6.3
CVE-2026-34477 - Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostnamβ¦
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property, buβ¦
5.5
CVE-2026-29043 - HDF5 H5T__ref_mem_setnull Heap Buffer Overflow
HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a denial-of-service condition, and potentially further issues such as remoβ¦
6.2
CVE-2026-40227 -
In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.
6.4
CVE-2026-40226 -
In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
6.4
CVE-2026-40225 -
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
6.7
CVE-2026-40224 -
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.
8.6
CVE-2026-29002 - CouchCMS Privilege Escalation via f_k_levels_list Parameter
CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with the f_k_levels_list parameter in user creation requests. Attackers can modify the parameter value from 4 to 10 in the HTTP request body to bypass authorβ¦
4.7
CVE-2026-40223 -
In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.
8.8
CVE-2026-40217 -
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
0.0
CVE-2026-6069 - CVE-2026-6069
NASMβs disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffer capacity.