Thu, Apr 09 · 03:16 PM CDTCVE-2025-62718
9.9/10 · Must read/watchNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the config
CVECVE-2025-62718
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 09 · 03:16 PM CDT
ModifiedTue, Aug 25 · 01:17 PM CDT
Mon, Jan 19 · 06:16 PM CSTCVE-2026-22797
9.9/10 · Must read/watchNVDvuln
Summary
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such
CVECVE-2026-22797
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jan 19 · 06:16 PM CST
ModifiedTue, Aug 25 · 01:17 PM CDT
Thu, Apr 06 · 09:59 PM CDTCVE-2016-8735
9.8/10 · Must read/watchNVDvuln
Summary
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 O
CVECVE-2016-8735
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 06 · 09:59 PM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT
Fri, Apr 26 · 07:29 PM CDTCVE-2019-2725
9.8/10 · Must read/watchNVDvuln
Summary
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successf
CVECVE-2019-2725
SeverityCRITICAL
TypeUPDATED
PublishedFri, Apr 26 · 07:29 PM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT
Fri, May 01 · 07:15 PM CDTCVE-2020-10683
9.8/10 · Must read/watchNVDvuln
Summary
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
CVECVE-2020-10683
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 01 · 07:15 PM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT
Mon, Feb 24 · 10:15 PM CSTCVE-2020-1938
9.8/10 · Must read/watchNVDvuln
Summary
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. I
CVECVE-2020-1938
SeverityCRITICAL
TypeUPDATED
PublishedMon, Feb 24 · 10:15 PM CST
ModifiedTue, Aug 25 · 04:28 PM CDT
Mon, Mar 02 · 04:15 AM CSTCVE-2020-9546
9.8/10 · Must read/watchNVDvuln
Summary
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
CVECVE-2020-9546
SeverityCRITICAL
TypeUPDATED
PublishedMon, Mar 02 · 04:15 AM CST
ModifiedTue, Aug 25 · 04:28 PM CDT
Mon, Mar 02 · 04:15 AM CSTCVE-2020-9548
9.8/10 · Must read/watchNVDvuln
Summary
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
CVECVE-2020-9548
SeverityCRITICAL
TypeUPDATED
PublishedMon, Mar 02 · 04:15 AM CST
ModifiedTue, Aug 25 · 04:28 PM CDT
Mon, Feb 09 · 05:16 AM CSTCVE-2026-1615
9.8/10 · Must read/watchNVDvuln
Summary
Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this vulnerabilit
CVECVE-2026-1615
SeverityCRITICAL
TypeUPDATED
PublishedMon, Feb 09 · 05:16 AM CST
ModifiedTue, Aug 25 · 01:17 PM CDT
Wed, Mar 18 · 12:16 AM CDTCVE-2026-27459
9.8/10 · Must read/watchNVDvuln
Summary
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values t
CVECVE-2026-27459
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 18 · 12:16 AM CDT
ModifiedTue, Aug 25 · 01:18 PM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedTue, Aug 25 · 01:18 PM CDT
Tue, Jan 27 · 04:16 PM CSTCVE-2026-24874
9.1/10 · Must read/watchNVDvuln
Summary
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.
CVECVE-2026-24874
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jan 27 · 04:16 PM CST
ModifiedTue, Aug 25 · 03:20 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedTue, Aug 25 · 01:18 PM CDT
Wed, May 21 · 10:15 PM CDTCVE-2025-34027
9.0/10 · Must read/watchNVDvuln
Summary
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for a Time-of-Check to Time-of-Use (TOCTOU) write in combination with a race conditio
CVECVE-2025-34027
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 21 · 10:15 PM CDT
ModifiedTue, Aug 25 · 03:04 PM CDT
Fri, May 11 · 08:29 PM CDTCVE-2018-1258
8.8/10 · Worth your timeNVDvuln
Summary
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
CVECVE-2018-1258
SeverityHIGH
TypeUPDATED
PublishedFri, May 11 · 08:29 PM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT
Wed, Mar 18 · 10:15 PM CDTCVE-2020-10672
8.8/10 · Worth your timeNVDvuln
Summary
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
CVECVE-2020-10672
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 18 · 10:15 PM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT
Wed, Mar 18 · 10:15 PM CDTCVE-2020-10673
8.8/10 · Worth your timeNVDvuln
Summary
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
CVECVE-2020-10673
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 18 · 10:15 PM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT
Thu, Mar 26 · 01:15 PM CDTCVE-2020-10968
8.8/10 · Worth your timeNVDvuln
Summary
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
CVECVE-2020-10968
SeverityHIGH
TypeUPDATED
PublishedThu, Mar 26 · 01:15 PM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT
Thu, Mar 26 · 01:15 PM CDTCVE-2020-10969
8.8/10 · Worth your timeNVDvuln
Summary
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
CVECVE-2020-10969
SeverityHIGH
TypeUPDATED
PublishedThu, Mar 26 · 01:15 PM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT
Tue, Mar 31 · 05:15 AM CDTCVE-2020-11111
8.8/10 · Worth your timeNVDvuln
Summary
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVECVE-2020-11111
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 31 · 05:15 AM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT
Tue, Mar 31 · 05:15 AM CDTCVE-2020-11112
8.8/10 · Worth your timeNVDvuln
Summary
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVECVE-2020-11112
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 31 · 05:15 AM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT
Tue, Mar 31 · 05:15 AM CDTCVE-2020-11113
8.8/10 · Worth your timeNVDvuln
Summary
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVECVE-2020-11113
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 31 · 05:15 AM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT
Wed, May 21 · 11:15 PM CDTCVE-2025-34025
8.8/10 · Worth your timeNVDvuln
Summary
The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe default mounting of host binary paths that allow the container to modify host paths. The escape can be used to trigger remote code execution or direct host access depending on t
CVECVE-2025-34025
SeverityHIGH
TypeUPDATED
PublishedWed, May 21 · 11:15 PM CDT
ModifiedTue, Aug 25 · 02:40 PM CDT
Fri, May 13 · 08:15 AM CDTCVE-2022-25762
8.6/10 · Worth your timeNVDvuln
Summary
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case cou
CVECVE-2022-25762
SeverityHIGH
TypeUPDATED
PublishedFri, May 13 · 08:15 AM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT
Wed, Jul 21 · 03:15 PM CDTCVE-2021-2351
8.3/10 · Worth your timeNVDvuln
Summary
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks req
CVECVE-2021-2351
SeverityHIGH
TypeUPDATED
PublishedWed, Jul 21 · 03:15 PM CDT
ModifiedTue, Aug 25 · 04:28 PM CDT