Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-33375 — Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS

The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, cras…

grafana | Remote | Denial of Service
Mar 26, 2026 Mar 31, 2026
Mar 26, 2026
Mar 31, 2026
6.5 MEDIUM
CVE-2026-2272 — Gimp: gimp: memory corruption due to integer overflow in ico file handling

A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size…

enterprise_linux gimp | Remote | Memory Corruption
Mar 26, 2026 Apr 03, 2026
Mar 26, 2026
Apr 03, 2026
5.5 MEDIUM
CVE-2026-2271 — Gimp: gimp: denial of service via crafted psp image file

A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PS…

gimp | Memory Corruption
Mar 26, 2026 Apr 21, 2026
Mar 26, 2026
Apr 21, 2026
6.5 MEDIUM
CVE-2026-2239 — Gimp: gimp: application crash (dos) via crafted psd file due to heap-buffer-overflow

A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buff…

enterprise_linux gimp | Remote | Memory Corruption
Mar 26, 2026 Apr 03, 2026
Mar 26, 2026
Apr 03, 2026
7.5 HIGH
CVE-2026-2100 — P11-kit: null dereference via c_derivekey with specific null parameters

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters se…

enterprise_linux p11-kit hardened_images | Remote | Denial of Service
Mar 26, 2026 Apr 25, 2026
Mar 26, 2026
Apr 25, 2026
5.4 MEDIUM
CVE-2026-21724 — Missing Protected-field Authorization in Provisioning Contact Points API

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the requ…

grafana | Remote | Authorization
Mar 26, 2026 Apr 14, 2026
Mar 26, 2026
Apr 14, 2026
9.8 CRITICAL
CVE-2026-0968 — Libssh: libssh: denial of service due to malformed sftp message

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listin…

enterprise_linux libssh | Remote | Memory Corruption
Mar 26, 2026 Apr 13, 2026
Mar 26, 2026
Apr 13, 2026
5.5 MEDIUM
CVE-2026-0967 — Libssh: libssh: denial of service via inefficient regular expression processing

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can…

enterprise_linux libssh | Denial of Service
Mar 26, 2026 Apr 02, 2026
Mar 26, 2026
Apr 02, 2026
6.5 MEDIUM
CVE-2026-0966 — Libssh: buffer underflow in ssh_get_hexa() on invalid input

The API function `ssh_get_hexa()` is vulnerable, when 0-lenght input is provided to this function. This function is used internally in `ssh_get_fingerprint_hash()` and `ssh_print_hexa()` (deprecated)…

hardened_images | Remote | Denial of Service
Mar 26, 2026 Apr 24, 2026
Mar 26, 2026
Apr 24, 2026
3.3 LOW
CVE-2026-0965 — Libssh: libssh: denial of service via improper configuration file handling

A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system …

enterprise_linux libssh | Path Traversal
Mar 26, 2026 Apr 02, 2026
Mar 26, 2026
Apr 02, 2026
5.0 MEDIUM
CVE-2026-0964 — Libssh: improper sanitation of paths received from scp servers

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or conf…

Remote | Path Traversal
Mar 26, 2026 Mar 30, 2026
Mar 26, 2026
Mar 30, 2026
Showing 20 of 5851 Results