Fri, Jul 09 · 02:15 PM CDTCVE-2021-30116
10.0/10 · Must read/watchNVDvuln
Summary
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and instal
CVECVE-2021-30116
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jul 09 · 02:15 PM CDT
ModifiedFri, Aug 14 · 05:16 AM CDT
Fri, Jul 09 · 02:15 PM CDTCVE-2021-30120
9.9/10 · Must read/watchNVDvuln
Summary
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, after the user authenticates with username
CVECVE-2021-30120
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jul 09 · 02:15 PM CDT
ModifiedFri, Aug 14 · 05:16 AM CDT
Tue, May 26 · 02:16 PM CDTCVE-2026-7374
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container r
CVECVE-2026-7374
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 26 · 02:16 PM CDT
ModifiedThu, Aug 13 · 05:17 PM CDT
Wed, Aug 11 · 06:47 PM CDTCVE-2010-2861
9.8/10 · Must read/watchNVDvuln
Summary
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm
CVECVE-2010-2861
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 11 · 06:47 PM CDT
ModifiedFri, Aug 14 · 05:16 AM CDT
Thu, Jun 07 · 10:55 PM CDTCVE-2012-0507
9.8/10 · Must read/watchNVDvuln
Summary
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous informa
CVECVE-2012-0507
SeverityCRITICAL
TypeUPDATED
PublishedThu, Jun 07 · 10:55 PM CDT
ModifiedFri, Aug 14 · 05:16 AM CDT
Thu, Apr 07 · 10:59 AM CDTCVE-2016-1019
9.8/10 · Must read/watchNVDvuln
Summary
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
CVECVE-2016-1019
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 07 · 10:59 AM CDT
ModifiedFri, Aug 14 · 05:16 AM CDT
Wed, Aug 23 · 05:29 PM CDTCVE-2017-11357
9.8/10 · Must read/watchNVDvuln
Summary
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
CVECVE-2017-11357
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 23 · 05:29 PM CDT
ModifiedFri, Aug 14 · 05:16 AM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedThu, Aug 13 · 01:18 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedThu, Aug 13 · 10:17 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedThu, Aug 13 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedThu, Aug 13 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedThu, Aug 13 · 01:18 PM CDT
Wed, Jan 13 · 05:59 AM CSTCVE-2016-0034
8.8/10 · Worth your timeNVDvuln
Summary
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."
CVECVE-2016-0034
SeverityHIGH
TypeUPDATED
PublishedWed, Jan 13 · 05:59 AM CST
ModifiedFri, Aug 14 · 05:16 AM CDT
Fri, Mar 17 · 12:59 AM CDTCVE-2017-0144
8.8/10 · Worth your timeNVDvuln
Summary
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Co
CVECVE-2017-0144
SeverityHIGH
TypeUPDATED
PublishedFri, Mar 17 · 12:59 AM CDT
ModifiedFri, Aug 14 · 05:16 AM CDT
Fri, Mar 17 · 12:59 AM CDTCVE-2017-0145
8.8/10 · Worth your timeNVDvuln
Summary
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Co
CVECVE-2017-0145
SeverityHIGH
TypeUPDATED
PublishedFri, Mar 17 · 12:59 AM CDT
ModifiedFri, Aug 14 · 05:16 AM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44494
8.7/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepti
CVECVE-2026-44494
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedThu, Aug 13 · 01:19 PM CDT
Fri, Jun 12 · 03:16 PM CDTCVE-2026-45674
8.7/10 · Worth your timeNVDvuln
Summary
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CVECVE-2026-45674
SeverityHIGH
TypeUPDATED
PublishedFri, Jun 12 · 03:16 PM CDT
ModifiedThu, Aug 13 · 01:19 PM CDT
Fri, Jun 12 · 04:16 PM CDTCVE-2026-47691
8.7/10 · Worth your timeNVDvuln
Summary
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain
CVECVE-2026-47691
SeverityHIGH
TypeUPDATED
PublishedFri, Jun 12 · 04:16 PM CDT
ModifiedThu, Aug 13 · 01:19 PM CDT
Thu, Feb 05 · 04:15 AM CSTCVE-2025-61732
8.6/10 · Worth your timeNVDvuln
Summary
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVECVE-2025-61732
SeverityHIGH
TypeUPDATED
PublishedThu, Feb 05 · 04:15 AM CST
ModifiedThu, Aug 13 · 01:17 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44492
8.6/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes throug
CVECVE-2026-44492
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedThu, Aug 13 · 01:19 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-44578
8.6/10 · Worth your timeNVDvuln
Summary
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to
CVECVE-2026-44578
SeverityHIGH
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedThu, Aug 13 · 01:19 PM CDT
Wed, Sep 09 · 12:59 AM CDTCVE-2015-2546
8.2/10 · Worth your timeNVDvuln
Summary
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege
CVECVE-2015-2546
SeverityHIGH
TypeUPDATED
PublishedWed, Sep 09 · 12:59 AM CDT
ModifiedFri, Aug 14 · 05:16 AM CDT
Wed, Apr 08 · 02:16 AM CDTCVE-2026-33810
8.2/10 · Worth your timeNVDvuln
Summary
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in th
CVECVE-2026-33810
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedThu, Aug 13 · 01:18 PM CDT
Tue, May 05 · 09:16 PM CDTCVE-2026-39852
8.2/10 · Worth your timeNVDvuln
Summary
Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP path-based authorizatio
CVECVE-2026-39852
SeverityHIGH
TypeUPDATED
PublishedTue, May 05 · 09:16 PM CDT
ModifiedThu, Aug 13 · 01:18 PM CDT
Tue, Apr 28 · 10:16 AM CDTCVE-2026-41604
8.2/10 · Worth your timeNVDvuln
Summary
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVECVE-2026-41604
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 28 · 10:16 AM CDT
ModifiedThu, Aug 13 · 01:18 PM CDT