Low — Podatności CVE o niskim poziomie ważności (CVSS < 4.0). Monitoruj i oceń ryzyko. Znaleziono 200 CVE.

Inne poziomy: 🔴 Critical 🟠 High 🟡 Medium
CVE-2013-2423 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOT…

3.7 CVSS
93.4% EPSS
oracle 2013-04-17
CVE-2026-48907 🔴 Łataj teraz KEV

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

0.0 CVSS
0.8% EPSS
2026-06-05
CVE-2015-4000 ⚪ Do wiadomości
appsos

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgra…

3.7 CVSS
92.3% EPSS
oracle 2015-05-21
CVE-2014-3566 ⚪ Do wiadomości
apps

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a…

3.4 CVSS
93.5% EPSS
openssl 2014-10-15
CVE-2006-5614 ⚪ Do wiadomości
appscloud

Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, w…

2.6 CVSS
88.4% EPSS
microsoftdos 2006-10-31
CVE-2025-34037 ⚪ Do wiadomości

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied inp…

0.0 CVSS
81.6% EPSS
rce 2025-06-24
CVE-2012-10027 ⚪ Do wiadomości

WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a t…

0.0 CVSS
73.7% EPSS
rce 2025-08-05
CVE-2010-0926 ⚪ Do wiadomości

The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, an…

3.5 CVSS
52.4% EPSS
sambapath-traversal 2010-03-10
CVE-2006-5229 ⚪ Do wiadomości

OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via timing discrepancies in which responses t…

2.6 CVSS
56.6% EPSS
novell 2006-10-10
CVE-1999-0532 ⚪ Do wiadomości

A DNS server allows zone transfers.

0.0 CVSS
68.5% EPSS
1997-07-01
CVE-2006-4685 ⚪ Do wiadomości
appscloud

The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other …

2.6 CVSS
55.4% EPSS
microsoft 2006-10-10
CVE-1999-0612 ⚪ Do wiadomości

A version of finger is running that exposes valid user information to any entity on the network.

0.0 CVSS
68.2% EPSS
gnu 1997-03-01
CVE-2013-10068 ⚪ Do wiadomości

Foxit Reader versions through 5.4.5.0114, including the bundled Foxit Reader Plugin 2.2.1.530, contains a stack-based buffer overflow vulnerability in the npFoxitReaderPlugin.dll module. When a PDF file is loaded from a …

0.0 CVSS
58.7% EPSS
buffer-overflow 2025-08-05
CVE-2012-10047 ⚪ Do wiadomości

Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is not properly sanitized, allowing attackers to in…

0.0 CVSS
53.2% EPSS
rcesql-injection 2025-08-08
CVE-2012-10024 ⚪ Do wiadomości

XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request…

0.0 CVSS
43.2% EPSS
path-traversal 2025-08-05
CVE-2012-10032 ⚪ Do wiadomości

Maxthon3 version 3.2.2 build 1000 and prior are vulnerable to cross context scripting (XCS) via the about:history page. The browser’s trusted zone improperly handles injected script content, allowing attackers to execute…

0.0 CVSS
43.0% EPSS
2025-08-05
CVE-2015-2808 ⚪ Do wiadomości

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recover…

3.7 CVSS
23.4% EPSS
huawei 2015-04-01
CVE-1999-1538 ⚪ Do wiadomości
appscloud

When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information…

2.1 CVSS
25.5% EPSS
microsoftexploit 1999-01-14
CVE-1999-0031 ⚪ Do wiadomości

JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.

2.6 CVSS
18.3% EPSS
netscape 1997-07-08
CVE-1999-0869 ⚪ Do wiadomości
appscloud

Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.

2.6 CVSS
17.3% EPSS
microsoft 1998-12-01
CVE-2006-4842 ⚪ Do wiadomości

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users t…

3.6 CVSS
12.2% EPSS
netscape 2006-10-12
CVE-2024-51788 ⚪ Do wiadomości

Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Sto…

0.0 CVSS
29.6% EPSS
2024-11-11
CVE-2025-26793 ⚪ Do wiadomości

The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change the…

0.0 CVSS
27.2% EPSS
2025-02-15
CVE-2024-28085 ⚪ Do wiadomości
os

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, bu…

3.3 CVSS
10.2% EPSS
debianexploit 2024-03-27
CVE-1999-0487 ⚪ Do wiadomości
appscloud

The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.

