Fri, Apr 23 · 06:15 PM CDTCVE-2021-22205
10.0/10 · Must read/watchNVDvuln
Summary
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
CVECVE-2021-22205
SeverityCRITICAL
TypeUPDATED
PublishedFri, Apr 23 · 06:15 PM CDT
ModifiedThu, Aug 06 · 05:16 AM CDT
Mon, Aug 12 · 01:38 PM CDTCVE-2024-42467
10.0/10 · Must read/watchNVDvuln
Summary
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu add-on can be accessed without authentication. This proxy-feature can be exploited as Server-Side Request Forgery (SSRF) t
CVECVE-2024-42467
SeverityCRITICAL
TypeUPDATED
PublishedMon, Aug 12 · 01:38 PM CDT
ModifiedWed, Aug 05 · 04:16 PM CDT
Mon, Jan 19 · 06:16 PM CSTCVE-2026-22797
9.9/10 · Must read/watchNVDvuln
Summary
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such
CVECVE-2026-22797
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jan 19 · 06:16 PM CST
ModifiedWed, Aug 05 · 01:20 PM CDT
Sat, Jun 16 · 09:55 PM CDTCVE-2012-1723
9.8/10 · Must read/watchNVDvuln
Summary
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
CVECVE-2012-1723
SeverityCRITICAL
TypeUPDATED
PublishedSat, Jun 16 · 09:55 PM CDT
ModifiedThu, Aug 06 · 05:16 AM CDT
Tue, Aug 28 · 12:55 AM CDTCVE-2012-4681
9.8/10 · Must read/watchNVDvuln
Summary
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the
CVECVE-2012-4681
SeverityCRITICAL
TypeUPDATED
PublishedTue, Aug 28 · 12:55 AM CDT
ModifiedThu, Aug 06 · 05:16 AM CDT
Fri, Aug 16 · 03:15 AM CDTCVE-2019-15107
9.8/10 · Must read/watchNVDvuln
Summary
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
CVECVE-2019-15107
SeverityCRITICAL
TypeUPDATED
PublishedFri, Aug 16 · 03:15 AM CDT
ModifiedThu, Aug 06 · 05:16 AM CDT
Tue, Apr 26 · 02:15 AM CDTCVE-2022-29499
9.8/10 · Must read/watchNVDvuln
Summary
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
CVECVE-2022-29499
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 26 · 02:15 AM CDT
ModifiedThu, Aug 06 · 05:16 AM CDT
Tue, Oct 18 · 02:15 PM CDTCVE-2022-40684
9.8/10 · Must read/watchNVDvuln
Summary
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administ
CVECVE-2022-40684
SeverityCRITICAL
TypeUPDATED
PublishedTue, Oct 18 · 02:15 PM CDT
ModifiedThu, Aug 06 · 05:16 AM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedWed, Aug 05 · 01:21 PM CDT
Thu, Apr 09 · 08:16 PM CDTCVE-2026-34486
9.8/10 · Must read/watchNVDvuln
Summary
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
CVECVE-2026-34486
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 09 · 08:16 PM CDT
ModifiedWed, Aug 05 · 03:33 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedWed, Aug 05 · 01:22 PM CDT
Tue, Jun 09 · 09:17 PM CDTCVE-2026-47928
9.6/10 · Must read/watchNVDvuln
Summary
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require us
CVECVE-2026-47928
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jun 09 · 09:17 PM CDT
ModifiedWed, Aug 05 · 05:32 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedWed, Aug 05 · 01:21 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedWed, Aug 05 · 01:22 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39832
9.1/10 · Must read/watchNVDvuln
Summary
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. A
CVECVE-2026-39832
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedWed, Aug 05 · 01:22 PM CDT
Thu, Sep 16 · 03:15 PM CDTCVE-2021-40438
9.0/10 · Must read/watchNVDvuln
Summary
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVECVE-2021-40438
SeverityCRITICAL
TypeUPDATED
PublishedThu, Sep 16 · 03:15 PM CDT
ModifiedThu, Aug 06 · 05:16 AM CDT
Wed, Mar 04 · 10:16 PM CSTCVE-2025-66024
9.0/10 · Must read/watchNVDvuln
Summary
The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability arises because the post title is injected directly into the HTML tag without prope
CVECVE-2025-66024
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 04 · 10:16 PM CST
ModifiedWed, Aug 05 · 04:16 PM CDT
Wed, Jun 10 · 03:16 AM CDTCVE-2025-58468
8.8/10 · Worth your timeNVDvuln
Summary
A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later
CVECVE-2025-58468
SeverityHIGH
TypeUPDATED
PublishedWed, Jun 10 · 03:16 AM CDT
ModifiedWed, Aug 05 · 01:59 PM CDT
Tue, Jun 02 · 09:16 AM CDTCVE-2026-1784
8.8/10 · Worth your timeNVDvuln
Summary
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVECVE-2026-1784
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 02 · 09:16 AM CDT
ModifiedWed, Aug 05 · 01:20 PM CDT
Wed, May 13 · 04:16 PM CDTCVE-2026-44293
8.8/10 · Worth your timeNVDvuln
Summary
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field
CVECVE-2026-44293
SeverityHIGH
TypeUPDATED
PublishedWed, May 13 · 04:16 PM CDT
ModifiedWed, Aug 05 · 01:22 PM CDT
Tue, Jun 09 · 09:17 PM CDTCVE-2026-47932
8.8/10 · Worth your timeNVDvuln
Summary
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vu
CVECVE-2026-47932
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 09 · 09:17 PM CDT
ModifiedWed, Aug 05 · 05:32 PM CDT
Thu, Feb 05 · 04:15 AM CSTCVE-2025-61732
8.6/10 · Worth your timeNVDvuln
Summary
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVECVE-2025-61732
SeverityHIGH
TypeUPDATED
PublishedThu, Feb 05 · 04:15 AM CST
ModifiedWed, Aug 05 · 01:20 PM CDT
Tue, Jun 09 · 09:17 PM CDTCVE-2026-47929
8.4/10 · Worth your timeNVDvuln
Summary
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session.
CVECVE-2026-47929
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 09 · 09:17 PM CDT
ModifiedWed, Aug 05 · 05:32 PM CDT
Tue, Jun 09 · 09:17 PM CDTCVE-2026-47931
8.4/10 · Worth your timeNVDvuln
Summary
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted
CVECVE-2026-47931
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 09 · 09:17 PM CDT
ModifiedWed, Aug 05 · 05:32 PM CDT
Wed, Apr 08 · 02:16 AM CDTCVE-2026-33810
8.2/10 · Worth your timeNVDvuln
Summary
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in th
CVECVE-2026-33810
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedWed, Aug 05 · 01:21 PM CDT