enterprise linux records
90 published records for vendor enterprise linux.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 10
- With a fix record
- 92.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-122 Heap-based Buffer Overflow8
- CWE-125 Out-of-bounds Read7
- CWE-190 Integer Overflow or Wraparound7
- CWE-400 Uncontrolled Resource Consumption5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-121 Stack-based Buffer Overflow3
The weakness classes this vendor ships most often: where to look.
CWEAll records
90 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2026-4631Proof of concept | Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injectionred hat · red hat enterprise linux 10 · CWE-78 | Critical9.8 | — | 9.2% | Apr 7, 2026 |
37Monitor | CVE-2026-8450No exploit | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()oalders · http::daemon · CWE-73 | Critical9.1 | — | 2.6% | May 27, 2026 |
37Monitor | CVE-2025-14813No exploit | GOSTCTR implementation unable to process more than 255 blocks correctlylegion of the bouncy castle inc. · bc-java · CWE-327 | Critical9.3 | — | 0.3% | Apr 15, 2026 |
36Monitor | CVE-2026-9277Proof of concept | shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`CWE-77 | Critical9.2 | — | 1.0% | May 22, 2026 |
36Monitor | CVE-2026-6100No exploit | Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressurepython software foundation · cpython · CWE-416 | Critical9.1 | — | 0.8% | Apr 13, 2026 |
36Monitor | CVE-2025-10263No exploit | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-arm · c1-ultra · CWE-362 | Critical9.1 | — | 0.5% | Jun 9, 2026 |
35Monitor | CVE-2026-52720No exploit | Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfbred hat · red hat enterprise linux 10 · CWE-122 | High8.8 | — | 1.2% | Jun 15, 2026 |
35Monitor | CVE-2026-5598No exploit | Non-constant time comparisons risk private key leakage in FrodoKEM.legion of the bouncy castle inc. · bc-java · CWE-385 | High8.9 | — | 1.0% | Apr 15, 2026 |
34Monitor | CVE-2026-1761No exploit | Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http responsered hat · red hat enterprise linux 10 · CWE-121 | High8.6 | — | 1.0% | Feb 2, 2026 |
34Monitor | CVE-2026-46384No exploit | iskorotkov/avro: Integer Overflow in Avro Decoderiskorotkov · avro · CWE-190 | High8.7 | — | 0.9% | May 29, 2026 |
34Monitor | CVE-2026-31812No exploit | Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsingquinn-rs · quinn · CWE-248 | High8.7 | — | 0.9% | Mar 10, 2026 |
34Monitor | CVE-2026-46385No exploit | iskorotkov/avro: CPU Exhaustion in Avro Decoderiskorotkov · avro · CWE-400 | High8.7 | — | 0.9% | May 29, 2026 |
34Monitor | CVE-2026-3505No exploit | Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.legion of the bouncy castle inc. · bc-java · CWE-400 | High8.7 | — | 0.9% | Apr 15, 2026 |
34Monitor | CVE-2026-41673No exploit | xmldom: Denial of service via uncontrolled recursion in XML serializationxmldom · xmldom · CWE-674 | High8.7 | — | 0.9% | May 7, 2026 |
34Monitor | CVE-2026-5367No exploit | Ovn: ovn: information disclosure via crafted dhcpv6 packetsred hat · fast datapath for red hat enterprise linux 10 · CWE-130 | High8.6 | — | 0.9% | Apr 24, 2026 |
34Monitor | CVE-2026-12143No exploit | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)form-data · form-data · CWE-93 | High8.7 | — | 0.7% | Jun 12, 2026 |
34Monitor | CVE-2026-41672No exploit | xmldom: XML node injection through unvalidated comment serializationxmldom · xmldom · CWE-91 | High8.7 | — | 0.7% | May 7, 2026 |
34Monitor | CVE-2026-41675No exploit | xmldom: XML node injection through unvalidated processing instruction serializationxmldom · xmldom · CWE-91 | High8.7 | — | 0.6% | May 7, 2026 |
34Monitor | CVE-2026-0719No exploit | Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authenticationred hat · red hat enterprise linux 10 · CWE-121 | High8.6 | — | 0.6% | Jan 8, 2026 |
34Monitor | CVE-2026-10649No exploit | Pacemaker: pacemaker: denial of service via integer overflow in remote message decompressionred hat · red hat enterprise linux 10 · CWE-190 | High8.6 | — | 0.6% | Jun 16, 2026 |
34Monitor | CVE-2026-41163No exploit | bubblewrap vulnerable to privilege escalation in setuid mode via ptracecontainers · bubblewrap · CWE-269 | High8.7 | — | 0.4% | May 9, 2026 |
33Monitor | CVE-2025-13878No exploit | Malformed BRID/HHIT records can cause named to terminate unexpectedlyisc · bind 9 · CWE-617 | High7.5 | — | 9.2% | Jan 21, 2026 |