2.6 CVSS
13.3% EPSS
microsoft 1999-05-01
CVE-2024-52375 ⚪ Do wiadomości

Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative datasets-manager-by-arttia-creative.This issue affects Datasets Manager by Arttia Creative: from n/a th…

0.0 CVSS
25.7% EPSS
2024-11-14
CVE-1999-0870 ⚪ Do wiadomości
appscloud

Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.

2.6 CVSS
12.5% EPSS
microsoft 1998-10-01
CVE-2010-0733 ⚪ Do wiadomości
apps

Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with ma…

3.5 CVSS
7.7% EPSS
postgresqldos 2010-03-19
CVE-1999-0871 ⚪ Do wiadomości
appscloud

Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.

2.6 CVSS
12.2% EPSS
microsoft 1998-09-04
CVE-2006-5432 ⚪ Do wiadomości

Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) em…

2.6 CVSS
11.8% EPSS
CVE-1999-1453 ⚪ Do wiadomości
appscloud

Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.

2.6 CVSS
11.2% EPSS
microsoftexploit 1999-02-02
CVE-2016-7429 ⚪ Do wiadomości

NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communication with a source) by sending a respons…

3.7 CVSS
5.2% EPSS
ntpdos 2017-01-13
CVE-2014-2287 ⚪ Do wiadomości

channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain…

3.5 CVSS
5.2% EPSS
digiumdos 2014-04-18
CVE-2010-0716 ⚪ Do wiadomości
appscloud

_layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), whi…

3.5 CVSS
4.7% EPSS
microsoftexploitxss 2010-02-26
CVE-2024-12970 ⚪ Do wiadomości

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection. This issue affects Pardus OS My Computer: bef…

3.9 CVSS
2.7% EPSS
rce 2025-01-06
CVE-2014-2289 ⚪ Do wiadomości

res/res_pjsip_exten_state.c in the PJSIP channel driver in Asterisk Open Source 12.x before 12.1.0 allows remote authenticated users to cause a denial of service (crash) via a SUBSCRIBE request without any Accept headers…

3.5 CVSS
3.7% EPSS
digiumdos 2014-04-18
CVE-2008-5161 ⚪ Do wiadomości

Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux o…

3.7 CVSS
1.8% EPSS
ssh 2008-11-19
CVE-2023-48231 ⚪ Do wiadomości

Vim is an open source command line text editor. When closing a window, vim may try to access already freed window structure. Exploitation beyond crashing the application has not been shown to be viable. This issue has be…

3.9 CVSS
0.7% EPSS
fedoraproject 2023-11-16
CVE-2023-48232 ⚪ Do wiadomości

Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset for overlong lines and smooth scrolling is enabled and the cpo-settings include the 'n' flag. This may…

3.9 CVSS
0.7% EPSS
fedoraproject 2023-11-16
CVE-2024-45615 ⚪ Do wiadomości
os

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).

3.9 CVSS
0.4% EPSS
redhat 2024-09-03
CVE-2024-45616 ⚪ Do wiadomości
os

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs.…

3.9 CVSS
0.4% EPSS
redhat 2024-09-03
CVE-2025-5918 ⚪ Do wiadomości
os

A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can le…

3.9 CVSS
0.3% EPSS
redhat 2025-06-09
CVE-2024-45617 ⚪ Do wiadomości
os

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs.…

3.9 CVSS
0.3% EPSS
redhat 2024-09-03
CVE-2024-45618 ⚪ Do wiadomości
os

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking …

3.9 CVSS
0.3% EPSS
redhat 2024-09-03
CVE-2024-45620 ⚪ Do wiadomości
os

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially…

3.9 CVSS
0.3% EPSS
redhat 2024-09-03
CVE-2010-0801 ⚪ Do wiadomości

Directory traversal vulnerability in the AutartiTarot (com_autartitarot) component 1.0.3 for Joomla! allows remote authenticated users, with "Public Back-end" group permissions, to read arbitrary files via directory trav…

3.5 CVSS
2.2% EPSS
CVE-2025-5916 ⚪ Do wiadomości
os

A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content by…

3.9 CVSS
0.1% EPSS
redhat 2025-06-09
CVE-2026-3632 ⚪ Do wiadomości
os

A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP h…

3.9 CVSS
0.1% EPSS
redhatexploitssrf 2026-03-17
CVE-2025-1939 ⚪ Do wiadomości

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actual…

3.9 CVSS
0.1% EPSS
mozilla 2025-03-04
CVE-2026-45642 ⚪ Do wiadomości
appscloud

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.

