CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) MSRC Security Update Guide 8 août 2026 à 10:40 Information published.
CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) MSRC Security Update Guide 8 août 2026 à 10:40 Information published.
CVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsi MSRC Security Update Guide 8 août 2026 à 10:41 Information published.
CVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsi MSRC Security Update Guide 8 août 2026 à 10:41 Information published.
CVE-2026-44943 remote limited file-write as root via discovery in open-iscsi MSRC Security Update Guide 8 août 2026 à 10:41 Information published.
CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates MSRC Security Update Guide 8 août 2026 à 10:41 Information published.
CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations MSRC Security Update Guide 8 août 2026 à 10:40 Information published.
CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate. MSRC Security Update Guide 8 août 2026 à 10:40 Information published.
CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate. MSRC Security Update Guide 8 août 2026 à 10:40 Information published.
CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate. MSRC Security Update Guide 8 août 2026 à 10:40 Information published.
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys MSRC Security Update Guide 8 août 2026 à 10:40 Information published.
CVE-2026-68480 x86/bugs: Make Safe-RET robust against interrupt injection MSRC Security Update Guide 8 août 2026 à 10:01 Information published.
CVE-2019-9192 In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion MSRC Security Update Guide 7 août 2026 à 10:07 Information published.
CVE-2019-9924 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell. MSRC Security Update Guide 7 août 2026 à 10:06 Information published.
CVE-2010-4052 Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD. MSRC Security Update Guide 7 août 2026 à 10:05 Information published.
CVE-2019-6706 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships. MSRC Security Update Guide 7 août 2026 à 10:03 Information published.
CVE-2018-6829 cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation. MSRC Security Update Guide 7 août 2026 à 09:59 Information published.
CVE-2018-1128 It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable. MSRC Security Update Guide 7 août 2026 à 09:42 Information published.
CVE-2018-5407 Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. MSRC Security Update Guide 7 août 2026 à 09:24 Information published.
CVE-2016-2568 pkexec, when used with --user nonpriv, allows local users to escape to the parent session MSRC Security Update Guide 7 août 2026 à 09:20 Information published.
CVE-2007-3205 The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin. MSRC Security Update Guide 7 août 2026 à 09:19 Information published.