Fri, Apr 23 · 06:15 PM CDTCVE-2021-22205
10.0/10 · Must read/watchNVDvuln
Summary
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
CVECVE-2021-22205
SeverityCRITICAL
TypeUPDATED
PublishedFri, Apr 23 · 06:15 PM CDT
ModifiedSat, Aug 01 · 05:16 AM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-46595
10.0/10 · Must read/watchNVDvuln
Summary
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVECVE-2026-46595
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Jul 31 · 01:18 PM CDT
Thu, Apr 09 · 03:16 PM CDTCVE-2025-62718
9.9/10 · Must read/watchNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the config
CVECVE-2025-62718
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 09 · 03:16 PM CDT
ModifiedFri, Jul 31 · 01:17 PM CDT
Thu, Jun 18 · 01:18 AM CDTCVE-2026-12569
9.8/10 · Must read/watchNVDvuln
Summary
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases p
CVECVE-2026-12569
SeverityCRITICAL
TypeUPDATED
PublishedThu, Jun 18 · 01:18 AM CDT
ModifiedSat, Aug 01 · 05:16 AM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedFri, Jul 31 · 01:17 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33815
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33815
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedFri, Jul 31 · 01:17 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33816
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33816
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedFri, Jul 31 · 01:17 PM CDT
Tue, Jul 21 · 10:17 PM CDTCVE-2026-46982
9.8/10 · Must read/watchNVDvuln
Summary
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful atta
CVECVE-2026-46982
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jul 21 · 10:17 PM CDT
ModifiedFri, Jul 31 · 03:07 PM CDT
Tue, Jul 21 · 10:17 PM CDTCVE-2026-46983
9.8/10 · Must read/watchNVDvuln
Summary
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful attack
CVECVE-2026-46983
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jul 21 · 10:17 PM CDT
ModifiedFri, Jul 31 · 03:18 PM CDT
Tue, Jul 21 · 10:17 PM CDTCVE-2026-60329
9.8/10 · Must read/watchNVDvuln
Summary
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Succes
CVECVE-2026-60329
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jul 21 · 10:17 PM CDT
ModifiedSat, Aug 01 · 05:16 AM CDT
Wed, May 20 · 09:16 PM CDTCVE-2026-8631
9.8/10 · Must read/watchNVDvuln
Summary
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.
CVECVE-2026-8631
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 20 · 09:16 PM CDT
ModifiedFri, Jul 31 · 01:18 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedFri, Jul 31 · 01:18 PM CDT
Tue, Jun 03 · 01:15 PM CDTCVE-2025-4517
9.4/10 · Must read/watchNVDvuln
Summary
Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See
CVECVE-2025-4517
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jun 03 · 01:15 PM CDT
ModifiedFri, Jul 31 · 02:16 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedFri, Jul 31 · 01:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Jul 31 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39832
9.1/10 · Must read/watchNVDvuln
Summary
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. A
CVECVE-2026-39832
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Jul 31 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Jul 31 · 01:18 PM CDT
Thu, Sep 16 · 03:15 PM CDTCVE-2021-40438
9.0/10 · Must read/watchNVDvuln
Summary
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVECVE-2021-40438
SeverityCRITICAL
TypeUPDATED
PublishedThu, Sep 16 · 03:15 PM CDT
ModifiedSat, Aug 01 · 05:16 AM CDT
Tue, Jun 02 · 09:16 AM CDTCVE-2026-1784
8.8/10 · Worth your timeNVDvuln
Summary
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVECVE-2026-1784
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 02 · 09:16 AM CDT
ModifiedFri, Jul 31 · 01:17 PM CDT
Tue, Jul 21 · 10:17 PM CDTCVE-2026-46992
8.8/10 · Worth your timeNVDvuln
Summary
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterpri
CVECVE-2026-46992
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 21 · 10:17 PM CDT
ModifiedFri, Jul 31 · 09:08 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44494
8.7/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepti
CVECVE-2026-44494
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedFri, Jul 31 · 01:18 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44492
8.6/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes throug
CVECVE-2026-44492
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedFri, Jul 31 · 01:18 PM CDT
Sun, Jun 28 · 02:16 AM CDTCVE-2026-58049
8.6/10 · Worth your timeNVDvuln
Summary
FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream
CVECVE-2026-58049
SeverityHIGH
TypeUPDATED
PublishedSun, Jun 28 · 02:16 AM CDT
ModifiedFri, Jul 31 · 01:18 PM CDT
Tue, Jul 21 · 10:17 PM CDTCVE-2026-60330
8.5/10 · Worth your timeNVDvuln
Summary
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the
CVECVE-2026-60330
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 21 · 10:17 PM CDT
ModifiedSat, Aug 01 · 05:16 AM CDT
Tue, Sep 19 · 01:29 PM CDTCVE-2017-12615
8.1/10 · Worth your timeNVDvuln
Summary
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed b
CVECVE-2017-12615
SeverityHIGH
TypeUPDATED
PublishedTue, Sep 19 · 01:29 PM CDT
ModifiedSat, Aug 01 · 05:16 AM CDT