Fri, May 22 · 04:16 AM CDTCVE-2026-46595
10.0/10 · Must read/watchNVDvuln
Summary
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVECVE-2026-46595
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedFri, Jul 17 · 01:18 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33815
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33815
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33816
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33816
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Wed, Apr 08 · 09:17 PM CDTCVE-2026-39892
9.8/10 · Must read/watchNVDvuln
Summary
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
CVECVE-2026-39892
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 08 · 09:17 PM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Fri, Jun 12 · 09:16 PM CDTCVE-2026-44990
9.3/10 · Must read/watchNVDvuln
Summary
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This i
CVECVE-2026-44990
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jun 12 · 09:16 PM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39832
9.1/10 · Must read/watchNVDvuln
Summary
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. A
CVECVE-2026-39832
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Fri, May 29 · 08:16 PM CDTCVE-2026-44421
8.8/10 · Worth your timeNVDvuln
Summary
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX, but then performs
CVECVE-2026-44421
SeverityHIGH
TypeUPDATED
PublishedFri, May 29 · 08:16 PM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Wed, Jun 24 · 05:17 PM CDTCVE-2026-52968
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic kvm_s390_pci_aif_enable(), kvm_s390_pci_aif_disable(), and aen_host_forward() index the GAIT by manually multiplying the index with sizeof(struct zpci_gaite). Since aift->
CVECVE-2026-52968
SeverityHIGH
TypeUPDATED
PublishedWed, Jun 24 · 05:17 PM CDT
ModifiedSat, Jul 18 · 08:16 AM CDT
Thu, Jun 25 · 09:16 AM CDTCVE-2026-53159
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA address corruption due to find_vma misuse fastrpc_get_args() uses find_vma() to look up the VMA for a user-provided pointer and compute a DMA address offset. When the address falls in a gap before the returned VMA, (ptr & PAGE_MA
CVECVE-2026-53159
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 25 · 09:16 AM CDT
ModifiedSat, Jul 18 · 08:16 AM CDT
Fri, Jun 26 · 08:17 PM CDTCVE-2026-53281
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption Commit 60f030f7418d ("iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE") fixed a NULL pointer dereference in an unlikely situation partly. If dev_pasid is not found in the dev_pasids lis
CVECVE-2026-53281
SeverityHIGH
TypeUPDATED
PublishedFri, Jun 26 · 08:17 PM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Thu, May 14 · 02:16 PM CDTCVE-2026-6473
8.8/10 · Worth your timeNVDvuln
Summary
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant d
CVECVE-2026-6473
SeverityHIGH
TypeUPDATED
PublishedThu, May 14 · 02:16 PM CDT
ModifiedFri, Jul 17 · 01:19 PM CDT
Thu, May 14 · 02:16 PM CDTCVE-2026-6477
8.8/10 · Worth your timeNVDvuln
Summary
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length
CVECVE-2026-6477
SeverityHIGH
TypeUPDATED
PublishedThu, May 14 · 02:16 PM CDT
ModifiedFri, Jul 17 · 01:19 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44494
8.7/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepti
CVECVE-2026-44494
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Tue, Jun 16 · 05:16 PM CDTCVE-2026-10649
8.6/10 · Worth your timeNVDvuln
Summary
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in th
CVECVE-2026-10649
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 16 · 05:16 PM CDT
ModifiedFri, Jul 17 · 01:17 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44492
8.6/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes throug
CVECVE-2026-44492
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Mon, May 11 · 11:19 PM CDTCVE-2026-34963
8.4/10 · Worth your timeNVDvuln
Summary
barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithmetic on section VirtualAddress and size values allows undersized heap allocation, and PE section loading logic fails to v
CVECVE-2026-34963
SeverityHIGH
TypeUPDATED
PublishedMon, May 11 · 11:19 PM CDT
ModifiedSat, Jul 18 · 03:16 AM CDT
Tue, May 14 · 03:42 PM CDTCVE-2024-3727
8.3/10 · Worth your timeNVDvuln
Summary
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
CVECVE-2024-3727
SeverityHIGH
TypeUPDATED
PublishedTue, May 14 · 03:42 PM CDT
ModifiedSat, Jul 18 · 10:17 AM CDT
Wed, Apr 08 · 02:16 AM CDTCVE-2026-33810
8.2/10 · Worth your timeNVDvuln
Summary
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in th
CVECVE-2026-33810
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedFri, Jul 17 · 01:18 PM CDT
Fri, Apr 24 · 06:16 PM CDTCVE-2026-41678
8.1/10 · Worth your timeNVDvuln
Summary
rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 = in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or below the
CVECVE-2026-41678
SeverityHIGH
TypeUPDATED
PublishedFri, Apr 24 · 06:16 PM CDT
ModifiedFri, Jul 17 · 07:24 PM CDT
Thu, Jun 11 · 07:16 AM CDTCVE-2026-41699
8.1/10 · Worth your timeNVDvuln
Summary
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can be
CVECVE-2026-41699
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 07:16 AM CDT
ModifiedFri, Jul 17 · 08:41 PM CDT