Low — Podatności CVE o niskim poziomie ważności (CVSS < 4.0). Monitoruj i oceń ryzyko. Znaleziono 200 CVE.

Inne poziomy: 🔴 Critical 🟠 High 🟡 Medium
CVE-2013-2423 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOT…

3.7 CVSS
93.4% EPSS
oracle 2013-04-17
CVE-2024-55550 🔴 Łataj teraz KEV

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated …

2.7 CVSS
38.1% EPSS
CVE-2026-18577 🔴 Łataj teraz KEV

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

0.0 CVSS
1.5% EPSS
auth-bypass 2026-08-02
CVE-2026-48907 🔴 Łataj teraz KEV

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

0.0 CVSS
0.8% EPSS
2026-06-05
CVE-2015-4000 ⚪ Do wiadomości
appsos

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgra…

3.7 CVSS
92.3% EPSS
oracle 2015-05-21
CVE-2014-3566 ⚪ Do wiadomości
apps

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a…

3.4 CVSS
93.5% EPSS
openssl 2014-10-15
CVE-2006-5614 ⚪ Do wiadomości
appscloud

Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, w…

2.6 CVSS
88.4% EPSS
microsoftdos 2006-10-31
CVE-2025-34037 ⚪ Do wiadomości

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied inp…

0.0 CVSS
86.0% EPSS
rce 2025-06-24
CVE-2012-10027 ⚪ Do wiadomości

WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a t…

0.0 CVSS
73.7% EPSS
rce 2025-08-05
CVE-2010-0926 ⚪ Do wiadomości

The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, an…

3.5 CVSS
52.4% EPSS
sambapath-traversal 2010-03-10
CVE-2006-5229 ⚪ Do wiadomości

OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via timing discrepancies in which responses t…

2.6 CVSS
56.6% EPSS
novell 2006-10-10
CVE-1999-0532 ⚪ Do wiadomości

A DNS server allows zone transfers.

0.0 CVSS
68.5% EPSS
1997-07-01
CVE-2006-4685 ⚪ Do wiadomości
appscloud

The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other …

2.6 CVSS
55.4% EPSS
microsoft 2006-10-10
CVE-1999-0612 ⚪ Do wiadomości

A version of finger is running that exposes valid user information to any entity on the network.

0.0 CVSS
68.2% EPSS
gnu 1997-03-01
CVE-2013-10068 ⚪ Do wiadomości

Foxit Reader versions through 5.4.5.0114, including the bundled Foxit Reader Plugin 2.2.1.530, contains a stack-based buffer overflow vulnerability in the npFoxitReaderPlugin.dll module. When a PDF file is loaded from a …

0.0 CVSS
58.7% EPSS
buffer-overflow 2025-08-05
CVE-2012-10047 ⚪ Do wiadomości

Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is not properly sanitized, allowing attackers to in…

0.0 CVSS
53.2% EPSS
rcesql-injection 2025-08-08
CVE-2012-10024 ⚪ Do wiadomości

XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request…

0.0 CVSS
43.2% EPSS
path-traversal 2025-08-05
CVE-2012-10032 ⚪ Do wiadomości

Maxthon3 version 3.2.2 build 1000 and prior are vulnerable to cross context scripting (XCS) via the about:history page. The browser’s trusted zone improperly handles injected script content, allowing attackers to execute…

0.0 CVSS
43.0% EPSS
2025-08-05
CVE-2015-2808 ⚪ Do wiadomości

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recover…

3.7 CVSS
23.4% EPSS
huawei 2015-04-01
CVE-1999-1538 ⚪ Do wiadomości
appscloud

When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information…

2.1 CVSS
25.5% EPSS
microsoftexploit 1999-01-14
CVE-1999-0031 ⚪ Do wiadomości

JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.

2.6 CVSS
18.3% EPSS
netscape 1997-07-08
CVE-1999-0869 ⚪ Do wiadomości
appscloud

Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.

2.6 CVSS
17.3% EPSS
microsoft 1998-12-01
CVE-2006-4842 ⚪ Do wiadomości

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users t…

3.6 CVSS
12.2% EPSS
netscape 2006-10-12
CVE-2024-51788 ⚪ Do wiadomości

Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Sto…

0.0 CVSS
29.6% EPSS
2024-11-11
CVE-2019-11045 ⚪ Do wiadomości
os

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabiliti…

3.7 CVSS
8.8% EPSS
canonicalexploit 2019-12-23
CVE-2025-26793 ⚪ Do wiadomości

The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change the…

0.0 CVSS
27.2% EPSS
2025-02-15
CVE-2024-28085 ⚪ Do wiadomości
os

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, bu…

3.3 CVSS
10.2% EPSS
debianexploit 2024-03-27
CVE-1999-0487 ⚪ Do wiadomości
appscloud

The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.

