Thu, Apr 09 · 03:16 PM CDTCVE-2025-62718
9.9/10 · Must read/watchNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the config
CVECVE-2025-62718
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 09 · 03:16 PM CDT
ModifiedMon, Sep 07 · 01:17 PM CDT
Mon, Jan 19 · 06:16 PM CSTCVE-2026-22797
9.9/10 · Must read/watchNVDvuln
Summary
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such
CVECVE-2026-22797
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jan 19 · 06:16 PM CST
ModifiedMon, Sep 07 · 01:18 PM CDT
Wed, Jan 28 · 04:16 PM CSTCVE-2025-61140
9.8/10 · Must read/watchNVDvuln
Summary
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
CVECVE-2025-61140
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 28 · 04:16 PM CST
ModifiedMon, Sep 07 · 01:17 PM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedMon, Sep 07 · 01:18 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33815
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33815
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedMon, Sep 07 · 01:19 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33816
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33816
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedMon, Sep 07 · 01:19 PM CDT
Sat, Apr 18 · 05:16 PM CDTCVE-2026-41242
9.8/10 · Must read/watchNVDvuln
Summary
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.
CVECVE-2026-41242
SeverityCRITICAL
TypeUPDATED
PublishedSat, Apr 18 · 05:16 PM CDT
ModifiedMon, Sep 07 · 01:19 PM CDT
Wed, Jan 07 · 05:15 PM CSTCVE-2025-12543
9.6/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling at
CVECVE-2025-12543
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 07 · 05:15 PM CST
ModifiedMon, Sep 07 · 01:17 PM CDT
Tue, Mar 24 · 12:16 AM CDTCVE-2026-33211
9.6/10 · Must read/watchNVDvuln
Summary
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `Resolut
CVECVE-2026-33211
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 24 · 12:16 AM CDT
ModifiedMon, Sep 07 · 01:18 PM CDT
Fri, Feb 20 · 09:19 PM CSTCVE-2026-25896
9.3/10 · Must read/watchNVDvuln
Summary
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&
CVECVE-2026-25896
SeverityCRITICAL
TypeUPDATED
PublishedFri, Feb 20 · 09:19 PM CST
ModifiedMon, Sep 07 · 01:18 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedMon, Sep 07 · 01:18 PM CDT
Tue, May 05 · 04:16 PM CDTCVE-2026-43071
9.1/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two There is an OOB read problem on dentry_hashtable when user sets 'dhash_entries=1': BUG: unable to handle page fault for address: ffff888b30b774b0 #PF: supervisor read access in kernel mode #PF: error_co
CVECVE-2026-43071
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 05 · 04:16 PM CDT
ModifiedTue, Sep 08 · 09:18 AM CDT
Tue, Jan 27 · 04:16 PM CSTCVE-2025-15467
8.8/10 · Worth your timeNVDvuln
Summary
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structure
CVECVE-2025-15467
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 27 · 04:16 PM CST
ModifiedMon, Sep 07 · 01:17 PM CDT
Wed, Apr 08 · 02:16 AM CDTCVE-2026-27140
8.8/10 · Worth your timeNVDvuln
Summary
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
CVECVE-2026-27140
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedMon, Sep 07 · 01:18 PM CDT
Wed, Apr 16 · 03:16 PM CDTCVE-2025-22108
8.6/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Mask the bd_cnt field in the TX BD properly The bd_cnt field in the TX BD specifies the total number of BDs for the TX packet. The bd_cnt field has 5 bits and the maximum number supported is 32 with the value 0. CONFIG_MAX_SKB_FRAGS can be mod
CVECVE-2025-22108
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 16 · 03:16 PM CDT
ModifiedMon, Sep 07 · 04:17 PM CDT
Thu, Feb 05 · 04:15 AM CSTCVE-2025-61732
8.6/10 · Worth your timeNVDvuln
Summary
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVECVE-2025-61732
SeverityHIGH
TypeUPDATED
PublishedThu, Feb 05 · 04:15 AM CST
ModifiedMon, Sep 07 · 01:17 PM CDT
Wed, Mar 25 · 08:16 PM CDTCVE-2026-33216
8.6/10 · Worth your timeNVDvuln
Summary
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions
CVECVE-2026-33216
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 25 · 08:16 PM CDT
ModifiedMon, Sep 07 · 01:18 PM CDT
Mon, Nov 18 · 10:15 AM CSTCVE-2024-42386
8.2/10 · Worth your timeNVDvuln
Summary
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
CVECVE-2024-42386
SeverityHIGH
TypeUPDATED
PublishedMon, Nov 18 · 10:15 AM CST
ModifiedTue, Sep 08 · 09:17 AM CDT
Tue, Mar 11 · 10:15 AM CDTCVE-2024-56181
8.2/10 · Worth your timeNVDvuln
Summary
A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (All versions < V32.01.04), SIMATIC IPC PX-32A (All versions < V29.01.07), SIMATIC IP
CVECVE-2024-56181
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 11 · 10:15 AM CDT
ModifiedTue, Sep 08 · 09:17 AM CDT
Tue, Mar 11 · 10:15 AM CDTCVE-2024-56182
8.2/10 · Worth your timeNVDvuln
Summary
A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (All versions < V32.01.04), SIMATIC I
CVECVE-2024-56182
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 11 · 10:15 AM CDT
ModifiedTue, Sep 08 · 09:17 AM CDT
Fri, May 16 · 01:15 AM CDTCVE-2025-47809
8.2/10 · Worth your timeNVDvuln
Summary
Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not ha
CVECVE-2025-47809
SeverityHIGH
TypeUPDATED
PublishedFri, May 16 · 01:15 AM CDT
ModifiedTue, Sep 08 · 09:17 AM CDT
Fri, Apr 03 · 04:16 PM CDTCVE-2026-23459
8.2/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which call iptunnel_xmit_stats(). iptunnel_xmit_stats() was assuming tunnels were only using NETDEV_PCPU_STAT_TSTATS.
CVECVE-2026-23459
SeverityHIGH
TypeUPDATED
PublishedFri, Apr 03 · 04:16 PM CDT
ModifiedMon, Sep 07 · 04:17 PM CDT
Wed, Jan 28 · 01:16 AM CSTCVE-2026-24842
8.2/10 · Worth your timeNVDvuln
Summary
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and c
CVECVE-2026-24842
SeverityHIGH
TypeUPDATED
PublishedWed, Jan 28 · 01:16 AM CST
ModifiedMon, Sep 07 · 01:18 PM CDT
Wed, Apr 08 · 02:16 AM CDTCVE-2026-33810
8.2/10 · Worth your timeNVDvuln
Summary
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in th
CVECVE-2026-33810
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedMon, Sep 07 · 01:18 PM CDT
Tue, Apr 28 · 10:16 AM CDTCVE-2026-41604
8.2/10 · Worth your timeNVDvuln
Summary
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVECVE-2026-41604
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 28 · 10:16 AM CDT
ModifiedMon, Sep 07 · 01:19 PM CDT