Sat, Jul 18 · 02:17 PM CDTCVE-2026-16117
10.0/10 · Must read/watchNVDvuln
Summary
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encoded form, and the prefix-rewrite step uses a literal string replace against the decod
CVECVE-2026-16117
SeverityCRITICAL
TypeNEW
PublishedSat, Jul 18 · 02:17 PM CDT
ModifiedSat, Jul 18 · 02:17 PM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49794
9.1/10 · Must read/watchNVDvuln
Summary
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or
CVECVE-2025-49794
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedSun, Jul 19 · 12:16 AM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49796
9.1/10 · Must read/watchNVDvuln
Summary
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive
CVECVE-2025-49796
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedSun, Jul 19 · 12:16 AM CDT
Sat, Jul 18 · 02:17 PM CDTCVE-2023-54366
8.8/10 · Worth your timeNVDvuln
Summary
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database access or unauthenticated users on publicly exposed instances can perform unrestricted operations on unprotected tables wi
CVECVE-2023-54366
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 02:17 PM CDT
ModifiedSat, Jul 18 · 02:17 PM CDT
Sat, Jul 18 · 02:17 PM CDTCVE-2024-58362
8.8/10 · Worth your timeNVDvuln
Summary
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. When a record access method defines a SIGNIN or SIGNUP query and the RPC API is exposed to untrusted users, an unauthentic
CVECVE-2024-58362
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 02:17 PM CDT
ModifiedSat, Jul 18 · 02:17 PM CDT
Wed, Nov 12 · 05:15 PM CSTCVE-2025-2843
8.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create
CVECVE-2025-2843
SeverityHIGH
TypeUPDATED
PublishedWed, Nov 12 · 05:15 PM CST
ModifiedSat, Jul 18 · 08:17 PM CDT
Sat, Jul 18 · 02:17 PM CDTCVE-2026-11826
8.8/10 · Worth your timeNVDvuln
Summary
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supplied buffer with no size parameter and no bounds check. In parseConfig() the function is invoked with the 100-byte heap-allocated MB_device.
CVECVE-2026-11826
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 02:17 PM CDT
ModifiedSat, Jul 18 · 02:17 PM CDT
Sat, Jul 18 · 11:16 AM CDTCVE-2026-16095
8.8/10 · Worth your timeNVDvuln
Summary
A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write. The attack may be performed from remote. This project is superseded by FreshTomato.
CVECVE-2026-16095
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 11:16 AM CDT
ModifiedSat, Jul 18 · 11:16 AM CDT
Sat, Jul 18 · 12:17 PM CDTCVE-2026-16096
8.8/10 · Worth your timeNVDvuln
Summary
A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This project is superseded by FreshTomato.
CVECVE-2026-16096
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 12:17 PM CDT
ModifiedSat, Jul 18 · 12:17 PM CDT
Sat, Jul 18 · 12:17 PM CDTCVE-2026-16097
8.8/10 · Worth your timeNVDvuln
Summary
A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato.
