Thu, Apr 09 · 03:16 PM CDTCVE-2025-62718
9.9/10 · Must read/watchNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the config
CVECVE-2025-62718
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 09 · 03:16 PM CDT
ModifiedMon, Aug 17 · 12:17 PM CDT
Mon, Jan 19 · 06:16 PM CSTCVE-2026-22797
9.9/10 · Must read/watchNVDvuln
Summary
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such
CVECVE-2026-22797
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jan 19 · 06:16 PM CST
ModifiedMon, Aug 17 · 12:17 PM CDT
Fri, May 30 · 07:15 PM CDTCVE-2025-48938
9.8/10 · Must read/watchNVDvuln
Summary
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by replacing HTTP URLs provided by GitHub wi
CVECVE-2025-48938
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 30 · 07:15 PM CDT
ModifiedMon, Aug 17 · 12:05 PM CDT
Wed, Jan 28 · 04:16 PM CSTCVE-2025-61140
9.8/10 · Must read/watchNVDvuln
Summary
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
CVECVE-2025-61140
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 28 · 04:16 PM CST
ModifiedMon, Aug 17 · 12:16 PM CDT
Wed, Mar 18 · 12:16 AM CDTCVE-2026-27459
9.8/10 · Must read/watchNVDvuln
Summary
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values t
CVECVE-2026-27459
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 18 · 12:16 AM CDT
ModifiedMon, Aug 17 · 12:17 PM CDT
Wed, Feb 25 · 03:16 AM CSTCVE-2026-27606
9.8/10 · Must read/watchNVDvuln
Summary
Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker to control output file
CVECVE-2026-27606
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 25 · 03:16 AM CST
ModifiedMon, Aug 17 · 12:17 PM CDT
Wed, Feb 25 · 05:25 PM CSTCVE-2026-27727
9.8/10 · Must read/watchNVDvuln
Summary
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked within a running application. If an attacker can provoke an application to read a
CVECVE-2026-27727
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 25 · 05:25 PM CST
ModifiedMon, Aug 17 · 12:17 PM CDT
Fri, Mar 06 · 07:16 AM CSTCVE-2026-28802
9.8/10 · Must read/watchNVDvuln
Summary
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was e
CVECVE-2026-28802
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 AM CST
ModifiedMon, Aug 17 · 12:17 PM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedMon, Aug 17 · 12:17 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33815
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33815
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedMon, Aug 17 · 12:18 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33816
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33816
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedMon, Aug 17 · 12:18 PM CDT
Wed, Apr 08 · 09:17 PM CDTCVE-2026-39892
9.8/10 · Must read/watchNVDvuln
Summary
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
CVECVE-2026-39892
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 08 · 09:17 PM CDT
ModifiedMon, Aug 17 · 12:18 PM CDT
Wed, Mar 18 · 04:17 AM CDTCVE-2026-31938
9.6/10 · Must read/watchNVDvuln
Summary
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the created PDF is opened in. The vulnerability can be exploited in the following scenario: the
CVECVE-2026-31938
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 18 · 04:17 AM CDT
ModifiedMon, Aug 17 · 12:17 PM CDT
Tue, Mar 24 · 12:16 AM CDTCVE-2026-33211
9.6/10 · Must read/watchNVDvuln
Summary
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `Resolut
CVECVE-2026-33211
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 24 · 12:16 AM CDT
ModifiedMon, Aug 17 · 12:18 PM CDT
Fri, Feb 20 · 09:19 PM CSTCVE-2026-25896
9.3/10 · Must read/watchNVDvuln
Summary
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&
CVECVE-2026-25896
SeverityCRITICAL
TypeUPDATED
PublishedFri, Feb 20 · 09:19 PM CST
ModifiedMon, Aug 17 · 12:17 PM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49794
9.1/10 · Must read/watchNVDvuln
Summary
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or
CVECVE-2025-49794
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedMon, Aug 17 · 02:20 PM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49796
9.1/10 · Must read/watchNVDvuln
Summary
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive
CVECVE-2025-49796
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedMon, Aug 17 · 02:20 PM CDT
Mon, Mar 16 · 06:16 PM CDTCVE-2026-27962
9.1/10 · Must read/watchNVDvuln
Summary
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization fu
CVECVE-2026-27962
SeverityCRITICAL
TypeUPDATED
PublishedMon, Mar 16 · 06:16 PM CDT
ModifiedMon, Aug 17 · 12:17 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedMon, Aug 17 · 12:17 PM CDT
Mon, Mar 23 · 06:16 AM CDTCVE-2026-4599
9.1/10 · Must read/watchNVDvuln
Summary
Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accep
CVECVE-2026-4599
SeverityCRITICAL
TypeUPDATED
PublishedMon, Mar 23 · 06:16 AM CDT
ModifiedMon, Aug 17 · 12:18 PM CDT
Thu, Nov 02 · 05:29 PM CDTCVE-2017-11508
8.8/10 · Worth your timeNVDvuln
Summary
SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within Secur
CVECVE-2017-11508
SeverityHIGH
TypeUPDATED
PublishedThu, Nov 02 · 05:29 PM CDT
ModifiedMon, Aug 17 · 02:50 PM CDT
Thu, Aug 02 · 07:29 PM CDTCVE-2018-1154
8.8/10 · Worth your timeNVDvuln
Summary
In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response output has been unified to correct this issue.
CVECVE-2018-1154
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 02 · 07:29 PM CDT
ModifiedMon, Aug 17 · 02:50 PM CDT
Wed, Feb 12 · 03:15 PM CSTCVE-2025-1244
8.8/10 · Worth your timeNVDvuln
Summary
A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.
CVECVE-2025-1244
SeverityHIGH
TypeUPDATED
PublishedWed, Feb 12 · 03:15 PM CST
ModifiedMon, Aug 17 · 11:16 AM CDT
Wed, Nov 26 · 11:15 PM CSTCVE-2025-62593
8.8/10 · Worth your timeNVDvuln
Summary
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent heade
CVECVE-2025-62593
SeverityHIGH
TypeUPDATED
PublishedWed, Nov 26 · 11:15 PM CST
ModifiedTue, Aug 18 · 04:16 AM CDT
Mon, Feb 23 · 09:17 AM CSTCVE-2026-25747
8.8/10 · Worth your timeNVDvuln
Summary
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. An attacker who can wri
CVECVE-2026-25747
SeverityHIGH
TypeUPDATED
PublishedMon, Feb 23 · 09:17 AM CST
ModifiedMon, Aug 17 · 12:17 PM CDT