3.9 CVSS
0.1% EPSS
microsoft 2026-06-09
CVE-2017-3321 ⚪ Do wiadomości
appsos

Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: General). Supported versions that are affected are 7.2.19 and earlier, 7.3.8 and earlier and 7.4.5 and earlier. Difficult to exploit vu…

3.7 CVSS
1.1% EPSS
oracledos 2017-01-27
CVE-2026-30963 ⚪ Do wiadomości

Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to validate update requests targe…

3.9 CVSS
0.1% EPSS
CVE-2020-1968 ⚪ Do wiadomości

The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case…

3.7 CVSS
1.0% EPSS
fujitsu 2020-09-09
CVE-2026-3633 ⚪ Do wiadomości
os

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Car…

3.9 CVSS
0.0% EPSS
redhatexploit 2026-03-17
CVE-2026-3634 ⚪ Do wiadomości
os

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_se…

3.9 CVSS
0.0% EPSS
redhatexploit 2026-03-17
CVE-2025-31974 ⚪ Do wiadomości

HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modifications to critical system components, potentially i…

3.9 CVSS
0.0% EPSS
hcltech 2026-05-06
CVE-2026-27964 ⚪ Do wiadomości

FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The application reflects the…

3.9 CVSS
0.0% EPSS
xss 2026-05-18
CVE-2026-34768 ⚪ Do wiadomości

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true…

3.9 CVSS
0.0% EPSS
electronjs 2026-04-04
CVE-2026-44069 ⚪ Do wiadomości

An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a minor service disruption via crafted volume tran…

3.9 CVSS
0.0% EPSS
2026-05-21
CVE-2025-66037 ⚪ Do wiadomości

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling …

3.9 CVSS
0.0% EPSS
2026-03-30
CVE-2025-66038 ⚪ Do wiadomości

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and val…

3.9 CVSS
0.0% EPSS
2026-03-30
CVE-2016-1551 ⚪ Do wiadomości

ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that impersonate reference clocks. Because reference clocks are treated like o…

3.7 CVSS
1.0% EPSS
ntp 2017-01-27
CVE-2017-3322 ⚪ Do wiadomości
appsos

Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: NDBAPI). Supported versions that are affected are 7.2.25 and earlier, 7.3.14 and earlier, 7.4.12 and earlier and . Difficult to exploit…

3.7 CVSS
0.9% EPSS
oracledos 2017-01-27
CVE-2017-3323 ⚪ Do wiadomości
appsos

Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: General). Supported versions that are affected are 7.2.25 and earlier, 7.3.14 and earlier and 7.4.12 and earlier. Difficult to exploit …

3.7 CVSS
0.9% EPSS
oracledos 2017-01-27
CVE-2022-4031 ⚪ Do wiadomości

The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.8 via the 'file' parameter which does not properly restrict files to be edited in the context of the…

3.8 CVSS
0.3% EPSS
simple-press 2022-11-29
CVE-2026-8823 ⚪ Do wiadomości

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote…

3.8 CVSS
0.2% EPSS
mattermost 2026-06-22
CVE-2026-3832 ⚪ Do wiadomości
os

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnut…

3.7 CVSS
0.7% EPSS
redhatexploit 2026-04-30
CVE-2026-56212 ⚪ Do wiadomości

Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authentication for all team members without first enabl…

3.8 CVSS
0.2% EPSS
2026-06-20
CVE-2026-0934 ⚪ Do wiadomości
dev

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom r…

3.8 CVSS
0.2% EPSS
gitlab 2026-06-25
CVE-2026-8074 ⚪ Do wiadomości

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integratio…

3.8 CVSS
0.2% EPSS
mattermost 2026-06-22
CVE-2026-2110 ⚪ Do wiadomości

A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing a manipulation resul…

3.7 CVSS
0.7% EPSS
swiftbuyexploit 2026-02-07
CVE-2026-24656 ⚪ Do wiadomości
apps

Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configu…

3.7 CVSS
0.7% EPSS
CVE-2026-3470 ⚪ Do wiadomości
network

A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by pro…

3.8 CVSS
0.1% EPSS
sonicwall 2026-03-31
CVE-2026-13322 ⚪ Do wiadomości

A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character is received, with no len…

