The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2026-62299 - CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two response rules, edns0SetResponseRule and edns0ReplaceResponseRule[T] in plugin/rewrite/edns0.go, ... read CVE-2026-62299
Published: July 16, 2026; 4:16:46 PM -0400 -
CVE-2026-62309 - CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go PacketConn.ReadFrom handles a PROXY v2 header wit... read CVE-2026-62309
Published: July 16, 2026; 4:16:47 PM -0400 -
CVE-2026-62994 - CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configured with k8s_external headless-service zone transfers and Kubernetes contain... read CVE-2026-62994
Published: July 16, 2026; 4:16:47 PM -0400 -
CVE-2026-44978 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the FIPS-specific receive paths. This vulnerability does not affect the default configuration of xrdp. The vulnerability is only ex... read CVE-2026-44978
Published: July 20, 2026; 1:17:09 PM -0400 -
CVE-2026-44178 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the xrdp pro... read CVE-2026-44178
Published: July 20, 2026; 1:17:09 PM -0400 -
CVE-2026-42218 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker can infer the existence of a username on the syst... read CVE-2026-42218
Published: July 20, 2026; 1:17:08 PM -0400 -
CVE-2026-41521 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that ... read CVE-2026-41521
Published: July 20, 2026; 1:17:08 PM -0400V3.1: 9.1 CRITICAL
-
CVE-2026-54538 - xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to properly validate the totalLength field within the RDP protocol control header during packet reception. An unauthenticated remote... read CVE-2026-54538
Published: July 20, 2026; 1:17:59 PM -0400 -
CVE-2026-55238 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did not perform sufficient length validation for sp... read CVE-2026-55238
Published: July 20, 2026; 1:18:07 PM -0400 -
CVE-2026-55645 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client Control PDUs. During the RDP connection sequence, the parser does not perform sufficient length validation before reading spec... read CVE-2026-55645
Published: July 20, 2026; 1:18:07 PM -0400 -
CVE-2026-41252 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during the handling of RFB protocol color map messages ... read CVE-2026-41252
Published: July 20, 2026; 1:17:08 PM -0400 -
CVE-2026-63762 - SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript scripting engine, which is enabled via the --allow-scripting capability (disabled by default). Any user able to execute arbitr... read CVE-2026-63762
Published: July 20, 2026; 8:19:46 AM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-63763 - SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or modify fields containing futures, functions, or closures. Be... read CVE-2026-63763
Published: July 20, 2026; 8:19:46 AM -0400V3.1: 8.8 HIGH
-
CVE-2026-44891 - Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative siz... read CVE-2026-44891
Published: July 17, 2026; 5:17:06 PM -0400 -
CVE-2026-55833 - Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceede... read CVE-2026-55833
Published: July 20, 2026; 8:17:35 PM -0400 -
CVE-2026-55831 - Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and m... read CVE-2026-55831
Published: July 20, 2026; 8:17:35 PM -0400 -
CVE-2026-53345 - In the Linux kernel, the following vulnerability has been resolved: KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying When marking a page dirty, complain about not having a running/loaded vCPU if and only if the VM is stil... read CVE-2026-53345
Published: July 01, 2026; 10:16:42 AM -0400V3.1: 5.5 MEDIUM
-
CVE-2026-53346 - In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES Due to a rustc bug [1] the -Cforce-unwind-tables=y flag only emits the uwtable annotation for functions, but n... read CVE-2026-53346
Published: July 01, 2026; 10:16:42 AM -0400V3.1: 7.1 HIGH
-
CVE-2026-53347 - In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting aren't initialized if virtio-gpu driver built with disabled KMS, leading to access of uninitialized d... read CVE-2026-53347
Published: July 01, 2026; 10:16:42 AM -0400V3.1: 5.5 MEDIUM
-
CVE-2026-53348 - In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions sdca_dev_unregister_functions() iterates over all SDCA function descriptors and calls sdca_dev_unregist... read CVE-2026-53348
Published: July 01, 2026; 10:16:42 AM -0400V3.1: 5.5 MEDIUM