Tue, May 26 · 02:16 PM CDTCVE-2026-7374
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container r
CVECVE-2026-7374
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 26 · 02:16 PM CDT
ModifiedTue, Jul 28 · 01:19 PM CDT
Wed, Jan 28 · 04:16 PM CSTCVE-2025-61140
9.8/10 · Must read/watchNVDvuln
Summary
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
CVECVE-2025-61140
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 28 · 04:16 PM CST
ModifiedTue, Jul 28 · 01:17 PM CDT
Tue, May 05 · 10:16 PM CDTCVE-2026-28780
9.8/10 · Must read/watchNVDvuln
Summary
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HT
CVECVE-2026-28780
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 05 · 10:16 PM CDT
ModifiedTue, Jul 28 · 01:17 PM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedTue, Jul 28 · 01:17 PM CDT
Wed, Apr 08 · 09:17 PM CDTCVE-2026-39892
9.8/10 · Must read/watchNVDvuln
Summary
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
CVECVE-2026-39892
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 08 · 09:17 PM CDT
ModifiedTue, Jul 28 · 01:18 PM CDT
Fri, May 29 · 08:16 PM CDTCVE-2026-45700
9.8/10 · Must read/watchNVDvuln
Summary
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against the caller-provided desti
CVECVE-2026-45700
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 29 · 08:16 PM CDT
ModifiedTue, Jul 28 · 01:18 PM CDT
Fri, Jun 12 · 10:16 AM CDTCVE-2026-49875
9.8/10 · Must read/watchNVDvuln
Summary
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
CVECVE-2026-49875
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jun 12 · 10:16 AM CDT
ModifiedTue, Jul 28 · 01:18 PM CDT
Thu, May 07 · 01:16 PM CDTCVE-2026-8094
9.8/10 · Must read/watchNVDvuln
Summary
Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
CVECVE-2026-8094
SeverityCRITICAL
TypeUPDATED
PublishedThu, May 07 · 01:16 PM CDT
ModifiedTue, Jul 28 · 01:19 PM CDT
Mon, Jun 15 · 04:16 PM CDTCVE-2026-9862
9.8/10 · Must read/watchNVDvuln
Summary
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
CVECVE-2026-9862
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 15 · 04:16 PM CDT
ModifiedTue, Jul 28 · 01:20 PM CDT
Wed, Jan 07 · 05:15 PM CSTCVE-2025-12543
9.6/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling at
CVECVE-2025-12543
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 07 · 05:15 PM CST
ModifiedTue, Jul 28 · 01:17 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedTue, Jul 28 · 01:18 PM CDT
Fri, Jun 12 · 09:16 PM CDTCVE-2026-44990
9.3/10 · Must read/watchNVDvuln
Summary
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This i
CVECVE-2026-44990
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jun 12 · 09:16 PM CDT
ModifiedTue, Jul 28 · 01:18 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedTue, Jul 28 · 01:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedTue, Jul 28 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedTue, Jul 28 · 01:18 PM CDT
Fri, Jun 12 · 06:16 PM CDTCVE-2026-44172
9.1/10 · Must read/watchNVDvuln
Summary
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_r
CVECVE-2026-44172
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jun 12 · 06:16 PM CDT
ModifiedTue, Jul 28 · 01:18 PM CDT
Thu, May 21 · 09:16 AM CDTCVE-2026-5433
9.1/10 · Must read/watchNVDvuln
Summary
Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE). Honeywell recommends updating to the most recent version of this product, service or offering [
CVECVE-2026-5433
SeverityCRITICAL
TypeUPDATED
PublishedThu, May 21 · 09:16 AM CDT
ModifiedTue, Jul 28 · 04:00 PM CDT
Wed, Jul 08 · 02:15 PM CDTCVE-2020-3973
8.8/10 · Worth your timeNVDvuln
Summary
The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.
CVECVE-2020-3973
SeverityHIGH
TypeUPDATED
PublishedWed, Jul 08 · 02:15 PM CDT
ModifiedTue, Jul 28 · 02:54 PM CDT
Tue, Jan 27 · 04:16 PM CSTCVE-2025-15467
8.8/10 · Worth your timeNVDvuln
Summary
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structure
CVECVE-2025-15467
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 27 · 04:16 PM CST
ModifiedTue, Jul 28 · 01:17 PM CDT
Wed, May 13 · 04:16 PM CDTCVE-2026-44293
8.8/10 · Worth your timeNVDvuln
Summary
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field
CVECVE-2026-44293
SeverityHIGH
TypeUPDATED
PublishedWed, May 13 · 04:16 PM CDT
ModifiedTue, Jul 28 · 01:18 PM CDT
Tue, Jun 09 · 05:17 PM CDTCVE-2026-45504
8.8/10 · Worth your timeNVDvuln
Summary
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVECVE-2026-45504
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 09 · 05:17 PM CDT
ModifiedTue, Jul 28 · 11:16 PM CDT
Mon, Jun 15 · 08:16 PM CDTCVE-2026-52720
8.8/10 · Worth your timeNVDvuln
Summary
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server a
CVECVE-2026-52720
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 15 · 08:16 PM CDT
ModifiedTue, Jul 28 · 07:17 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44494
8.7/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepti
CVECVE-2026-44494
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedTue, Jul 28 · 01:18 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44492
8.6/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes throug
CVECVE-2026-44492
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedTue, Jul 28 · 01:18 PM CDT
Fri, Jan 23 · 07:15 AM CSTCVE-2026-0603
8.3/10 · Worth your timeNVDvuln
Summary
A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as r
CVECVE-2026-0603
SeverityHIGH
TypeUPDATED
PublishedFri, Jan 23 · 07:15 AM CST
ModifiedTue, Jul 28 · 01:17 PM CDT