Fri, Jan 18 · 10:29 PM CST
CVE-2019-3774
9.8/10 · Must read/watch
NVDvuln
Summary
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
CVECVE-2019-3774
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jan 18 · 10:29 PM CST
ModifiedTue, Sep 01 · 06:07 PM CDT
Mon, Mar 30 · 07:16 PM CDT
CVE-2026-34714
9.2/10 · Must read/watch
NVDvuln
Summary
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
CVECVE-2026-34714
SeverityCRITICAL
TypeUPDATED
PublishedMon, Mar 30 · 07:16 PM CDT
ModifiedTue, Sep 01 · 01:18 PM CDT
Mon, Jun 16 · 04:15 PM CDT
CVE-2025-49794
9.1/10 · Must read/watch
NVDvuln
Summary
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or
CVECVE-2025-49794
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedTue, Sep 01 · 12:17 PM CDT
Mon, Jun 16 · 04:15 PM CDT
CVE-2025-49796
9.1/10 · Must read/watch
NVDvuln
Summary
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive
CVECVE-2025-49796
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedTue, Sep 01 · 12:17 PM CDT
Fri, Mar 20 · 11:16 PM CDT
CVE-2026-33186
9.1/10 · Must read/watch
NVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedTue, Sep 01 · 01:18 PM CDT
Tue, May 14 · 03:42 PM CDT
CVE-2024-3727
8.3/10 · Worth your time
NVDvuln
Summary
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
CVECVE-2024-3727
SeverityHIGH
TypeUPDATED
PublishedTue, May 14 · 03:42 PM CDT
ModifiedTue, Sep 01 · 12:17 PM CDT
Thu, Mar 26 · 09:17 PM CDT
CVE-2026-0966
8.2/10 · Worth your time
NVDvuln
Summary
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_P
CVECVE-2026-0966
SeverityHIGH
TypeUPDATED
PublishedThu, Mar 26 · 09:17 PM CDT
ModifiedTue, Sep 01 · 12:17 PM CDT
Wed, Apr 08 · 02:16 AM CDT
CVE-2026-33810
8.2/10 · Worth your time
NVDvuln
Summary
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in th
CVECVE-2026-33810
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedTue, Sep 01 · 01:18 PM CDT
Fri, Mar 27 · 10:16 PM CDT
CVE-2026-33941
8.2/10 · Worth your time
NVDvuln
Summary
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any
CVECVE-2026-33941
SeverityHIGH
TypeUPDATED
PublishedFri, Mar 27 · 10:16 PM CDT
ModifiedTue, Sep 01 · 01:18 PM CDT
Thu, Jun 11 · 05:15 PM CDT
CVE-2020-5411
8.1/10 · Worth your time
NVDvuln
Summary
When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blacklisting known "deserialization gadgets". Spring Batch configures Jackson with global default typing enabled which means that through the previ
CVECVE-2020-5411
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:15 PM CDT
ModifiedTue, Sep 01 · 06:07 PM CDT
Mon, Jul 01 · 01:15 PM CDT
CVE-2024-6387
8.1/10 · Worth your time
NVDvuln
Summary
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
CVECVE-2024-6387
SeverityHIGH
TypeUPDATED
PublishedMon, Jul 01 · 01:15 PM CDT
ModifiedTue, Sep 01 · 12:17 PM CDT
Fri, Mar 27 · 10:16 PM CDT
CVE-2026-33940
8.1/10 · Worth your time
NVDvuln
Summary
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all conditional guards in `resolvePartial()` and cause `invokePartial()` to return `undefined`. The Handlebars runtime then treats the unresolved par
CVECVE-2026-33940
SeverityHIGH
TypeUPDATED
PublishedFri, Mar 27 · 10:16 PM CDT
ModifiedTue, Sep 01 · 01:18 PM CDT
Sun, Mar 06 · 04:15 AM CST
CVE-2022-26490
7.8/10 · Worth your time
NVDvuln
Summary
st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.
