CVE-2026-41889 pgx: SQL Injection via placeholder confusion with dollar quoted string literals Microsoft Security 10 Mei 2026 om 10:03 Information published.
CVE-2026-33079 Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles Microsoft Security 10 Mei 2026 om 10:03 Information published.
CVE-2026-42501 Malicious module proxy can bypass checksum database in cmd/go Microsoft Security 10 Mei 2026 om 10:03 Information published.
CVE-2026-42499 Quadratic string concatenation in consumePhrase in net/mail Microsoft Security 10 Mei 2026 om 10:03 Information published.
CVE-2026-39836 Panic in Dial and LookupPort when handling NUL byte on Windows in net Microsoft Security 10 Mei 2026 om 10:03 Information published.
CVE-2026-39826 Escaper bypass leads to XSS in html/template Microsoft Security 10 Mei 2026 om 10:02 Information published.
CVE-2026-39825 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil Microsoft Security 10 Mei 2026 om 10:02 Information published.
CVE-2026-39823 Bypass of meta content URL escaping causes XSS in html/template Microsoft Security 10 Mei 2026 om 10:02 Information published.
CVE-2026-39820 Quadratic string concatentation in consumeComment in net/mail Microsoft Security 10 Mei 2026 om 10:02 Information published.
CVE-2026-39819 Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go Microsoft Security 10 Mei 2026 om 10:02 Information published.
CVE-2026-39817 Invoking "go tool pack" does not sanitize output paths in cmd/go Microsoft Security 10 Mei 2026 om 10:02 Information published.
CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net Microsoft Security 10 Mei 2026 om 10:02 Information published.
CVE-2026-33811 Crash when handling long CNAME response in net Microsoft Security 10 Mei 2026 om 10:01 Information published.
CVE-2026-44656 Vim: OS Command Injection via 'path' completion Microsoft Security 10 Mei 2026 om 10:01 Information published.
CVE-2026-45130 Vim: Heap Buffer Overflow in spell file loading Microsoft Security 10 Mei 2026 om 10:01 Information published.
CVE-2026-6666 PgBouncer crash in kill_pool_logins_server_error Microsoft Security 10 Mei 2026 om 10:01 Information published.
CVE-2026-6667 PgBouncer missing authorization check in KILL_CLIENT admin command Microsoft Security 10 Mei 2026 om 10:01 Information published.
CVE-2026-6665 PgBouncer buffer overflow in SCRAM Microsoft Security 10 Mei 2026 om 10:01 Information published.
CVE-2026-6664 PgBouncer integer overflow in PgBouncer network packet parsing Microsoft Security 10 Mei 2026 om 10:01 Information published.
CVE-2026-3832 Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response Microsoft Security 9 Mei 2026 om 10:39 Information published.
CVE-2026-4948 Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization Microsoft Security 9 Mei 2026 om 10:39 Information published.
CVE-2025-71289 fs/ntfs3: handle attr_set_size() errors when truncating files Microsoft Security 8 Mei 2026 om 10:44 Information published.
CVE-2026-43274 mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq() Microsoft Security 8 Mei 2026 om 10:44 Information published.
CVE-2026-43116 netfilter: ctnetlink: ensure safe access to master conntrack Microsoft Security 8 Mei 2026 om 10:44 Information published.
CVE-2026-43153 xfs: remove xfs_attr_leaf_hasname Microsoft Security 8 Mei 2026 om 10:43 Information published.
CVE-2025-71273 wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band() Microsoft Security 8 Mei 2026 om 10:43 Information published.
CVE-2026-43172 wifi: iwlwifi: fix 22000 series SMEM parsing Microsoft Security 8 Mei 2026 om 10:43 Information published.
CVE-2026-43245 ntfs: ->d_compare() must not block Microsoft Security 8 Mei 2026 om 10:43 Information published.
CVE-2026-43198 tcp: fix potential race in tcp_v6_syn_recv_sock() Microsoft Security 8 Mei 2026 om 10:43 Information published.