Mon, Jun 01 · 10:16 PM CDTCVE-2026-40965
10.0/10 · Must read/watchNVDvuln
Summary
Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JWT token verification
CVECVE-2026-40965
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 01 · 10:16 PM CDT
ModifiedWed, Jul 22 · 06:10 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-46595
10.0/10 · Must read/watchNVDvuln
Summary
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVECVE-2026-46595
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedWed, Jul 22 · 12:18 PM CDT
Mon, Jan 19 · 06:16 PM CSTCVE-2026-22797
9.9/10 · Must read/watchNVDvuln
Summary
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such
CVECVE-2026-22797
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jan 19 · 06:16 PM CST
ModifiedWed, Jul 22 · 12:17 PM CDT
Sun, May 10 · 05:16 AM CDTCVE-2026-6722
9.8/10 · Must read/watchNVDvuln
Summary
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second en
CVECVE-2026-6722
SeverityCRITICAL
TypeUPDATED
PublishedSun, May 10 · 05:16 AM CDT
ModifiedWed, Jul 22 · 12:18 PM CDT
Thu, May 07 · 01:16 PM CDTCVE-2026-8091
9.8/10 · Must read/watchNVDvuln
Summary
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.
CVECVE-2026-8091
SeverityCRITICAL
TypeUPDATED
PublishedThu, May 07 · 01:16 PM CDT
ModifiedWed, Jul 22 · 12:18 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedWed, Jul 22 · 12:17 PM CDT
Wed, May 13 · 04:16 PM CDTCVE-2026-42557
9.6/10 · Must read/watchNVDvuln
Summary
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.b
CVECVE-2026-42557
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 04:16 PM CDT
ModifiedWed, Jul 22 · 12:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39832
9.1/10 · Must read/watchNVDvuln
Summary
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. A
CVECVE-2026-39832
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedWed, Jul 22 · 12:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedWed, Jul 22 · 12:17 PM CDT
Mon, Jun 01 · 10:16 PM CDTCVE-2026-10292
8.8/10 · Worth your timeNVDvuln
Summary
A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcpy of the file /goform/formTaskEdit. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
CVECVE-2026-10292
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 01 · 10:16 PM CDT
ModifiedWed, Jul 22 · 06:10 PM CDT
Mon, Jun 01 · 10:16 PM CDTCVE-2026-10293
8.8/10 · Worth your timeNVDvuln
Summary
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/formFireWall. This manipulation of the argument Profile causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
CVECVE-2026-10293
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 01 · 10:16 PM CDT
ModifiedWed, Jul 22 · 06:10 PM CDT
Tue, May 05 · 08:16 PM CDTCVE-2026-35397
8.8/10 · Worth your timeNVDvuln
Summary
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the root_dir. For example, with a root_dir na
CVECVE-2026-35397
SeverityHIGH
TypeUPDATED
PublishedTue, May 05 · 08:16 PM CDT
ModifiedWed, Jul 22 · 12:17 PM CDT
Wed, May 13 · 04:16 PM CDTCVE-2026-42266
8.8/10 · Worth your timeNVDvuln
Summary
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manage
CVECVE-2026-42266
SeverityHIGH
TypeUPDATED
PublishedWed, May 13 · 04:16 PM CDT
ModifiedWed, Jul 22 · 12:17 PM CDT
Wed, May 06 · 10:16 AM CDTCVE-2026-43112
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., "/"), the current logic attempts to check *(cursor2 - 1) before cursor2 has advanced.
CVECVE-2026-43112
SeverityHIGH
TypeUPDATED
PublishedWed, May 06 · 10:16 AM CDT
ModifiedWed, Jul 22 · 12:17 PM CDT
Wed, May 13 · 04:16 PM CDTCVE-2026-44293
8.8/10 · Worth your timeNVDvuln
Summary
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field
CVECVE-2026-44293
SeverityHIGH
TypeUPDATED
PublishedWed, May 13 · 04:16 PM CDT
ModifiedWed, Jul 22 · 12:18 PM CDT
Mon, Jun 01 · 11:16 PM CDTCVE-2019-25718
8.4/10 · Worth your timeNVDvuln
Summary
Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display i
CVECVE-2019-25718
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 01 · 11:16 PM CDT
ModifiedWed, Jul 22 · 06:10 PM CDT
Wed, Apr 08 · 02:16 AM CDTCVE-2026-33810
8.2/10 · Worth your timeNVDvuln
Summary
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in th
CVECVE-2026-33810
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedWed, Jul 22 · 12:17 PM CDT
Tue, Apr 28 · 10:16 AM CDTCVE-2026-41604
8.2/10 · Worth your timeNVDvuln
Summary
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVECVE-2026-41604
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 28 · 10:16 AM CDT
ModifiedWed, Jul 22 · 12:17 PM CDT
Tue, May 26 · 10:16 PM CDTCVE-2026-42013
8.2/10 · Worth your timeNVDvuln
Summary
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-
CVECVE-2026-42013
SeverityHIGH
TypeUPDATED
PublishedTue, May 26 · 10:16 PM CDT
ModifiedWed, Jul 22 · 04:17 PM CDT
Mon, Jun 01 · 10:16 PM CDTCVE-2026-49491
8.2/10 · Worth your timeNVDvuln
Summary
Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email address
CVECVE-2026-49491
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 01 · 10:16 PM CDT
ModifiedWed, Jul 22 · 06:10 PM CDT
Tue, May 26 · 10:16 PM CDTCVE-2026-5260
8.2/10 · Worth your timeNVDvuln
Summary
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.
CVECVE-2026-5260
SeverityHIGH
TypeUPDATED
PublishedTue, May 26 · 10:16 PM CDT
ModifiedWed, Jul 22 · 04:18 PM CDT
Fri, May 22 · 02:16 PM CDTCVE-2026-9277
8.1/10 · Worth your timeNVDvuln
Summary
shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.op` therefore passed throu
CVECVE-2026-9277
SeverityHIGH
TypeUPDATED
PublishedFri, May 22 · 02:16 PM CDT
ModifiedWed, Jul 22 · 12:18 PM CDT
Mon, Jun 01 · 10:16 PM CDTCVE-2026-0095
8.0/10 · Worth your timeNVDvuln
Summary
In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVE-2026-0095
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 01 · 10:16 PM CDT
ModifiedWed, Jul 22 · 05:10 PM CDT
Mon, Jun 01 · 10:16 PM CDTCVE-2026-0097
8.0/10 · Worth your timeNVDvuln
Summary
In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVE-2026-0097
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 01 · 10:16 PM CDT
ModifiedWed, Jul 22 · 05:10 PM CDT
Wed, Jun 28 · 09:15 PM CDTCVE-2023-3390
7.8/10 · Worth your timeNVDvuln
Summary
A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user acce
CVECVE-2023-3390
SeverityHIGH
TypeUPDATED
PublishedWed, Jun 28 · 09:15 PM CDT
ModifiedWed, Jul 22 · 12:16 PM CDT