Fri, May 22 · 04:16 AM CDTCVE-2026-46595
10.0/10 · Must read/watchNVDvuln
Summary
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVECVE-2026-46595
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Aug 14 · 01:18 PM CDT
Thu, Apr 09 · 03:16 PM CDTCVE-2025-62718
9.9/10 · Must read/watchNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the config
CVECVE-2025-62718
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 09 · 03:16 PM CDT
ModifiedFri, Aug 14 · 01:17 PM CDT
Fri, May 29 · 04:16 PM CDTCVE-2026-44962
9.9/10 · Must read/watchNVDvuln
Summary
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in loca
CVECVE-2026-44962
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 29 · 04:16 PM CDT
ModifiedFri, Aug 14 · 04:16 PM CDT
Tue, May 26 · 02:16 PM CDTCVE-2026-7374
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container r
CVECVE-2026-7374
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 26 · 02:16 PM CDT
ModifiedFri, Aug 14 · 01:19 PM CDT
Fri, Dec 11 · 05:15 PM CSTCVE-2020-29574
9.8/10 · Must read/watchNVDvuln
Summary
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
CVECVE-2020-29574
SeverityCRITICAL
TypeUPDATED
PublishedFri, Dec 11 · 05:15 PM CST
ModifiedSat, Aug 15 · 04:17 AM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedFri, Aug 14 · 01:17 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33815
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33815
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedFri, Aug 14 · 01:18 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33816
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33816
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedFri, Aug 14 · 01:18 PM CDT
Thu, Jun 25 · 09:16 AM CDTCVE-2026-53175
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush On netns teardown, fqdir_pre_exit() walks the fqdir rhashtable and flushes every fragment queue that is not yet complete using inet_frag_queue_flush(). That helper frees all the skbs
CVECVE-2026-53175
SeverityCRITICAL
TypeUPDATED
PublishedThu, Jun 25 · 09:16 AM CDT
ModifiedFri, Aug 14 · 01:19 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedFri, Aug 14 · 01:18 PM CDT
Fri, Feb 20 · 09:19 PM CSTCVE-2026-25896
9.3/10 · Must read/watchNVDvuln
Summary
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&
CVECVE-2026-25896
SeverityCRITICAL
TypeUPDATED
PublishedFri, Feb 20 · 09:19 PM CST
ModifiedFri, Aug 14 · 01:17 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedFri, Aug 14 · 01:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Aug 14 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39832
9.1/10 · Must read/watchNVDvuln
Summary
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. A
CVECVE-2026-39832
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Aug 14 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Aug 14 · 01:18 PM CDT
Mon, Jun 22 · 11:16 PM CDTCVE-2026-48746
9.1/10 · Must read/watchNVDvuln
Summary
vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_AP
CVECVE-2026-48746
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 22 · 11:16 PM CDT
ModifiedFri, Aug 14 · 01:18 PM CDT
Tue, Feb 11 · 10:15 PM CSTCVE-2020-0618
8.8/10 · Worth your timeNVDvuln
Summary
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
CVECVE-2020-0618
SeverityHIGH
TypeUPDATED
PublishedTue, Feb 11 · 10:15 PM CST
ModifiedSat, Aug 15 · 04:17 AM CDT
Tue, Nov 04 · 02:15 AM CSTCVE-2025-43433
8.8/10 · Worth your timeNVDvuln
Summary
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption.
CVECVE-2025-43433
SeverityHIGH
TypeUPDATED
PublishedTue, Nov 04 · 02:15 AM CST
ModifiedFri, Aug 14 · 01:17 PM CDT
Thu, May 14 · 02:16 PM CDTCVE-2026-6477
8.8/10 · Worth your timeNVDvuln
Summary
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length
CVECVE-2026-6477
SeverityHIGH
TypeUPDATED
PublishedThu, May 14 · 02:16 PM CDT
ModifiedFri, Aug 14 · 01:19 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44494
8.7/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepti
CVECVE-2026-44494
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedFri, Aug 14 · 01:18 PM CDT
Wed, Jan 31 · 10:15 PM CSTCVE-2024-21626
8.6/10 · Worth your timeNVDvuln
Summary
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a
CVECVE-2024-21626
SeverityHIGH
TypeUPDATED
PublishedWed, Jan 31 · 10:15 PM CST
ModifiedFri, Aug 14 · 01:17 PM CDT
Wed, Mar 25 · 08:16 PM CDTCVE-2026-33216
8.6/10 · Worth your timeNVDvuln
Summary
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions
CVECVE-2026-33216
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 25 · 08:16 PM CDT
ModifiedFri, Aug 14 · 01:18 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44492
8.6/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes throug
CVECVE-2026-44492
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedFri, Aug 14 · 01:18 PM CDT
Tue, May 14 · 03:42 PM CDTCVE-2024-3727
8.3/10 · Worth your timeNVDvuln
Summary
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
CVECVE-2024-3727
SeverityHIGH
TypeUPDATED
PublishedTue, May 14 · 03:42 PM CDT
ModifiedSat, Aug 15 · 03:16 AM CDT
Wed, Feb 18 · 06:24 PM CSTCVE-2026-24708
8.2/10 · Worth your timeNVDvuln
Summary
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize o
CVECVE-2026-24708
SeverityHIGH
TypeUPDATED
PublishedWed, Feb 18 · 06:24 PM CST
ModifiedFri, Aug 14 · 01:17 PM CDT