20260917-0001 |
CVE-2026-33231 | 2026-03-20 | HIGH | 7.5 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Proce NVD ↗ · NTAP-20260917-0001 |
CVE-2026-33236 | 2026-03-20 | HIGH | 8.1 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Proce NVD ↗ · NTAP-20260917-0001 |
CVE-2026-33278 | — | — | — | NVD ↗ · NTAP-20260626-0001 |
CVE-2026-33413 | — | — | — | NVD ↗ · NTAP-20260724-0005 |
CVE-2026-33416 | 2026-03-26 | HIGH | 7.5 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 th NVD ↗ · NTAP-20260917-0001 |
CVE-2026-33523 | — | — | — | NVD ↗ · NTAP-20260508-0012 |
CVE-2026-33630 | — | — | — | NVD ↗ · NTAP-20260731-0015 |
CVE-2026-33747 | — | — | — | NVD ↗ · NTAP-20260619-0013 |
CVE-2026-33748 | — | — | — | NVD ↗ · NTAP-20260619-0014 |
CVE-2026-33810 | — | — | — | NVD ↗ · NTAP-20260424-0003 |
CVE-2026-33811 | — | — | — | NVD ↗ · NTAP-20260612-0004 |
CVE-2026-33814 | — | — | — | NVD ↗ · NTAP-20260612-0006 |
CVE-2026-33845 | 2026-04-30 | HIGH | 7.5 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and r NVD ↗ · NTAP-20260724-0002 |
CVE-2026-33846 | 2026-05-04 | HIGH | 7.5 | A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incomi NVD ↗ · NTAP-20260724-0002 |
CVE-2026-33857 | — | — | — | NVD ↗ · NTAP-20260508-0015 |
CVE-2026-33870 | — | — | — | NVD ↗ · NTAP-20260717-0001 · NTAP-20260626-0008 |
Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999