Tue, Jan 20 · 10:15 PM CSTCVE-2026-21962
10.0/10 · Must read/watchNVDvuln
Summary
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable v
CVECVE-2026-21962
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jan 20 · 10:15 PM CST
ModifiedTue, Aug 25 · 04:18 AM CDT
Thu, Apr 09 · 03:16 PM CDTCVE-2025-62718
9.9/10 · Must read/watchNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the config
CVECVE-2025-62718
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 09 · 03:16 PM CDT
ModifiedMon, Aug 24 · 01:17 PM CDT
Mon, Jan 19 · 06:16 PM CSTCVE-2026-22797
9.9/10 · Must read/watchNVDvuln
Summary
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such
CVECVE-2026-22797
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jan 19 · 06:16 PM CST
ModifiedMon, Aug 24 · 01:17 PM CDT
Wed, Aug 07 · 09:15 PM CDTCVE-2019-1895
9.8/10 · Must read/watchNVDvuln
Summary
A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The vulnerability is due to an insufficient authenticat
CVECVE-2019-1895
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 07 · 09:15 PM CDT
ModifiedMon, Aug 24 · 06:22 PM CDT
Thu, Aug 08 · 08:15 AM CDTCVE-2019-1971
9.8/10 · Must read/watchNVDvuln
Summary
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the web portal framework. An a
CVECVE-2019-1971
SeverityCRITICAL
TypeUPDATED
PublishedThu, Aug 08 · 08:15 AM CDT
ModifiedMon, Aug 24 · 06:22 PM CDT
Mon, Apr 29 · 06:15 PM CDTCVE-2024-31823
9.8/10 · Must read/watchNVDvuln
Summary
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.
CVECVE-2024-31823
SeverityCRITICAL
TypeUPDATED
PublishedMon, Apr 29 · 06:15 PM CDT
ModifiedMon, Aug 24 · 02:16 PM CDT
Tue, Jan 20 · 07:15 PM CSTCVE-2025-56005
9.8/10 · Must read/watchNVDvuln
Summary
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pickle.load()` without validation. Because `pickle` allows execution of embedded code v
CVECVE-2025-56005
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jan 20 · 07:15 PM CST
ModifiedMon, Aug 24 · 01:16 PM CDT
Fri, Feb 27 · 10:16 AM CSTCVE-2026-21660
9.8/10 · Must read/watchNVDvuln
Summary
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise This issue affects Frick Controls Quantum H
CVECVE-2026-21660
SeverityCRITICAL
TypeUPDATED
PublishedFri, Feb 27 · 10:16 AM CST
ModifiedMon, Aug 24 · 06:16 PM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedMon, Aug 24 · 01:17 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33815
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33815
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedMon, Aug 24 · 01:18 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33816
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33816
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedMon, Aug 24 · 01:18 PM CDT
Tue, Mar 24 · 12:16 AM CDTCVE-2026-33211
9.6/10 · Must read/watchNVDvuln
Summary
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `Resolut
CVECVE-2026-33211
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 24 · 12:16 AM CDT
ModifiedMon, Aug 24 · 01:18 PM CDT
Fri, Feb 20 · 09:19 PM CSTCVE-2026-25896
9.3/10 · Must read/watchNVDvuln
Summary
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&
CVECVE-2026-25896
SeverityCRITICAL
TypeUPDATED
PublishedFri, Feb 20 · 09:19 PM CST
ModifiedMon, Aug 24 · 01:17 PM CDT
Wed, Apr 15 · 08:16 PM CDTCVE-2025-41118
9.1/10 · Must read/watchNVDvuln
Summary
Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Pyroscope API. To exploi
CVECVE-2025-41118
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 15 · 08:16 PM CDT
ModifiedMon, Aug 24 · 01:16 PM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49794
9.1/10 · Must read/watchNVDvuln
Summary
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or
CVECVE-2025-49794
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedMon, Aug 24 · 11:16 AM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49796
9.1/10 · Must read/watchNVDvuln
Summary
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive
CVECVE-2025-49796
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedMon, Aug 24 · 11:16 AM CDT
Tue, Jan 27 · 04:16 PM CSTCVE-2026-24874
9.1/10 · Must read/watchNVDvuln
Summary
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.
CVECVE-2026-24874
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jan 27 · 04:16 PM CST
ModifiedMon, Aug 24 · 09:06 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedMon, Aug 24 · 01:18 PM CDT
Wed, May 01 · 01:15 PM CDTCVE-2024-33775
8.8/10 · Worth your timeNVDvuln
Summary
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
CVECVE-2024-33775
SeverityHIGH
TypeUPDATED
PublishedWed, May 01 · 01:15 PM CDT
ModifiedMon, Aug 24 · 02:16 PM CDT
Tue, Jan 27 · 04:16 PM CSTCVE-2025-15467
8.8/10 · Worth your timeNVDvuln
Summary
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structure
CVECVE-2025-15467
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 27 · 04:16 PM CST
ModifiedMon, Aug 24 · 01:16 PM CDT
Wed, Mar 25 · 06:16 PM CDTCVE-2025-67030
8.8/10 · Worth your timeNVDvuln
Summary
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
CVECVE-2025-67030
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 25 · 06:16 PM CDT
ModifiedMon, Aug 24 · 01:17 PM CDT
Tue, Jan 20 · 01:15 AM CSTCVE-2026-23950
8.8/10 · Worth your timeNVDvuln
Summary
node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the li
CVECVE-2026-23950
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 20 · 01:15 AM CST
ModifiedMon, Aug 24 · 01:17 PM CDT
Sun, Feb 15 · 04:15 PM CSTCVE-2026-26369
8.8/10 · Worth your timeNVDvuln
Summary
eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrpc/management specifying their own username to elevate their account to the UG_ADMIN
CVECVE-2026-26369
SeverityHIGH
TypeUPDATED
PublishedSun, Feb 15 · 04:15 PM CST
ModifiedMon, Aug 24 · 11:16 AM CDT
Wed, Jan 13 · 11:15 PM CSTCVE-2021-21009
8.6/10 · Worth your timeNVDvuln
Summary
Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to issue
CVECVE-2021-21009
SeverityHIGH
TypeUPDATED
PublishedWed, Jan 13 · 11:15 PM CST
ModifiedMon, Aug 24 · 06:07 PM CDT
Wed, Jan 31 · 10:15 PM CSTCVE-2024-21626
8.6/10 · Worth your timeNVDvuln
Summary
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a
CVECVE-2024-21626
SeverityHIGH
TypeUPDATED
PublishedWed, Jan 31 · 10:15 PM CST
ModifiedMon, Aug 24 · 01:16 PM CDT