Thu, Apr 09 · 03:16 PM CDTCVE-2025-62718
9.9/10 · Must read/watchNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the config
CVECVE-2025-62718
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 09 · 03:16 PM CDT
ModifiedFri, Aug 07 · 12:17 PM CDT
Wed, Nov 27 · 04:15 PM CSTCVE-2019-18184
9.8/10 · Must read/watchNVDvuln
Summary
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
CVECVE-2019-18184
SeverityCRITICAL
TypeUPDATED
PublishedWed, Nov 27 · 04:15 PM CST
ModifiedFri, Aug 07 · 03:16 PM CDT
Tue, Jan 20 · 07:15 PM CSTCVE-2025-56005
9.8/10 · Must read/watchNVDvuln
Summary
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pickle.load()` without validation. Because `pickle` allows execution of embedded code v
CVECVE-2025-56005
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jan 20 · 07:15 PM CST
ModifiedFri, Aug 07 · 12:17 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33815
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33815
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedFri, Aug 07 · 12:17 PM CDT
Fri, Jun 12 · 10:16 AM CDTCVE-2026-49875
9.8/10 · Must read/watchNVDvuln
Summary
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue.
CVECVE-2026-49875
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jun 12 · 10:16 AM CDT
ModifiedFri, Aug 07 · 01:16 PM CDT
Wed, Jun 24 · 07:17 PM CDTCVE-2026-49980
9.8/10 · Must read/watchNVDvuln
Summary
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend in
CVECVE-2026-49980
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jun 24 · 07:17 PM CDT
ModifiedFri, Aug 07 · 12:18 PM CDT
Fri, Jun 12 · 10:16 AM CDTCVE-2026-50628
9.8/10 · Must read/watchNVDvuln
Summary
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which f
CVECVE-2026-50628
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jun 12 · 10:16 AM CDT
ModifiedFri, Aug 07 · 01:16 PM CDT
Sun, Jul 19 · 12:16 PM CDTCVE-2026-53384
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 8250 port via serial8250_register_8250_port() and then, if the device has a clock, registers a clock notifier. If clk_notifier_register() fails, probe r
CVECVE-2026-53384
SeverityCRITICAL
TypeUPDATED
PublishedSun, Jul 19 · 12:16 PM CDT
ModifiedFri, Aug 07 · 08:47 PM CDT
Tue, Jul 21 · 10:17 PM CDTCVE-2026-60269
9.8/10 · Must read/watchNVDvuln
Summary
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful
CVECVE-2026-60269
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jul 21 · 10:17 PM CDT
ModifiedFri, Aug 07 · 01:12 PM CDT
Tue, Jul 21 · 10:17 PM CDTCVE-2026-60276
9.8/10 · Must read/watchNVDvuln
Summary
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Coherence. Successf
CVECVE-2026-60276
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jul 21 · 10:17 PM CDT
ModifiedFri, Aug 07 · 01:12 PM CDT
Tue, Jul 21 · 10:17 PM CDTCVE-2026-60279
9.8/10 · Must read/watchNVDvuln
Summary
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successfu
CVECVE-2026-60279
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jul 21 · 10:17 PM CDT
ModifiedFri, Aug 07 · 01:13 PM CDT
Tue, Jul 21 · 10:17 PM CDTCVE-2026-60296
9.8/10 · Must read/watchNVDvuln
Summary
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful
CVECVE-2026-60296
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jul 21 · 10:17 PM CDT
ModifiedFri, Aug 07 · 01:11 PM CDT
Wed, Jan 07 · 05:15 PM CSTCVE-2025-12543
9.6/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling at
CVECVE-2025-12543
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 07 · 05:15 PM CST
ModifiedFri, Aug 07 · 02:16 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedFri, Aug 07 · 12:17 PM CDT
Thu, Jun 04 · 02:16 PM CDTCVE-2026-8037
9.6/10 · Must read/watchNVDvuln
Summary
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
CVECVE-2026-8037
SeverityCRITICAL
TypeUPDATED
PublishedThu, Jun 04 · 02:16 PM CDT
ModifiedSat, Aug 08 · 05:17 AM CDT
Fri, Feb 20 · 09:19 PM CSTCVE-2026-25896
9.3/10 · Must read/watchNVDvuln
Summary
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&
CVECVE-2026-25896
SeverityCRITICAL
TypeUPDATED
PublishedFri, Feb 20 · 09:19 PM CST
ModifiedFri, Aug 07 · 12:17 PM CDT
Fri, Jun 12 · 09:16 PM CDTCVE-2026-44990
9.3/10 · Must read/watchNVDvuln
Summary
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This i
CVECVE-2026-44990
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jun 12 · 09:16 PM CDT
ModifiedFri, Aug 07 · 12:17 PM CDT
Wed, Sep 25 · 12:15 PM CDTCVE-2024-6592
9.1/10 · Must read/watchNVDvuln
Summary
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an
CVECVE-2024-6592
SeverityCRITICAL
TypeUPDATED
PublishedWed, Sep 25 · 12:15 PM CDT
ModifiedSat, Aug 08 · 12:16 AM CDT
Wed, Sep 25 · 12:15 PM CDTCVE-2024-6593
9.1/10 · Must read/watchNVDvuln
Summary
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and g
CVECVE-2024-6593
SeverityCRITICAL
TypeUPDATED
PublishedWed, Sep 25 · 12:15 PM CDT
ModifiedSat, Aug 08 · 12:16 AM CDT
Tue, Jun 09 · 10:16 AM CDTCVE-2025-10263
9.1/10 · Must read/watchNVDvuln
Summary
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.
CVECVE-2025-10263
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jun 09 · 10:16 AM CDT
ModifiedFri, Aug 07 · 12:16 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39832
9.1/10 · Must read/watchNVDvuln
Summary
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. A
CVECVE-2026-39832
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Aug 07 · 12:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Aug 07 · 12:17 PM CDT
Mon, Jul 20 · 08:16 PM CDTCVE-2026-44231
9.1/10 · Must read/watchNVDvuln
Summary
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other
CVECVE-2026-44231
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jul 20 · 08:16 PM CDT
ModifiedFri, Aug 07 · 01:25 PM CDT
Fri, Jun 12 · 10:16 AM CDTCVE-2026-50627
9.1/10 · Must read/watchNVDvuln
Summary
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to u
CVECVE-2026-50627
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jun 12 · 10:16 AM CDT
ModifiedFri, Aug 07 · 01:16 PM CDT
Tue, Jul 21 · 10:17 PM CDTCVE-2026-60334
8.8/10 · Worth your timeNVDvuln
Summary
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successf
CVECVE-2026-60334
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 21 · 10:17 PM CDT
ModifiedFri, Aug 07 · 08:45 PM CDT