CVECVE-2022-26490
SeverityHIGH
TypeUPDATED
PublishedSun, Mar 06 · 04:15 AM CST
ModifiedTue, Sep 01 · 06:04 PM CDT
Wed, Mar 23 · 06:15 AM CDT
CVE-2022-27666
7.8/10 · Worth your time
NVDvuln
Summary
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
CVECVE-2022-27666
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 23 · 06:15 AM CDT
ModifiedTue, Sep 01 · 06:05 PM CDT
Wed, Jan 11 · 01:15 PM CST
CVE-2022-4696
7.8/10 · Worth your time
NVDvuln
Summary
There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter is not increased. This assumption is not always true as cal
CVECVE-2022-4696
SeverityHIGH
TypeUPDATED
PublishedWed, Jan 11 · 01:15 PM CST
ModifiedTue, Sep 01 · 06:05 PM CDT
Mon, Jun 09 · 08:15 PM CDT
CVE-2025-5914
7.8/10 · Worth your time
NVDvuln
Summary
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to
CVECVE-2025-5914
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 09 · 08:15 PM CDT
ModifiedTue, Sep 01 · 12:17 PM CDT
Tue, Nov 18 · 07:15 PM CST
CVE-2025-61662
7.8/10 · Worth your time
NVDvuln
Summary
A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condition by invoking the orphaned command, causing the application to access a memory l
CVECVE-2025-61662
SeverityHIGH
TypeUPDATED
PublishedTue, Nov 18 · 07:15 PM CST
ModifiedTue, Sep 01 · 12:17 PM CDT
Thu, Jul 10 · 02:15 PM CDT
CVE-2025-7425
7.8/10 · Worth your time
NVDvuln
Summary
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, caus
CVECVE-2025-7425
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 10 · 02:15 PM CDT
ModifiedTue, Sep 01 · 12:17 PM CDT
Wed, Jan 07 · 09:16 PM CST
CVE-2026-22184
7.8/10 · Worth your time
NVDvuln
Summary
zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessiv
CVECVE-2026-22184
SeverityHIGH
TypeUPDATED
PublishedWed, Jan 07 · 09:16 PM CST
ModifiedTue, Sep 01 · 01:18 PM CDT
Wed, Apr 22 · 09:16 AM CDT
CVE-2026-6846
7.8/10 · Worth your time
NVDvuln
Summary
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacke
CVECVE-2026-6846
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 22 · 09:16 AM CDT
ModifiedTue, Sep 01 · 12:17 PM CDT
Wed, Sep 21 · 11:15 AM CDT
CVE-2022-38177
7.5/10 · Worth your time
NVDvuln
Summary
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
CVECVE-2022-38177
SeverityHIGH
TypeUPDATED
PublishedWed, Sep 21 · 11:15 AM CDT
ModifiedTue, Sep 01 · 07:44 PM CDT
Wed, Sep 21 · 11:15 AM CDT
CVE-2022-38178
7.5/10 · Worth your time
NVDvuln
Summary
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
CVECVE-2022-38178
SeverityHIGH
TypeUPDATED
PublishedWed, Sep 21 · 11:15 AM CDT
ModifiedTue, Sep 01 · 07:44 PM CDT
Tue, Aug 08 · 07:15 PM CDT
CVE-2023-39533
7.5/10 · Worth your time
NVDvuln
Summary
go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verification of the large key. This vulnerability is present in the core/crypto module of
CVECVE-2023-39533
SeverityHIGH
TypeUPDATED
PublishedTue, Aug 08 · 07:15 PM CDT
ModifiedTue, Sep 01 · 10:17 PM CDT
Fri, Jan 30 · 03:16 PM CST
CVE-2024-4027
7.5/10 · Worth your time
NVDvuln
Summary
A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.
CVECVE-2024-4027
SeverityHIGH
TypeUPDATED
PublishedFri, Jan 30 · 03:16 PM CST
ModifiedTue, Sep 01 · 01:17 PM CDT
Mon, Aug 05 · 02:15 PM CDT
CVE-2024-7409
7.5/10 · Worth your time
NVDvuln
Summary
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.
CVECVE-2024-7409
SeverityHIGH
TypeUPDATED
PublishedMon, Aug 05 · 02:15 PM CDT
ModifiedTue, Sep 01 · 12:17 PM CDT