33Monitor | CVE-2026-46529Proof of concept | PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenmate-desktop · atril · CWE-77 | High8.4 | — | 0.4% | Jun 10, 2026 |
33Monitor | CVE-2026-4892No exploit | A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code withdnsmasq · dnsmasq · CWE-122 | High8.4 | — | 0.3% | May 11, 2026 |
33Monitor | CVE-2026-54369No exploit | acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functionsacl project · acl · CWE-59 | High8.4 | — | 0.2% | Jun 29, 2026 |
- CVE-2026-463142Plan
Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection
CriticalCVSS 9.8Proof of conceptEPSS 9%red hat · red hat enterprise linux 10Apr 7, 2026
- CVE-2026-845037Monitor
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
CriticalCVSS 9.1No exploitEPSS 3%oalders · http::daemonMay 27, 2026
- CVE-2025-1481337Monitor
GOSTCTR implementation unable to process more than 255 blocks correctly
CriticalCVSS 9.3No exploitEPSS 0%legion of the bouncy castle inc. · bc-javaApr 15, 2026
- CVE-2026-927736Monitor
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
CriticalCVSS 9.2Proof of conceptEPSS 1%May 22, 2026
- CVE-2026-610036Monitor
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
CriticalCVSS 9.1No exploitEPSS 1%python software foundation · cpythonApr 13, 2026
- CVE-2025-1026336Monitor
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-
CriticalCVSS 9.1No exploitEPSS 1%arm · c1-ultraJun 9, 2026
- CVE-2026-5272035Monitor
Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfb
HighCVSS 8.8No exploitEPSS 1%red hat · red hat enterprise linux 10Jun 15, 2026
- CVE-2026-559835Monitor
Non-constant time comparisons risk private key leakage in FrodoKEM.
HighCVSS 8.9No exploitEPSS 1%legion of the bouncy castle inc. · bc-javaApr 15, 2026
- CVE-2026-176134Monitor
Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http response
HighCVSS 8.6No exploitEPSS 1%red hat · red hat enterprise linux 10Feb 2, 2026
- CVE-2026-4638434Monitor
iskorotkov/avro: Integer Overflow in Avro Decoder
HighCVSS 8.7No exploitEPSS 1%iskorotkov · avroMay 29, 2026
- CVE-2026-3181234Monitor
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
HighCVSS 8.7No exploitEPSS 1%quinn-rs · quinnMar 10, 2026
- CVE-2026-4638534Monitor
iskorotkov/avro: CPU Exhaustion in Avro Decoder
HighCVSS 8.7No exploitEPSS 1%iskorotkov · avroMay 29, 2026
- CVE-2026-350534Monitor
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
HighCVSS 8.7No exploitEPSS 1%legion of the bouncy castle inc. · bc-javaApr 15, 2026
- CVE-2026-4167334Monitor
xmldom: Denial of service via uncontrolled recursion in XML serialization
HighCVSS 8.7No exploitEPSS 1%xmldom · xmldomMay 7, 2026
- CVE-2026-536734Monitor
Ovn: ovn: information disclosure via crafted dhcpv6 packets
HighCVSS 8.6No exploitEPSS 1%red hat · fast datapath for red hat enterprise linux 10Apr 24, 2026
- CVE-2026-1214334Monitor
form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
HighCVSS 8.7No exploitEPSS 1%form-data · form-dataJun 12, 2026
- CVE-2026-4167234Monitor
xmldom: XML node injection through unvalidated comment serialization
HighCVSS 8.7No exploitEPSS 1%xmldom · xmldomMay 7, 2026
- CVE-2026-4167534Monitor
xmldom: XML node injection through unvalidated processing instruction serialization
HighCVSS 8.7No exploitEPSS 1%xmldom · xmldomMay 7, 2026
- CVE-2026-071934Monitor
Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication
HighCVSS 8.6No exploitEPSS 1%red hat · red hat enterprise linux 10Jan 8, 2026
- CVE-2026-1064934Monitor
Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression
HighCVSS 8.6No exploitEPSS 1%red hat · red hat enterprise linux 10Jun 16, 2026
- CVE-2026-4116334Monitor
bubblewrap vulnerable to privilege escalation in setuid mode via ptrace
HighCVSS 8.7No exploitEPSS 0%containers · bubblewrapMay 9, 2026
- CVE-2025-1387833Monitor
Malformed BRID/HHIT records can cause named to terminate unexpectedly
HighCVSS 7.5No exploitEPSS 9%isc · bind 9Jan 21, 2026
- CVE-2026-4652933Monitor
PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
HighCVSS 8.4Proof of conceptEPSS 0%mate-desktop · atrilJun 10, 2026
- CVE-2026-489233Monitor
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with
HighCVSS 8.4No exploitEPSS 0%dnsmasq · dnsmasqMay 11, 2026
- CVE-2026-5436933Monitor
acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
HighCVSS 8.4No exploitEPSS 0%acl project · aclJun 29, 2026