3.8 CVSS
0.1% EPSS
2026-06-26
CVE-2026-53809 ⚪ Do wiadomości

OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can ex…

3.8 CVSS
0.1% EPSS
openclaw 2026-06-11
CVE-2016-8328 ⚪ Do wiadomości
appsos

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unauthenticated attacker …

3.7 CVSS
0.6% EPSS
oracle 2017-01-27
CVE-2023-2434 ⚪ Do wiadomości

The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated…

3.8 CVSS
0.1% EPSS
kylephillips 2023-05-31
CVE-2024-29948 ⚪ Do wiadomości

There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending specially crafted messages to a vulnerable device, causing a service abnormality.

3.8 CVSS
0.1% EPSS
2024-04-02
CVE-2025-64350 ⚪ Do wiadomości

Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.

3.8 CVSS
0.1% EPSS
2025-10-31
CVE-2025-69015 ⚪ Do wiadomości

Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crowdsignal Forms: from n/a through <= 1.7.…

3.8 CVSS
0.1% EPSS
2025-12-30
CVE-2026-10299 ⚪ Do wiadomości

A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper…

3.8 CVSS
0.1% EPSS
2026-06-01
CVE-2025-4945 ⚪ Do wiadomości

A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted …

3.7 CVSS
0.5% EPSS
2025-05-19
CVE-2026-44459 ⚪ Do wiadomości

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-co…

3.8 CVSS
0.0% EPSS
hono 2026-05-13
CVE-2025-12656 ⚪ Do wiadomości

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all …

3.8 CVSS
0.0% EPSS
2026-06-06
CVE-2026-32715 ⚪ Do wiadomości

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-preferences endpoints allow manager role access, w…

3.8 CVSS
0.0% EPSS
mintplexlabsexploit 2026-03-16
CVE-2026-26230 ⚪ Do wiadomości

Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API endpoint which allows team administrators to demote members to guest role. Mattermost Advisory ID: MM…

3.8 CVSS
0.0% EPSS
mattermost 2026-03-16
CVE-2023-42419 ⚪ Do wiadomości

Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & acces…

3.8 CVSS
0.0% EPSS
2024-03-05
CVE-2025-47555 ⚪ Do wiadomości

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4.

3.8 CVSS
0.0% EPSS
2026-01-22
CVE-2013-6219 ⚪ Do wiadomości

Unspecified vulnerability in HP HP-UX Whitelisting (aka WLI) before A.01.02.02 on HP-UX B.11.31 allows local users to bypass intended access restrictions via unknown vectors.

3.8 CVSS
0.0% EPSS
hp 2014-04-19
CVE-2026-44987 ⚪ Do wiadomości

SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissions can change the email addresses of users with "Superuser" permissions. If the SysReptor installat…

3.8 CVSS
0.0% EPSS
2026-05-08
CVE-2026-34094 ⚪ Do wiadomości

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

3.8 CVSS
0.0% EPSS
mediawiki 2026-05-11
CVE-2026-3495 ⚪ Do wiadomości

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configurat…

3.8 CVSS
0.0% EPSS
mattermost 2026-05-18
CVE-2026-44410 ⚪ Do wiadomości

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks.

3.8 CVSS
0.0% EPSS
2026-05-26
CVE-2026-6816 ⚪ Do wiadomości

An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 throug…

3.8 CVSS
0.0% EPSS
CVE-2026-0849 ⚪ Do wiadomości

Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel memory and potentially hijack exec…

3.8 CVSS
0.0% EPSS
2026-03-16
CVE-2026-33585 ⚪ Do wiadomości

Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affect…

3.8 CVSS
0.0% EPSS
2026-05-13
CVE-2026-6923 ⚪ Do wiadomości

A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.

3.8 CVSS
0.0% EPSS
2026-05-14
CVE-2026-40510 ⚪ Do wiadomości

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption…

3.8 CVSS
0.0% EPSS
CVE-2026-40528 ⚪ Do wiadomości

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memory by supplying a craf…

3.8 CVSS
0.0% EPSS
opensc_project 2026-05-29
CVE-2026-45683 ⚪ Do wiadomości

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_probe_read instead of b…

3.8 CVSS
0.0% EPSS
CVE-2022-40696 ⚪ Do wiadomości

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2.

