Thu, Apr 09 · 03:16 PM CDTCVE-2025-62718
9.9/10 · Must read/watchNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the config
CVECVE-2025-62718
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 09 · 03:16 PM CDT
ModifiedTue, Jul 21 · 12:17 PM CDT
Mon, Jan 19 · 06:16 PM CSTCVE-2026-22797
9.9/10 · Must read/watchNVDvuln
Summary
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such
CVECVE-2026-22797
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jan 19 · 06:16 PM CST
ModifiedTue, Jul 21 · 12:17 PM CDT
Fri, Apr 03 · 06:16 PM CDTCVE-2026-0545
9.8/10 · Must read/watchNVDvuln
Summary
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_JOB_EXECUTION=true`) and any job functio
CVECVE-2026-0545
SeverityCRITICAL
TypeUPDATED
PublishedFri, Apr 03 · 06:16 PM CDT
ModifiedTue, Jul 21 · 07:10 PM CDT
Fri, Jan 23 · 04:16 AM CSTCVE-2026-0770
9.8/10 · Must read/watchNVDvuln
Summary
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within th
CVECVE-2026-0770
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jan 23 · 04:16 AM CST
ModifiedWed, Jul 22 · 05:17 AM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedTue, Jul 21 · 12:17 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33815
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33815
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedTue, Jul 21 · 12:18 PM CDT
Wed, Apr 08 · 09:17 PM CDTCVE-2026-39892
9.8/10 · Must read/watchNVDvuln
Summary
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
CVECVE-2026-39892
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 08 · 09:17 PM CDT
ModifiedTue, Jul 21 · 12:18 PM CDT
Fri, Feb 20 · 09:19 PM CSTCVE-2026-25896
9.3/10 · Must read/watchNVDvuln
Summary
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&
CVECVE-2026-25896
SeverityCRITICAL
TypeUPDATED
PublishedFri, Feb 20 · 09:19 PM CST
ModifiedTue, Jul 21 · 12:17 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedTue, Jul 21 · 12:18 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33210
9.1/10 · Must read/watchNVDvuln
Summary
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This i
CVECVE-2026-33210
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedTue, Jul 21 · 12:18 PM CDT
Tue, May 12 · 05:16 PM CDTCVE-2025-35990
8.8/10 · Worth your timeNVDvuln
Summary
Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This r
CVECVE-2025-35990
SeverityHIGH
TypeUPDATED
PublishedTue, May 12 · 05:16 PM CDT
ModifiedTue, Jul 21 · 03:42 PM CDT
Wed, Mar 25 · 06:16 PM CDTCVE-2025-67030
8.8/10 · Worth your timeNVDvuln
Summary
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
CVECVE-2025-67030
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 25 · 06:16 PM CDT
ModifiedTue, Jul 21 · 12:17 PM CDT
Wed, Jan 21 · 10:15 PM CSTCVE-2026-22807
8.8/10 · Worth your timeNVDvuln
Summary
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_code`, allowing attacker-controlled Python code in a model repo/path to execute at
CVECVE-2026-22807
SeverityHIGH
TypeUPDATED
PublishedWed, Jan 21 · 10:15 PM CST
ModifiedTue, Jul 21 · 12:17 PM CDT
Fri, Apr 03 · 02:16 PM CDTCVE-2026-23425
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix ID register initialization for non-protected pKVM guests In protected mode, the hypervisor maintains a separate instance of the `kvm` structure for each VM. For non-protected VMs, this structure is initialized from the host's `kvm` stat
CVECVE-2026-23425
SeverityHIGH
TypeUPDATED
PublishedFri, Apr 03 · 02:16 PM CDT
ModifiedTue, Jul 21 · 07:10 PM CDT
Fri, Mar 27 · 12:16 AM CDTCVE-2026-27893
8.8/10 · Worth your timeNVDvuln
Summary
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote
CVECVE-2026-27893
SeverityHIGH
TypeUPDATED
PublishedFri, Mar 27 · 12:16 AM CDT
ModifiedTue, Jul 21 · 12:17 PM CDT
Mon, Mar 16 · 02:19 PM CDTCVE-2026-3083
8.8/10 · Worth your timeNVDvuln
Summary
GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation
CVECVE-2026-3083
SeverityHIGH
TypeUPDATED
PublishedMon, Mar 16 · 02:19 PM CDT
ModifiedTue, Jul 21 · 12:18 PM CDT
Mon, Mar 16 · 02:19 PM CDTCVE-2026-3085
8.8/10 · Worth your timeNVDvuln
Summary
GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the impleme
CVECVE-2026-3085
SeverityHIGH
TypeUPDATED
PublishedMon, Mar 16 · 02:19 PM CDT
ModifiedTue, Jul 21 · 12:18 PM CDT
Wed, May 13 · 04:16 PM CDTCVE-2026-44293
8.8/10 · Worth your timeNVDvuln
Summary
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field
CVECVE-2026-44293
SeverityHIGH
TypeUPDATED
PublishedWed, May 13 · 04:16 PM CDT
ModifiedTue, Jul 21 · 12:18 PM CDT
Fri, Mar 27 · 05:16 PM CDTCVE-2026-28369
8.7/10 · Worth your timeNVDvuln
Summary
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Reque
CVECVE-2026-28369
SeverityHIGH
TypeUPDATED
PublishedFri, Mar 27 · 05:16 PM CDT
ModifiedWed, Jul 22 · 06:16 AM CDT
Tue, Jan 27 · 01:16 AM CSTCVE-2026-24486
8.6/10 · Worth your timeNVDvuln
Summary
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious fil
CVECVE-2026-24486
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 27 · 01:16 AM CST
ModifiedTue, Jul 21 · 12:17 PM CDT
Wed, Apr 08 · 02:16 AM CDTCVE-2026-33810
8.2/10 · Worth your timeNVDvuln
Summary
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in th
CVECVE-2026-33810
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedTue, Jul 21 · 12:18 PM CDT
Tue, Apr 28 · 10:16 AM CDTCVE-2026-41604
8.2/10 · Worth your timeNVDvuln
Summary
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVECVE-2026-41604
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 28 · 10:16 AM CDT
ModifiedTue, Jul 21 · 12:18 PM CDT
Fri, Apr 03 · 04:16 PM CDTCVE-2026-31392
8.1/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix krb5 mount with username option Customer reported that some of their krb5 mounts were failing against a single server as the client was trying to mount the shares with wrong credentials. It turned out the client was reusing SMB session
CVECVE-2026-31392
SeverityHIGH
TypeUPDATED
PublishedFri, Apr 03 · 04:16 PM CDT
ModifiedTue, Jul 21 · 07:10 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33236
8.1/10 · Worth your timeNVDvuln
Summary
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the `subdir` and `id` attributes when processing remote XML index files. Attackers can
CVECVE-2026-33236
SeverityHIGH
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedTue, Jul 21 · 12:18 PM CDT
Fri, Apr 03 · 08:16 AM CDTCVE-2026-4350
8.1/10 · Worth your timeNVDvuln
Summary
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verification. The unsaniti
CVECVE-2026-4350
SeverityHIGH
TypeUPDATED
PublishedFri, Apr 03 · 08:16 AM CDT
ModifiedTue, Jul 21 · 07:10 PM CDT