Wed, Mar 04 · 06:16 PM CSTCVE-2026-20079
10.0/10 · Must read/watchNVDvuln
Summary
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper
CVECVE-2026-20079
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 04 · 06:16 PM CST
ModifiedWed, Aug 26 · 05:16 PM CDT
Mon, Jan 19 · 06:16 PM CSTCVE-2026-22797
9.9/10 · Must read/watchNVDvuln
Summary
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such
CVECVE-2026-22797
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jan 19 · 06:16 PM CST
ModifiedWed, Aug 26 · 01:17 PM CDT
Tue, Dec 02 · 03:15 PM CSTCVE-2025-59693
9.8/10 · Must read/watchNVDvuln
Summary
The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate privileges by bypassing the tamper label and opening the chassis without leaving evide
CVECVE-2025-59693
SeverityCRITICAL
TypeUPDATED
PublishedTue, Dec 02 · 03:15 PM CST
ModifiedWed, Aug 26 · 04:16 PM CDT
Tue, Dec 02 · 03:15 PM CSTCVE-2025-59695
9.8/10 · Must read/watchNVDvuln
Summary
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04.
CVECVE-2025-59695
SeverityCRITICAL
TypeUPDATED
PublishedTue, Dec 02 · 03:15 PM CST
ModifiedWed, Aug 26 · 04:16 PM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedWed, Aug 26 · 01:18 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33815
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33815
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedWed, Aug 26 · 01:18 PM CDT
Tue, Apr 07 · 04:16 PM CDTCVE-2026-33816
9.8/10 · Must read/watchNVDvuln
Summary
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVECVE-2026-33816
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 04:16 PM CDT
ModifiedWed, Aug 26 · 01:18 PM CDT
Sat, Apr 18 · 05:16 PM CDTCVE-2026-41242
9.8/10 · Must read/watchNVDvuln
Summary
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.
CVECVE-2026-41242
SeverityCRITICAL
TypeUPDATED
PublishedSat, Apr 18 · 05:16 PM CDT
ModifiedWed, Aug 26 · 01:18 PM CDT
Wed, May 06 · 10:16 AM CDTCVE-2026-43114
9.4/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. The test first loads a ranomly generated pipapo set with 'ipv4 . port' key, i.e. nft -f foo. This works. T
CVECVE-2026-43114
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 06 · 10:16 AM CDT
ModifiedWed, Aug 26 · 01:19 PM CDT
Tue, Dec 02 · 04:15 PM CSTCVE-2025-59703
9.1/10 · Must read/watchNVDvuln
Summary
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamper evidence. To exploit this, the attacker needs to remove the tamper label and all
CVECVE-2025-59703
SeverityCRITICAL
TypeUPDATED
PublishedTue, Dec 02 · 04:15 PM CST
ModifiedWed, Aug 26 · 04:16 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedWed, Aug 26 · 01:18 PM CDT
Mon, Jul 15 · 07:15 PM CDTCVE-2019-1068
8.8/10 · Worth your timeNVDvuln
Summary
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.
CVECVE-2019-1068
SeverityHIGH
TypeUPDATED
PublishedMon, Jul 15 · 07:15 PM CDT
ModifiedThu, Aug 27 · 04:16 AM CDT
Wed, Mar 25 · 06:16 PM CDTCVE-2025-67030
8.8/10 · Worth your timeNVDvuln
Summary
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
CVECVE-2025-67030
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 25 · 06:16 PM CDT
ModifiedWed, Aug 26 · 01:17 PM CDT
Wed, Apr 08 · 02:16 AM CDTCVE-2026-27140
8.8/10 · Worth your timeNVDvuln
Summary
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
CVECVE-2026-27140
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedWed, Aug 26 · 01:18 PM CDT
Wed, May 06 · 10:16 AM CDTCVE-2026-43112
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., "/"), the current logic attempts to check *(cursor2 - 1) before cursor2 has advanced.
CVECVE-2026-43112
SeverityHIGH
TypeUPDATED
PublishedWed, May 06 · 10:16 AM CDT
ModifiedWed, Aug 26 · 01:19 PM CDT
Thu, Feb 05 · 04:15 AM CSTCVE-2025-61732
8.6/10 · Worth your timeNVDvuln
Summary
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVECVE-2025-61732
SeverityHIGH
TypeUPDATED
PublishedThu, Feb 05 · 04:15 AM CST
ModifiedWed, Aug 26 · 01:17 PM CDT
Mon, Mar 02 · 07:16 PM CSTCVE-2026-0010
8.4/10 · Worth your timeNVDvuln
Summary
In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVE-2026-0010
SeverityHIGH
TypeUPDATED
PublishedMon, Mar 02 · 07:16 PM CST
ModifiedWed, Aug 26 · 07:16 PM CDT
Mon, Mar 02 · 07:16 PM CSTCVE-2026-0011
8.4/10 · Worth your timeNVDvuln
Summary
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVE-2026-0011
SeverityHIGH
TypeUPDATED
PublishedMon, Mar 02 · 07:16 PM CST
ModifiedWed, Aug 26 · 07:16 PM CDT
Mon, Mar 02 · 07:16 PM CSTCVE-2026-0013
8.4/10 · Worth your timeNVDvuln
Summary
In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVE-2026-0013
SeverityHIGH
TypeUPDATED
PublishedMon, Mar 02 · 07:16 PM CST
ModifiedWed, Aug 26 · 07:16 PM CDT
Mon, May 04 · 02:16 PM CDTCVE-2026-6266
8.3/10 · Worth your timeNVDvuln
Summary
A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email ownership. This allows a remote attacker to potentially hijack a victim's account or g
CVECVE-2026-6266
SeverityHIGH
TypeUPDATED
PublishedMon, May 04 · 02:16 PM CDT
ModifiedWed, Aug 26 · 04:16 PM CDT
Wed, Apr 08 · 02:16 AM CDTCVE-2026-33810
8.2/10 · Worth your timeNVDvuln
Summary
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in th
CVECVE-2026-33810
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedWed, Aug 26 · 01:18 PM CDT
Mon, Apr 06 · 04:16 PM CDTCVE-2026-34982
8.2/10 · Worth your timeNVDvuln
Summary
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, t
CVECVE-2026-34982
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 04:16 PM CDT
ModifiedWed, Aug 26 · 01:18 PM CDT
Tue, Apr 28 · 10:16 AM CDTCVE-2026-41604
8.2/10 · Worth your timeNVDvuln
Summary
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVECVE-2026-41604
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 28 · 10:16 AM CDT
ModifiedWed, Aug 26 · 01:18 PM CDT
Fri, Dec 03 · 08:15 PM CSTCVE-2021-23758
8.1/10 · Worth your timeNVDvuln
Summary
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
CVECVE-2021-23758
SeverityHIGH
TypeUPDATED
PublishedFri, Dec 03 · 08:15 PM CST
ModifiedThu, Aug 27 · 04:16 AM CDT
Tue, Mar 31 · 08:16 PM CDTCVE-2026-4800
8.1/10 · Worth your timeNVDvuln
Summary
Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as optio
CVECVE-2026-4800
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 31 · 08:16 PM CDT
ModifiedWed, Aug 26 · 01:19 PM CDT