3.7 CVSS
0.5% EPSS
CVE-2025-49010 ⚪ Do wiadomości

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write i…

3.8 CVSS
0.0% EPSS
2026-03-30
CVE-2025-66215 ⚪ Do wiadomości

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE i…

3.8 CVSS
0.0% EPSS
2026-03-30
CVE-2026-25224 ⚪ Do wiadomości

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Appl…

3.7 CVSS
0.5% EPSS
fastify 2026-02-03
CVE-2026-2391 ⚪ Do wiadomości

### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the arr…

3.7 CVSS
0.5% EPSS
CVE-2017-3259 ⚪ Do wiadomości
appsos

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112. Difficult to exploit vulnerability allows unauthenticated att…

3.7 CVSS
0.5% EPSS
oracle 2017-01-27
CVE-2016-8330 ⚪ Do wiadomości
appsos

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with …

3.7 CVSS
0.4% EPSS
oracle 2017-01-27
CVE-2026-24883 ⚪ Do wiadomości

In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).

3.7 CVSS
0.4% EPSS
gnupgdos 2026-01-27
CVE-2023-38546 ⚪ Do wiadomości

This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates "easy handles" th…

3.7 CVSS
0.4% EPSS
haxx 2023-10-18
CVE-2021-36368 ⚪ Do wiadomości
os

An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None aut…

3.7 CVSS
0.4% EPSS
debianauth-bypass 2022-03-13
CVE-2025-3416 ⚪ Do wiadomości

A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, lead…

3.7 CVSS
0.4% EPSS
2025-04-08
CVE-2025-6052 ⚪ Do wiadomości

A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the syste…

3.7 CVSS
0.4% EPSS
gnome 2025-06-13
CVE-2023-32251 ⚪ Do wiadomości

A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can b…

3.7 CVSS
0.4% EPSS
2025-07-31
CVE-2025-3360 ⚪ Do wiadomości

A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.

3.7 CVSS
0.4% EPSS
2025-04-07
CVE-2026-13491 ⚪ Do wiadomości

A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetInstance of the file main/protocols/mqtt_protocol.cc of the component MQTT Goodbye Handler. Performing…

3.7 CVSS
0.4% EPSS
dos 2026-06-28
CVE-2026-0989 ⚪ Do wiadomości

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially c…

3.7 CVSS
0.4% EPSS
2026-01-15
CVE-2026-26013 ⚪ Do wiadomości

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token …

3.7 CVSS
0.4% EPSS
langchainssrf 2026-02-10
CVE-1999-1498 ⚪ Do wiadomości

Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.

3.6 CVSS
0.9% EPSS
slackwareexploit 1998-04-06
CVE-1999-0141 ⚪ Do wiadomości

Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.

3.7 CVSS
0.4% EPSS
netscape 1996-03-29
CVE-2026-5419 ⚪ Do wiadomości

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding…

3.7 CVSS
0.4% EPSS
2026-06-01
CVE-2026-42768 ⚪ Do wiadomości
apps

Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output.…

3.7 CVSS
0.4% EPSS
openssl 2026-06-09
CVE-2026-56355 ⚪ Do wiadomości

GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.

3.7 CVSS
0.4% EPSS
2026-06-20
CVE-1999-0717 ⚪ Do wiadomości
appscloud

A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.

2.6 CVSS
5.8% EPSS
microsoft 1999-05-07
CVE-2026-48709 ⚪ Do wiadomości

OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/api/api.go does not perform any authentication or authori…

3.7 CVSS
0.3% EPSS
2026-06-15
CVE-2025-60019 ⚪ Do wiadomości

glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location.

3.7 CVSS
0.3% EPSS
2025-09-25
CVE-2026-41848 ⚪ Do wiadomości
cloud

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPath…

3.7 CVSS
0.3% EPSS
vmwaredos 2026-06-09
CVE-1999-0401 ⚪ Do wiadomości
os

A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.

3.7 CVSS
0.3% EPSS
linux 1999-01-01
CVE-2026-44489 ⚪ Do wiadomości

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in thei…

3.7 CVSS
0.3% EPSS
axiosexploit 2026-06-11
CVE-2026-55654 ⚪ Do wiadomości
os

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is …

3.7 CVSS
0.3% EPSS
redhatdosexploit 2026-06-23
CVE-2026-13490 ⚪ Do wiadomości

A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of the component Document Handler. Such manipulati…

3.7 CVSS
0.3% EPSS
2026-06-28
CVE-1999-0123 ⚪ Do wiadomości

Race condition in Linux mailx command allows local users to read user files.

