Mon, Mar 30 · 08:16 AM CDTCVE-2025-15379
10.0/10 · Must read/watchNVDvuln
Summary
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model artifact's `python_env.yaml` file and directly int
CVECVE-2025-15379
SeverityCRITICAL
TypeUPDATED
PublishedMon, Mar 30 · 08:16 AM CDT
ModifiedFri, Sep 04 · 08:02 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-43997
10.0/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom). This vulnerability is fixed in 3.11.0.
CVECVE-2026-43997
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedFri, Sep 04 · 01:19 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-44005
10.0/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled JavaScript running i
CVECVE-2026-44005
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedFri, Sep 04 · 01:19 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-46595
10.0/10 · Must read/watchNVDvuln
Summary
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVECVE-2026-46595
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Sep 04 · 01:19 PM CDT
Thu, Apr 09 · 03:16 PM CDTCVE-2025-62718
9.9/10 · Must read/watchNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the config
CVECVE-2025-62718
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 09 · 03:16 PM CDT
ModifiedFri, Sep 04 · 01:18 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-43999
9.9/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads any module by name directly in the host context, completely bypassing vm2's builtin
CVECVE-2026-43999
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedFri, Sep 04 · 01:19 PM CDT
Fri, Jan 18 · 10:29 PM CSTCVE-2019-3773
9.8/10 · Must read/watchNVDvuln
Summary
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
CVECVE-2019-3773
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jan 18 · 10:29 PM CST
ModifiedFri, Sep 04 · 01:45 PM CDT
Mon, Apr 15 · 06:15 PM CDTCVE-2024-28056
9.8/10 · Must read/watchNVDvuln
Summary
Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and consequently sts:AssumeRoleWithWebIdentity wou
CVECVE-2024-28056
SeverityCRITICAL
TypeUPDATED
PublishedMon, Apr 15 · 06:15 PM CDT
ModifiedFri, Sep 04 · 02:13 PM CDT
Wed, Jan 28 · 04:16 PM CSTCVE-2025-61140
9.8/10 · Must read/watchNVDvuln
Summary
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
CVECVE-2025-61140
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 28 · 04:16 PM CST
ModifiedFri, Sep 04 · 01:17 PM CDT
Wed, Mar 11 · 05:16 PM CDTCVE-2025-67038
9.8/10 · Must read/watchNVDvuln
Summary
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected
CVECVE-2025-67038
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 11 · 05:16 PM CDT
ModifiedFri, Sep 04 · 09:17 PM CDT
Wed, Mar 11 · 05:16 PM CDTCVE-2025-67039
9.8/10 · Must read/watchNVDvuln
Summary
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.
CVECVE-2025-67039
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 11 · 05:16 PM CDT
ModifiedFri, Sep 04 · 09:17 PM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedFri, Sep 04 · 01:18 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33228
9.8/10 · Must read/watchNVDvuln
Summary
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__" ret
CVECVE-2026-33228
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedFri, Sep 04 · 01:18 PM CDT
Fri, Mar 27 · 09:17 PM CDTCVE-2026-33937
9.8/10 · Must read/watchNVDvuln
Summary
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a `NumberLiteral` AST node is emitted directly into the generated JavaScript without quoting or sa
CVECVE-2026-33937
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 27 · 09:17 PM CDT
ModifiedFri, Sep 04 · 01:19 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-44009
9.8/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
CVECVE-2026-44009
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedFri, Sep 04 · 01:19 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-45411
9.8/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the runtime and passed t
CVECVE-2026-45411
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedFri, Sep 04 · 01:19 PM CDT
Wed, Jan 07 · 05:15 PM CSTCVE-2025-12543
9.6/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling at
CVECVE-2025-12543
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 07 · 05:15 PM CST
ModifiedFri, Sep 04 · 08:17 PM CDT
Tue, Jun 09 · 10:16 AM CDTCVE-2025-10263
9.1/10 · Must read/watchNVDvuln
Summary
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.
CVECVE-2025-10263
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jun 09 · 10:16 AM CDT
ModifiedFri, Sep 04 · 01:17 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedFri, Sep 04 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Sep 04 · 01:19 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39832
9.1/10 · Must read/watchNVDvuln
Summary
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. A
CVECVE-2026-39832
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Sep 04 · 01:19 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Sep 04 · 01:19 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-44007
9.1/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. With access to vm2, the sandbox constructs a new inner NodeVM with its own unrestrict
CVECVE-2026-44007
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedFri, Sep 04 · 01:19 PM CDT
Thu, May 28 · 09:16 AM CDTCVE-2026-4408
9.0/10 · Must read/watchNVDvuln
Summary
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-c
CVECVE-2026-4408
SeverityCRITICAL
TypeUPDATED
PublishedThu, May 28 · 09:16 AM CDT
ModifiedFri, Sep 04 · 01:19 PM CDT
Wed, Feb 12 · 03:15 PM CSTCVE-2025-1244
8.8/10 · Worth your timeNVDvuln
Summary
A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.
CVECVE-2025-1244
SeverityHIGH
TypeUPDATED
PublishedWed, Feb 12 · 03:15 PM CST
ModifiedFri, Sep 04 · 03:17 PM CDT