Fri, May 22 · 04:16 AM CDTCVE-2026-46595
10.0/10 · Must read/watchNVDvuln
Summary
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVECVE-2026-46595
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedMon, Jul 27 · 01:18 PM CDT
Mon, Apr 14 · 07:15 PM CDTCVE-2025-1782
9.9/10 · Must read/watchNVDvuln
Summary
In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web server user. This flaw requires the attacker to be authenticated with a valid user accoun
CVECVE-2025-1782
SeverityCRITICAL
TypeUPDATED
PublishedMon, Apr 14 · 07:15 PM CDT
ModifiedMon, Jul 27 · 05:16 PM CDT
Mon, Jan 19 · 06:16 PM CSTCVE-2026-22797
9.9/10 · Must read/watchNVDvuln
Summary
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such
CVECVE-2026-22797
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jan 19 · 06:16 PM CST
ModifiedMon, Jul 27 · 01:17 PM CDT
Wed, Feb 25 · 11:16 PM CSTCVE-2026-27577
9.9/10 · Must read/watchNVDvuln
Summary
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user with permission to create or modify workflows could abuse crafted expressions in wor
CVECVE-2026-27577
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 25 · 11:16 PM CST
ModifiedTue, Jul 28 · 05:17 AM CDT
Tue, May 26 · 02:16 PM CDTCVE-2026-7374
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container r
CVECVE-2026-7374
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 26 · 02:16 PM CDT
ModifiedMon, Jul 27 · 02:17 PM CDT
Sat, Jul 19 · 12:15 PM CDTCVE-2015-10138
9.8/10 · Must read/watchNVDvuln
Summary
The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sit
CVECVE-2015-10138
SeverityCRITICAL
TypeUPDATED
PublishedSat, Jul 19 · 12:15 PM CDT
ModifiedMon, Jul 27 · 03:48 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33815
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33815
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedMon, Jul 27 · 01:17 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33816
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33816
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedMon, Jul 27 · 01:17 PM CDT
Wed, Jan 07 · 05:15 PM CSTCVE-2025-12543
9.6/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling at
CVECVE-2025-12543
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 07 · 05:15 PM CST
ModifiedMon, Jul 27 · 04:16 PM CDT
Tue, Mar 24 · 12:16 AM CDTCVE-2026-33211
9.6/10 · Must read/watchNVDvuln
Summary
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `Resolut
CVECVE-2026-33211
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 24 · 12:16 AM CDT
ModifiedMon, Jul 27 · 01:17 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedMon, Jul 27 · 01:17 PM CDT
Thu, May 07 · 11:16 PM CDTCVE-2026-42880
9.6/10 · Must read/watchNVDvuln
Summary
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data f
CVECVE-2026-42880
SeverityCRITICAL
TypeUPDATED
PublishedThu, May 07 · 11:16 PM CDT
ModifiedMon, Jul 27 · 01:18 PM CDT
Wed, Apr 15 · 08:16 PM CDTCVE-2025-41118
9.1/10 · Must read/watchNVDvuln
Summary
Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Pyroscope API. To exploi
CVECVE-2025-41118
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 15 · 08:16 PM CDT
ModifiedMon, Jul 27 · 01:16 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedMon, Jul 27 · 01:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedMon, Jul 27 · 01:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39832
9.1/10 · Must read/watchNVDvuln
Summary
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. A
CVECVE-2026-39832
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedMon, Jul 27 · 01:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedMon, Jul 27 · 01:18 PM CDT
Thu, May 21 · 09:16 AM CDTCVE-2026-5433
9.1/10 · Must read/watchNVDvuln
Summary
Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE). Honeywell recommends updating to the most recent version of this product, service or offering [
CVECVE-2026-5433
SeverityCRITICAL
TypeUPDATED
PublishedThu, May 21 · 09:16 AM CDT
ModifiedMon, Jul 27 · 03:17 PM CDT
Mon, Sep 20 · 04:15 PM CDTCVE-2021-39537
8.8/10 · Worth your timeNVDvuln
Summary
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
CVECVE-2021-39537
SeverityHIGH
TypeUPDATED
PublishedMon, Sep 20 · 04:15 PM CDT
ModifiedMon, Jul 27 · 01:43 PM CDT
Tue, Jan 27 · 04:16 PM CSTCVE-2025-15467
8.8/10 · Worth your timeNVDvuln
Summary
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structure
CVECVE-2025-15467
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 27 · 04:16 PM CST
ModifiedMon, Jul 27 · 01:16 PM CDT
Tue, Jun 02 · 09:16 AM CDTCVE-2026-1784
8.8/10 · Worth your timeNVDvuln
Summary
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVECVE-2026-1784
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 02 · 09:16 AM CDT
ModifiedMon, Jul 27 · 01:16 PM CDT
Tue, May 26 · 03:16 PM CDTCVE-2026-40033
8.8/10 · Worth your timeNVDvuln
Summary
FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling
CVECVE-2026-40033
SeverityHIGH
TypeUPDATED
PublishedTue, May 26 · 03:16 PM CDT
ModifiedMon, Jul 27 · 01:17 PM CDT
Wed, May 13 · 04:16 PM CDTCVE-2026-44293
8.8/10 · Worth your timeNVDvuln
Summary
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field
CVECVE-2026-44293
SeverityHIGH
TypeUPDATED
PublishedWed, May 13 · 04:16 PM CDT
ModifiedMon, Jul 27 · 01:18 PM CDT
Fri, May 29 · 08:16 PM CDTCVE-2026-44420
8.8/10 · Worth your timeNVDvuln
Summary
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server process (remote DoS) and ma
CVECVE-2026-44420
SeverityHIGH
TypeUPDATED
PublishedFri, May 29 · 08:16 PM CDT
ModifiedMon, Jul 27 · 01:18 PM CDT
Fri, May 29 · 08:16 PM CDTCVE-2026-44421
8.8/10 · Worth your timeNVDvuln
Summary
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX, but then performs
CVECVE-2026-44421
SeverityHIGH
TypeUPDATED
PublishedFri, May 29 · 08:16 PM CDT
ModifiedMon, Jul 27 · 01:18 PM CDT