3.7 CVSS
0.3% EPSS
slackware 1995-12-01
CVE-2024-10106 ⚪ Do wiadomości

A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's buffer.

3.7 CVSS
0.3% EPSS
buffer-overflow 2025-01-09
CVE-2016-8217 ⚪ Do wiadomości

EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could be carried out by modifying a PKCS#12 file that has an integrity MAC for which the password is not …

3.7 CVSS
0.3% EPSS
dell 2017-02-03
CVE-2025-8283 ⚪ Do wiadomości
os

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as …

3.7 CVSS
0.3% EPSS
redhat 2025-07-28
CVE-2026-48931 ⚪ Do wiadomości

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**…

3.7 CVSS
0.3% EPSS
2026-06-22
CVE-2025-4527 ⚪ Do wiadomości

A security flaw has been discovered in Dígitro NGC Explorer up to 3.44.15/3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-s…

3.7 CVSS
0.3% EPSS
digitro 2025-05-11
CVE-2026-2215 ⚪ Do wiadomości

A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the file core/auth.py of the component JWT Handler. Performing a manipulation of the argument SECRET_KEY…

3.7 CVSS
0.3% EPSS
2026-02-09
CVE-2022-21624 ⚪ Do wiadomości
appsos

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Ora…

3.7 CVSS
0.3% EPSS
oracle 2022-10-18
CVE-2026-56368 ⚪ Do wiadomości

ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafte…

3.7 CVSS
0.3% EPSS
imagemagickdos 2026-06-24
CVE-2026-37977 ⚪ Do wiadomości
os

A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-Managed Access (UMA) token endpoint. This flaw occurs because the `azp`…

3.7 CVSS
0.3% EPSS
redhat 2026-04-06
CVE-2026-42770 ⚪ Do wiadomości
apps

Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carryi…

3.7 CVSS
0.3% EPSS
openssl 2026-06-09
CVE-2026-11525 ⚪ Do wiadomości

Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec valu…

3.7 CVSS
0.3% EPSS
nodejs 2026-06-17
CVE-2023-37867 ⚪ Do wiadomości

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: fro…

3.7 CVSS
0.2% EPSS
CVE-2026-56367 ⚪ Do wiadomości

ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on 32-bit builds. Proces…

3.7 CVSS
0.2% EPSS
imagemagick 2026-06-21
CVE-2026-6733 ⚪ Do wiadomości

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a requ…

3.7 CVSS
0.2% EPSS
nodejs 2026-06-17
CVE-2026-56968 ⚪ Do wiadomości

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

3.7 CVSS
0.2% EPSS
2026-06-23
CVE-2022-39399 ⚪ Do wiadomości

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM E…

3.7 CVSS
0.2% EPSS
netapp 2022-10-18
CVE-2026-41000 ⚪ Do wiadomości

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, …

3.7 CVSS
0.2% EPSS
2026-06-11
CVE-2026-56378 ⚪ Do wiadomości

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resu…

3.7 CVSS
0.2% EPSS
imagemagickdos 2026-06-21
CVE-2026-53540 ⚪ Do wiadomości

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Leng…

3.7 CVSS
0.2% EPSS
fastapiexpert 2026-06-22
CVE-2026-57288 ⚪ Do wiadomości
dev

Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP …

3.7 CVSS
0.2% EPSS
jenkins 2026-06-24
CVE-2026-13510 ⚪ Do wiadomości

A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/deployment.ts of the component Password Protection Handler. …

3.7 CVSS
0.2% EPSS
2026-06-28
CVE-2006-5883 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) dir parameter in (a) seldir.html, and the (2) user and (3) dir paramete…

3.5 CVSS
1.2% EPSS
cpanelexploitxss 2006-11-14
CVE-2023-3947 ⚪ Do wiadomości

The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapi_encrypt_decrypt' function in versions up to, and including, 4.2.1. This…

3.7 CVSS
0.2% EPSS
imdpen 2023-07-26
CVE-2026-53607 ⚪ Do wiadomości

ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: true` is enabled on `@apostrophecms/file` (a documented SEO feature for serving uploaded files …

