Patch Day month
August 2026 vulnerabilities
A server-rendered hunting trail for August 2026: 1,834 returned patch records across 4 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.
1,834all patches
57critical
0exploitation detected
1in CISA KEV
293tracked here
Microsoft 1,222Red Hat 581Cisco 30Android 1
Page 10 of 10 · records 1,801–1,834 of 1,834
Microsoft Security Response Center
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2024-49987 ↗2024-11-12azl3 kernel 6.6.57.1-2 on Azure Linux 3.0ModerateOut-of-band—bpftool: Fix undefined behavior in qsort(NULL 0 ...)
CVE-2024-49988 ↗2024-11-12azl3 kernel 6.6.57.1-2 on Azure Linux 3.0ModerateOut-of-band—ksmbd: add refcnt to ksmbd_conn struct
CVE-2024-47678 ↗2024-11-09azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-band—icmp: change the order of rate limits
CVE-2024-47683 ↗2024-11-09azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: Skip Recompute DSC Params if no Stream on Link
CVE-2024-47704 ↗2024-11-09azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: Check link_res->hpo_dp_link_enc before using it
CVE-2024-47728 ↗2024-11-09azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-band—bpf: Zero former ARG_PTR_TO_{LONGINT} args in case of error
CVE-2024-47738 ↗2024-11-09azl3 kernel 6.6.56.1-5 on Azure Linux 3.0LowOut-of-band—wifi: mac80211: don't use rate mask for offchannel TX either
CVE-2024-47745 ↗2024-11-09azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ImportantOut-of-band—mm: call the security_mmap_file() LSM hook in remap_file_pages()
CVE-2024-49859 ↗2024-11-09azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-band—f2fs: fix to check atomic_file in f2fs ioctl interfaces
CVE-2024-49861 ↗2024-11-09azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ImportantOut-of-band—bpf: Fix helper writes to read-only maps
CVE-2024-49905 ↗2024-11-09azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: Add null check for 'afb' in amdgpu_dm_plane_handle_cursor_update (v2)
CVE-2024-49912 ↗2024-11-09azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-band—drm/amd/display: Handle null 'stream_status' in 'planes_changed_for_existing_stream'
CVE-2024-50061 ↗2024-11-09azl3 kernel 6.6.57.1-1 on Azure Linux 3.0ImportantOut-of-band—i3c: master: cdns: Fix use after free vulnerability in cdns_i3c_master Driver Due to Race Condition
CVE-2024-46678 ↗2024-10-16azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-band—bonding: change ipsec_lock from spin lock to mutex
CVE-2024-46762 ↗2024-10-16azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-band—xen: privcmd: Fix possible access to a freed kirqfd instance
CVE-2024-46765 ↗2024-10-16azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-band—ice: protect XDP configuration with a mutex
CVE-2024-46803 ↗2024-10-16azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-band—drm/amdkfd: Check debug trap enable before write dbg_ev_file
CVE-2024-27005 ↗2024-09-11azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-band—interconnect: Don't access req_list while it's being manipulated
CVE-2024-35794 ↗2024-09-11azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-band—dm-raid: really frozen sync_thread during suspend
CVE-2024-35808 ↗2024-09-11azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-band—md/dm-raid: don't call md_reap_sync_thread() directly
CVE-2024-42067 ↗2024-08-16azl3 kernel 6.6.43.1-7 on Azure Linux 3.0ModerateOut-of-band—bpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro()
CVE-2023-38325 ↗2024-06-30azl3 python-cryptography 3.3.2-5 on Azure Linux 3.0ImportantOut-of-band—The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
CVE-2024-1151 ↗2024-06-30azl3 hyperv-daemons 6.6.22.1-2 on Azure Linux 3.0ModerateOut-of-band—Kernel: stack overflow problem in open vswitch kernel module leading to dos
CVE-2024-36009 ↗2024-05-23azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-band—ax25: Fix netdev refcount issue
CVE-2024-34251 ↗2024-05-13azl3 fluent-bit 3.1.9-4 on Azure Linux 3.0ImportantOut-of-band—An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h.
CVE-2023-4133 ↗2024-05-03cbl2 hyperv-daemons 5.15.180.1-1ModerateOut-of-band—Kernel: cxgb4: use-after-free in ch_flower_stats_cb()
CVE-2023-0567 ↗2023-03-01azl3 php 8.3.19-1 on Azure Linux 3.0ImportantOut-of-band—password_verify() always returns true for some invalid hashes
CVE-2022-38725 ↗2023-02-04azl3 syslog-ng 4.3.1-3 on Azure Linux 3.0ImportantOut-of-band—An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.
CVE-2020-29509 ↗2021-12-16azl3 golang 1.24.3-1 on Azure Linux 3.0ModerateOut-of-band—The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
CVE-2020-29511 ↗2021-12-16azl3 golang 1.24.3-1 on Azure Linux 3.0ModerateOut-of-band—The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
CVE-2021-33560 ↗2021-06-16cm1 libgcrypt 1.8.7-2 on CBL Mariner 1.0ImportantOut-of-band—Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm and the window size is not chosen appropriately. This for example affects use of ElGamal in OpenPGP.
CVE-2021-20227 ↗2021-03-27sqlite-3.34.1-1.cm1.x86_64.rpm on CBL Mariner 1.0 x64ModerateOut-of-band—A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
CVE-2020-15358 ↗2021-02-11cm1 mysql 8.0.26-1 on CBL Mariner 1.0ModerateOut-of-band—In SQLite before 3.32.3 select.c mishandles query-flattener optimization leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
CVE-2019-6706 ↗2020-09-25cm1 lua 5.3.5-8 on CBL Mariner 1.0ImportantOut-of-band—Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
The next page could not be added in place. The ordinary page link remains available; try it again to navigate normally.