NVD Dashboard
CVEs Received and Processed
NVD Contains
| CVE Vulnerabilities | 369560 |
| Checklists | 898 |
| US-CERT Alerts | 249 |
| US-CERT Vuln Notes | 4486 |
| OVAL Queries | 0 |
| CPE Names | 1776648 |
CVSS V3 Score Distribution
| Severity | Number of Vulns |
|---|
CVSS V2 Score Distribution
| Severity | Number of Vulns |
|---|
For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
-
CVE-2026-62299 - CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two response rules, edns0SetResponseRule and edns0ReplaceResponseRule[T] in plugin/rewrite/edns0.go, ... read CVE-2026-62299
Published: July 16, 2026; 4:16:46 PM -0400 -
CVE-2026-62309 - CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go PacketConn.ReadFrom handles a PROXY v2 header wit... read CVE-2026-62309
Published: July 16, 2026; 4:16:47 PM -0400 -
CVE-2026-62994 - CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configured with k8s_external headless-service zone transfers and Kubernetes contain... read CVE-2026-62994
Published: July 16, 2026; 4:16:47 PM -0400 -
CVE-2026-44978 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the FIPS-specific receive paths. This vulnerability does not affect the default configuration of xrdp. The vulnerability is only ex... read CVE-2026-44978
Published: July 20, 2026; 1:17:09 PM -0400 -
CVE-2026-44178 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the xrdp pro... read CVE-2026-44178
Published: July 20, 2026; 1:17:09 PM -0400 -
CVE-2026-42218 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker can infer the existence of a username on the syst... read CVE-2026-42218
Published: July 20, 2026; 1:17:08 PM -0400 -
CVE-2026-41521 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that ... read CVE-2026-41521
Published: July 20, 2026; 1:17:08 PM -0400V3.1: 9.1 CRITICAL
-
CVE-2026-54538 - xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to properly validate the totalLength field within the RDP protocol control header during packet reception. An unauthenticated remote... read CVE-2026-54538
Published: July 20, 2026; 1:17:59 PM -0400 -
CVE-2026-55238 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did not perform sufficient length validation for sp... read CVE-2026-55238
Published: July 20, 2026; 1:18:07 PM -0400 -
CVE-2026-55645 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client Control PDUs. During the RDP connection sequence, the parser does not perform sufficient length validation before reading spec... read CVE-2026-55645
Published: July 20, 2026; 1:18:07 PM -0400 -
CVE-2026-41252 - xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during the handling of RFB protocol color map messages ... read CVE-2026-41252
Published: July 20, 2026; 1:17:08 PM -0400 -
CVE-2026-63762 - SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript scripting engine, which is enabled via the --allow-scripting capability (disabled by default). Any user able to execute arbitr... read CVE-2026-63762
Published: July 20, 2026; 8:19:46 AM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-63763 - SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or modify fields containing futures, functions, or closures. Be... read CVE-2026-63763
Published: July 20, 2026; 8:19:46 AM -0400V3.1: 8.8 HIGH
-
CVE-2026-44891 - Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative siz... read CVE-2026-44891
Published: July 17, 2026; 5:17:06 PM -0400 -
CVE-2026-55833 - Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceede... read CVE-2026-55833
Published: July 20, 2026; 8:17:35 PM -0400 -
CVE-2026-55831 - Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and m... read CVE-2026-55831
Published: July 20, 2026; 8:17:35 PM -0400 -
CVE-2026-53345 - In the Linux kernel, the following vulnerability has been resolved: KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying When marking a page dirty, complain about not having a running/loaded vCPU if and only if the VM is stil... read CVE-2026-53345
Published: July 01, 2026; 10:16:42 AM -0400V3.1: 5.5 MEDIUM
-
CVE-2026-53346 - In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES Due to a rustc bug [1] the -Cforce-unwind-tables=y flag only emits the uwtable annotation for functions, but n... read CVE-2026-53346
Published: July 01, 2026; 10:16:42 AM -0400V3.1: 7.1 HIGH
-
CVE-2026-53347 - In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting aren't initialized if virtio-gpu driver built with disabled KMS, leading to access of uninitialized d... read CVE-2026-53347
Published: July 01, 2026; 10:16:42 AM -0400V3.1: 5.5 MEDIUM
-
CVE-2026-53348 - In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions sdca_dev_unregister_functions() iterates over all SDCA function descriptors and calls sdca_dev_unregist... read CVE-2026-53348
Published: July 01, 2026; 10:16:42 AM -0400V3.1: 5.5 MEDIUM