3.7 CVSS
0.2% EPSS
ssrf 2026-06-12
CVE-2022-21619 ⚪ Do wiadomości
appsos

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19;…

3.7 CVSS
0.2% EPSS
oracle 2022-10-18
CVE-2016-3045 ⚪ Do wiadomości

IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser histo…

3.7 CVSS
0.2% EPSS
ibm 2017-02-01
CVE-2026-53837 ⚪ Do wiadomości

OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass intended DM policy decisions by sending crafted M…

3.7 CVSS
0.2% EPSS
openclaw 2026-06-12
CVE-2026-24870 ⚪ Do wiadomości

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

3.7 CVSS
0.2% EPSS
ixray-team 2026-01-27
CVE-2026-54282 ⚪ Do wiadomości

Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{pa…

3.7 CVSS
0.2% EPSS
encode 2026-06-22
CVE-2026-13482 ⚪ Do wiadomości

A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the component User ID Handler. The manipulation results in use of weak hash.…

3.7 CVSS
0.2% EPSS
2026-06-28
CVE-2023-28786 ⚪ Do wiadomości

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SolidWP Solid Security – Password, Two Factor Authentication, and Brute Force Protection.This issue affects Solid Security – Password, Two Factor Authe…

3.7 CVSS
0.2% EPSS
solidwp 2023-12-29
CVE-2016-0297 ⚪ Do wiadomości

IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the middle techniques.

3.7 CVSS
0.2% EPSS
ibm 2017-02-01
CVE-2026-9143 ⚪ Do wiadomości

There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen.  This may silently discard high bits if a size value exceeded the target type's range. This a…

3.7 CVSS
0.2% EPSS
ni 2026-06-19
CVE-2026-53537 ⚪ Do wiadomości

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/59…

3.7 CVSS
0.2% EPSS
fastapiexpert 2026-06-22
CVE-2026-53538 ⚪ Do wiadomości

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, moder…

3.7 CVSS
0.2% EPSS
fastapiexpert 2026-06-22
CVE-2026-56376 ⚪ Do wiadomości

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing special…

3.7 CVSS
0.2% EPSS
imagemagickdos 2026-06-23
CVE-2017-6052 ⚪ Do wiadomości

A Man-in-the-Middle issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. Communication channel endpoints are not verified, which may allow a remote attacker to access or influence communications betwe…

3.7 CVSS
0.2% EPSS
hyundai 2017-04-26
CVE-2026-44546 ⚪ Do wiadomości

daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twisted does not treat \x0b, \x0c, \x1c, \x1d, \x1e, or \x85 as header line s…

3.7 CVSS
0.2% EPSS
djangoproject 2026-06-03
CVE-2023-40160 ⚪ Do wiadomości

Directory traversal vulnerability exists in Mailing List Search CGI (pmmls.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a remote attacker may obtain arbitrary f…

3.7 CVSS
0.2% EPSS
path-traversal 2024-03-18
CVE-2026-41852 ⚪ Do wiadomości
cloud

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended a…

3.7 CVSS
0.2% EPSS
vmware 2026-06-09
CVE-2026-24934 ⚪ Do wiadomości

The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a Man-in-th…

3.7 CVSS
0.2% EPSS
asustor 2026-02-03
CVE-2024-43944 ⚪ Do wiadomości

Authentication Bypass by Spoofing vulnerability in ilyasine Maintenance & Coming Soon Redirect Animation maintenance-coming-soon-redirect-animation allows Identity Spoofing.This issue affects Maintenance & Coming Soon Re…

3.7 CVSS
0.1% EPSS
auth-bypass 2024-08-29
CVE-2024-3735 ⚪ Do wiadomości

A vulnerability was found in Smart Office up to 20240405. It has been classified as problematic. Affected is an unknown function of the file Main.aspx. The manipulation of the argument New Password/Confirm Password with …

3.7 CVSS
0.1% EPSS
2024-04-13
CVE-2025-40745 ⚪ Do wiadomości

A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602),…

3.7 CVSS
0.1% EPSS
siemens 2026-04-14
CVE-2016-5953 ⚪ Do wiadomości

IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session …

3.7 CVSS
0.1% EPSS
ibm 2017-02-01
CVE-2026-41694 ⚪ Do wiadomości
cloud

Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Servic…

3.7 CVSS
0.1% EPSS
vmware 2026-06-10
CVE-2024-52963 ⚪ Do wiadomości
network

A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets…

3.7 CVSS
0.1% EPSS
fortinetdos 2025-01-14
CVE-2026-44071 ⚪ Do wiadomości

Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of service via memory errors t…

