Wed, Mar 04 · 06:16 PM CSTCVE-2026-20079
10.0/10 · Must read/watchNVDvuln
Summary
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper
CVECVE-2026-20079
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 04 · 06:16 PM CST
ModifiedThu, Sep 10 · 12:48 PM CDT
Thu, Apr 09 · 03:16 PM CDTCVE-2025-62718
9.9/10 · Must read/watchNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the config
CVECVE-2025-62718
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 09 · 03:16 PM CDT
ModifiedThu, Sep 10 · 01:17 PM CDT
Mon, Jan 19 · 06:16 PM CSTCVE-2026-22797
9.9/10 · Must read/watchNVDvuln
Summary
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such
CVECVE-2026-22797
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jan 19 · 06:16 PM CST
ModifiedThu, Sep 10 · 01:17 PM CDT
Tue, May 26 · 02:16 PM CDTCVE-2026-7374
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container r
CVECVE-2026-7374
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 26 · 02:16 PM CDT
ModifiedThu, Sep 10 · 01:20 PM CDT
Wed, Mar 18 · 12:16 AM CDTCVE-2026-27459
9.8/10 · Must read/watchNVDvuln
Summary
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values t
CVECVE-2026-27459
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 18 · 12:16 AM CDT
ModifiedThu, Sep 10 · 01:17 PM CDT
Wed, Feb 25 · 03:16 AM CSTCVE-2026-27606
9.8/10 · Must read/watchNVDvuln
Summary
Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker to control output file
CVECVE-2026-27606
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 25 · 03:16 AM CST
ModifiedThu, Sep 10 · 01:18 PM CDT
Tue, May 05 · 10:16 PM CDTCVE-2026-28780
9.8/10 · Must read/watchNVDvuln
Summary
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HT
CVECVE-2026-28780
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 05 · 10:16 PM CDT
ModifiedThu, Sep 10 · 01:18 PM CDT
Fri, Mar 06 · 07:16 AM CSTCVE-2026-28802
9.8/10 · Must read/watchNVDvuln
Summary
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was e
CVECVE-2026-28802
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 AM CST
ModifiedThu, Sep 10 · 01:18 PM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedThu, Sep 10 · 01:18 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33815
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33815
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedThu, Sep 10 · 01:18 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33816
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33816
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedThu, Sep 10 · 01:18 PM CDT
Wed, Apr 08 · 09:17 PM CDTCVE-2026-39892
9.8/10 · Must read/watchNVDvuln
Summary
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
CVECVE-2026-39892
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 08 · 09:17 PM CDT
ModifiedThu, Sep 10 · 01:20 PM CDT
Wed, Aug 26 · 02:15 PM CDTCVE-2020-14498
9.6/10 · Must read/watchNVDvuln
Summary
HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
CVECVE-2020-14498
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 26 · 02:15 PM CDT
ModifiedThu, Sep 10 · 06:17 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedThu, Sep 10 · 01:19 PM CDT
Fri, Feb 20 · 09:19 PM CSTCVE-2026-25896
9.3/10 · Must read/watchNVDvuln
Summary
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&
CVECVE-2026-25896
SeverityCRITICAL
TypeUPDATED
PublishedFri, Feb 20 · 09:19 PM CST
ModifiedThu, Sep 10 · 01:17 PM CDT
Mon, Mar 16 · 06:16 PM CDTCVE-2026-27962
9.1/10 · Must read/watchNVDvuln
Summary
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization fu
CVECVE-2026-27962
SeverityCRITICAL
TypeUPDATED
PublishedMon, Mar 16 · 06:16 PM CDT
ModifiedThu, Sep 10 · 01:18 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedThu, Sep 10 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedThu, Sep 10 · 01:19 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39832
9.1/10 · Must read/watchNVDvuln
Summary
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. A
CVECVE-2026-39832
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedThu, Sep 10 · 01:19 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedThu, Sep 10 · 01:20 PM CDT
Mon, Mar 23 · 06:16 AM CDTCVE-2026-4599
9.1/10 · Must read/watchNVDvuln
Summary
Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accep
CVECVE-2026-4599
SeverityCRITICAL
TypeUPDATED
PublishedMon, Mar 23 · 06:16 AM CDT
ModifiedThu, Sep 10 · 01:20 PM CDT
Tue, Jun 02 · 09:16 AM CDTCVE-2026-1784
8.8/10 · Worth your timeNVDvuln
Summary
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVECVE-2026-1784
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 02 · 09:16 AM CDT
ModifiedThu, Sep 10 · 01:17 PM CDT
Tue, Mar 24 · 07:16 PM CDTCVE-2026-23920
8.8/10 · Worth your timeNVDvuln
Summary
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.
CVECVE-2026-23920
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 24 · 07:16 PM CDT
ModifiedThu, Sep 10 · 09:15 PM CDT
Tue, Mar 24 · 07:16 PM CDTCVE-2026-23921
8.8/10 · Worth your timeNVDvuln
Summary
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniq
CVECVE-2026-23921
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 24 · 07:16 PM CDT
ModifiedThu, Sep 10 · 09:13 PM CDT
Wed, Apr 08 · 02:16 AM CDTCVE-2026-27140
8.8/10 · Worth your timeNVDvuln
Summary
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
CVECVE-2026-27140
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedThu, Sep 10 · 01:17 PM CDT