CVECVE-2026-16097
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 12:17 PM CDT
ModifiedSat, Jul 18 · 12:17 PM CDT
Tue, Jun 02 · 09:16 AM CDTCVE-2026-1784
8.8/10 · Worth your timeNVDvuln
Summary
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVECVE-2026-1784
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 02 · 09:16 AM CDT
ModifiedSun, Jul 19 · 08:16 AM CDT
Wed, May 27 · 02:17 PM CDTCVE-2026-45945
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix race condition during PASID entry replacement The Intel VT-d PASID table entry is 512 bits (64 bytes). When replacing an active PASID entry (e.g., during domain replacement), the current implementation calculates a new entry on the stac
CVECVE-2026-45945
SeverityHIGH
TypeUPDATED
PublishedWed, May 27 · 02:17 PM CDT
ModifiedSat, Jul 18 · 04:17 PM CDT
Mon, Dec 15 · 05:15 PM CSTCVE-2025-11393
8.7/10 · Worth your timeNVDvuln
Summary
A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user with
CVECVE-2025-11393
SeverityHIGH
TypeUPDATED
PublishedMon, Dec 15 · 05:15 PM CST
ModifiedSat, Jul 18 · 07:17 PM CDT
Sat, Jul 18 · 09:17 PM CDTCVE-2026-12228
8.7/10 · Worth your timeNVDvuln
Summary
A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.content` without server-side sanitization. When a victim opens the direct message (DM) thread, the messag
CVECVE-2026-12228
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 09:17 PM CDT
ModifiedSat, Jul 18 · 09:17 PM CDT
Sat, Jul 18 · 01:17 PM CDTCVE-2026-15631
8.7/10 · Worth your timeNVDvuln
Summary
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapses dot segments, so a
CVECVE-2026-15631
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 01:17 PM CDT
ModifiedSat, Jul 18 · 01:17 PM CDT
Sat, Jul 18 · 01:17 PM CDTCVE-2026-16158
8.7/10 · Worth your timeNVDvuln
Summary
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs. When getUpstream sel
CVECVE-2026-16158
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 01:17 PM CDT
ModifiedSat, Jul 18 · 01:17 PM CDT
Sat, Jul 18 · 02:17 PM CDTCVE-2024-58366
8.5/10 · Worth your timeNVDvuln
Summary
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
CVECVE-2024-58366
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 02:17 PM CDT
ModifiedSat, Jul 18 · 02:17 PM CDT
Tue, May 14 · 03:42 PM CDTCVE-2024-3727
8.3/10 · Worth your timeNVDvuln
Summary
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
CVECVE-2024-3727
SeverityHIGH
TypeUPDATED
PublishedTue, May 14 · 03:42 PM CDT
ModifiedSun, Jul 19 · 12:16 AM CDT
Sat, Jul 18 · 11:17 PM CDTCVE-2026-10130
8.2/10 · Worth your timeNVDvuln
Summary
QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The signup route unconditionally creates and links a new token to the matching Identity via a Cypher ME
CVECVE-2026-10130
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 11:17 PM CDT
ModifiedSat, Jul 18 · 11:17 PM CDT
Sat, Jul 18 · 02:17 PM CDTCVE-2026-9323
8.1/10 · Worth your timeNVDvuln
Summary
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twister PRNG, which is not cryptographically secure. Each call consumes approximately 30 bits of PRNG state, and the Mersenne
CVECVE-2026-9323
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 02:17 PM CDT
ModifiedSat, Jul 18 · 02:17 PM CDT
Mon, Jun 09 · 08:15 PM CDTCVE-2025-5914
7.8/10 · Worth your timeNVDvuln
Summary
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to
CVECVE-2025-5914
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 09 · 08:15 PM CDT
ModifiedSun, Jul 19 · 12:16 AM CDT
Tue, Jun 17 · 01:15 PM CDTCVE-2025-6020
7.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
CVECVE-2025-6020
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 17 · 01:15 PM CDT
ModifiedSun, Jul 19 · 09:16 AM CDT
Thu, Jul 10 · 02:15 PM CDTCVE-2025-7425
7.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, caus
CVECVE-2025-7425
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 10 · 02:15 PM CDT
ModifiedSun, Jul 19 · 12:16 AM CDT
Wed, May 27 · 02:17 PM CDTCVE-2026-46093
7.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: take vmap_purge_lock in shrinker decay_va_pool_node() can be invoked concurrently from two paths: __purge_vmap_area_lazy() when pools are being purged, and the shrinker via vmap_node_shrink_scan(). However, decay_va_pool_node() is not safe
CVECVE-2026-46093
SeverityHIGH
TypeUPDATED
PublishedWed, May 27 · 02:17 PM CDT
ModifiedSat, Jul 18 · 04:17 PM CDT
Sat, Jul 18 · 01:17 PM CDTCVE-2026-9147
7.8/10 · Worth your timeNVDvuln
Summary
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the generated Python source without safe quoting via repr() or the !r format specifier. An
CVECVE-2026-9147
SeverityHIGH
TypeNEW
PublishedSat, Jul 18 · 01:17 PM CDT
ModifiedSat, Jul 18 · 01:17 PM CDT