3.7 CVSS
0.1% EPSS
buffer-overflowdos 2026-05-21
CVE-2024-2355 ⚪ Do wiadomości

A vulnerability has been found in keerti1924 Secret-Coder-PHP-Project 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /secret_coder.sql. The manipulation leads to…

3.7 CVSS
0.1% EPSS
2024-03-10
CVE-2025-23384 ⚪ Do wiadomości

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2.1), SCALANCE M804PB (6GK5804-0AP00-2…

3.7 CVSS
0.1% EPSS
2025-03-11
CVE-2020-8284 ⚪ Do wiadomości
os

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherw…

3.7 CVSS
0.1% EPSS
apple 2020-12-14
CVE-2026-44074 ⚪ Do wiadomości

Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker to cause a minor ser…

3.7 CVSS
0.1% EPSS
2026-05-21
CVE-2000-1246 ⚪ Do wiadomości

NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allows remote authenticated users to cause a denial of service (abend) by sending an RNTO command after a failed RNFR command.

3.5 CVSS
1.1% EPSS
novelldos 2010-04-05
CVE-2026-5123 ⚪ Do wiadomości

A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument data[1] can lead to off-by-one. The attack m…

3.7 CVSS
0.1% EPSS
osrg 2026-03-30
CVE-2026-44075 ⚪ Do wiadomości

A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session option handling that ma…

3.7 CVSS
0.1% EPSS
2026-05-21
CVE-2026-11555 ⚪ Do wiadomości
network

A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. …

3.7 CVSS
0.1% EPSS
dlink 2026-06-08
CVE-2026-3184 ⚪ Do wiadomości

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could…

3.7 CVSS
0.1% EPSS
kernel 2026-04-03
CVE-2026-32690 ⚪ Do wiadomości
apps

Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sens…

3.7 CVSS
0.1% EPSS
apache 2026-04-18
CVE-2006-4393 ⚪ Do wiadomości
os

Unspecified vulnerability in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, when Fast User Switching is enabled, allows local users to gain access to Kerberos tickets of other users.

3.7 CVSS
0.1% EPSS
apple 2006-10-03
CVE-2026-43514 ⚪ Do wiadomości
apps

Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, fr…

3.7 CVSS
0.1% EPSS
apache 2026-05-12
CVE-2025-0824 ⚪ Do wiadomości

Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual Storage Platform One Block 23, 24, 26, 28: before DKCMAIN A3-04-21-40/00, E…

3.7 CVSS
0.1% EPSS
2026-06-29
CVE-1999-0159 ⚪ Do wiadomości
network

Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases.

3.5 CVSS
1.1% EPSS
cisco 1998-08-12
CVE-2006-5453 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote authenticated users to inject arbitrary web script o…

3.5 CVSS
1.1% EPSS
mozillaxss 2006-10-23
CVE-2026-0988 ⚪ Do wiadomości

A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are prov…

3.7 CVSS
0.1% EPSS
buffer-overflowdos 2026-01-21
CVE-2026-32897 ⚪ Do wiadomości

OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation when commands.ownerDisplay is set to hash and commands.ownerDisplaySecret is unset, creating dual-us…

3.7 CVSS
0.1% EPSS
openclaw 2026-03-21
CVE-2026-4831 ⚪ Do wiadomości

A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protected Share Handler. Perf…

3.7 CVSS
0.1% EPSS
2026-03-26
CVE-2026-5360 ⚪ Do wiadomości

A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack may be launched remotely. This attack is character…

3.7 CVSS
0.1% EPSS
free5gc 2026-04-02
CVE-2014-2459 ⚪ Do wiadomości
appsos

Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.3.2 and 6.3.3 allows local users to affect confidentiality, integrity, and availability via unknown vect…

3.7 CVSS
0.1% EPSS
oracle 2014-04-16
CVE-2023-21968 ⚪ Do wiadomości
appsos

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; O…

3.7 CVSS
0.1% EPSS
oracle 2023-04-18