Fri, May 22 · 04:16 AM CDTCVE-2026-46595
10.0/10 · Must read/watchNVDvuln
Summary
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVECVE-2026-46595
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedThu, Jul 16 · 12:18 PM CDT
Fri, Jul 03 · 08:16 AM CDTCVE-2026-14544
9.8/10 · Must read/watchNVDvuln
Summary
A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted pr
CVECVE-2026-14544
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jul 03 · 08:16 AM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Tue, Jun 09 · 04:16 PM CDTCVE-2026-25089
9.8/10 · Must read/watchNVDvuln
Summary
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthentic
CVECVE-2026-25089
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jun 09 · 04:16 PM CDT
ModifiedFri, Jul 17 · 05:16 AM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedThu, Jul 16 · 12:17 PM CDT
Wed, Jul 08 · 10:17 PM CDTCVE-2026-31309
9.8/10 · Must read/watchNVDvuln
Summary
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.
CVECVE-2026-31309
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jul 08 · 10:17 PM CDT
ModifiedThu, Jul 16 · 01:16 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33815
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33815
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33816
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33816
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Tue, Apr 14 · 04:16 PM CDTCVE-2026-39808
9.8/10 · Must read/watchNVDvuln
Summary
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via
CVECVE-2026-39808
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 14 · 04:16 PM CDT
ModifiedFri, Jul 17 · 05:16 AM CDT
Tue, Jun 09 · 08:16 AM CDTCVE-2026-9698
9.8/10 · Must read/watchNVDvuln
Summary
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buffer overflow.
CVECVE-2026-9698
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jun 09 · 08:16 AM CDT
ModifiedThu, Jul 16 · 12:18 PM CDT
Tue, Jun 23 · 09:16 PM CDTCVE-2026-11807
9.6/10 · Must read/watchNVDvuln
Summary
A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials a
CVECVE-2026-11807
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jun 23 · 09:16 PM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Fri, Feb 20 · 09:19 PM CSTCVE-2026-25896
9.3/10 · Must read/watchNVDvuln
Summary
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&
CVECVE-2026-25896
SeverityCRITICAL
TypeUPDATED
PublishedFri, Feb 20 · 09:19 PM CST
ModifiedThu, Jul 16 · 12:17 PM CDT
Fri, Jun 12 · 09:16 PM CDTCVE-2026-44990
9.3/10 · Must read/watchNVDvuln
Summary
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This i
CVECVE-2026-44990
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jun 12 · 09:16 PM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39832
9.1/10 · Must read/watchNVDvuln
Summary
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. A
CVECVE-2026-39832
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Wed, Mar 25 · 06:16 PM CDTCVE-2025-67030
8.8/10 · Worth your timeNVDvuln
Summary
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
CVECVE-2025-67030
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 25 · 06:16 PM CDT
ModifiedThu, Jul 16 · 12:16 PM CDT
Tue, May 05 · 05:17 PM CDTCVE-2026-23479
8.8/10 · Worth your timeNVDvuln
Summary
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free tha
CVECVE-2026-23479
SeverityHIGH
TypeUPDATED
PublishedTue, May 05 · 05:17 PM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Tue, May 05 · 05:17 PM CDTCVE-2026-25243
8.8/10 · Worth your timeNVDvuln
Summary
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code exec
CVECVE-2026-25243
SeverityHIGH
TypeUPDATED
PublishedTue, May 05 · 05:17 PM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Tue, May 26 · 03:16 PM CDTCVE-2026-40033
8.8/10 · Worth your timeNVDvuln
Summary
FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling
CVECVE-2026-40033
SeverityHIGH
TypeUPDATED
PublishedTue, May 26 · 03:16 PM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Thu, Jun 25 · 09:16 AM CDTCVE-2026-53232
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: net: phy: clean the sfp upstream if phy probing fails Sashiko reported that we don't call sfp_bus_del_upstream() in the probe failure path, so let's add it, otherwise the sfp-bus is left with a dangling 'upstream' field, that may be used later on durin
CVECVE-2026-53232
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 25 · 09:16 AM CDT
ModifiedThu, Jul 16 · 12:18 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44494
8.7/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepti
CVECVE-2026-44494
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedThu, Jul 16 · 12:17 PM CDT
Mon, Mar 23 · 06:16 AM CDTCVE-2026-4601
8.7/10 · Worth your timeNVDvuln
Summary
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then s
CVECVE-2026-4601
SeverityHIGH
TypeUPDATED
PublishedMon, Mar 23 · 06:16 AM CDT
ModifiedThu, Jul 16 · 04:19 PM CDT
Tue, Jun 16 · 05:16 PM CDTCVE-2026-10649
8.6/10 · Worth your timeNVDvuln
Summary
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in th
CVECVE-2026-10649
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 16 · 05:16 PM CDT
ModifiedFri, Jul 17 · 06:16 AM CDT