2.6 CVSS
13.3% EPSS
microsoft 1999-05-01
CVE-2024-52375 ⚪ Do wiadomości

Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative datasets-manager-by-arttia-creative.This issue affects Datasets Manager by Arttia Creative: from n/a th…

0.0 CVSS
25.7% EPSS
2024-11-14
CVE-1999-0870 ⚪ Do wiadomości
appscloud

Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.

2.6 CVSS
12.5% EPSS
microsoft 1998-10-01
CVE-2010-0733 ⚪ Do wiadomości
apps

Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with ma…

3.5 CVSS
7.7% EPSS
postgresqldos 2010-03-19
CVE-1999-0871 ⚪ Do wiadomości
appscloud

Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.

2.6 CVSS
12.2% EPSS
microsoft 1998-09-04
CVE-2006-5432 ⚪ Do wiadomości

Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) em…

2.6 CVSS
11.8% EPSS
CVE-1999-1453 ⚪ Do wiadomości
appscloud

Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.

2.6 CVSS
11.2% EPSS
microsoftexploit 1999-02-02
CVE-2016-7429 ⚪ Do wiadomości

NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communication with a source) by sending a respons…

3.7 CVSS
5.2% EPSS
ntpdos 2017-01-13
CVE-2019-11044 ⚪ Do wiadomości
dev

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabil…

3.7 CVSS
5.1% EPSS
phpexploit 2019-12-23
CVE-2014-2287 ⚪ Do wiadomości

channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain…

3.5 CVSS
5.2% EPSS
digiumdos 2014-04-18
CVE-2019-11046 ⚪ Do wiadomości
os

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string cont…

3.7 CVSS
4.1% EPSS
canonical 2019-12-23
CVE-2010-0716 ⚪ Do wiadomości
appscloud

_layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), whi…

3.5 CVSS
4.7% EPSS
microsoftexploitxss 2010-02-26
CVE-2024-12970 ⚪ Do wiadomości

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection. This issue affects Pardus OS My Computer: bef…

3.9 CVSS
2.7% EPSS
rce 2025-01-06
CVE-2014-2289 ⚪ Do wiadomości

res/res_pjsip_exten_state.c in the PJSIP channel driver in Asterisk Open Source 12.x before 12.1.0 allows remote authenticated users to cause a denial of service (crash) via a SUBSCRIBE request without any Accept headers…

3.5 CVSS
3.7% EPSS
digiumdos 2014-04-18
CVE-2008-5161 ⚪ Do wiadomości

Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux o…

3.7 CVSS
1.8% EPSS
ssh 2008-11-19
CVE-2023-48231 ⚪ Do wiadomości

Vim is an open source command line text editor. When closing a window, vim may try to access already freed window structure. Exploitation beyond crashing the application has not been shown to be viable. This issue has be…

3.9 CVSS
0.7% EPSS
fedoraproject 2023-11-16
CVE-2023-48232 ⚪ Do wiadomości

Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset for overlong lines and smooth scrolling is enabled and the cpo-settings include the 'n' flag. This may…

3.9 CVSS
0.7% EPSS
fedoraproject 2023-11-16
CVE-2024-45615 ⚪ Do wiadomości
os

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).

3.9 CVSS
0.4% EPSS
redhat 2024-09-03
CVE-2024-45616 ⚪ Do wiadomości
os

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs.…

3.9 CVSS
0.4% EPSS
redhat 2024-09-03
CVE-2025-5918 ⚪ Do wiadomości
os

A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can le…

3.9 CVSS
0.4% EPSS
redhat 2025-06-09
CVE-2024-45617 ⚪ Do wiadomości
os

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs.…

3.9 CVSS
0.3% EPSS
redhat 2024-09-03
CVE-2024-45618 ⚪ Do wiadomości
os

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking …

3.9 CVSS
0.3% EPSS
redhat 2024-09-03
CVE-2024-45620 ⚪ Do wiadomości
os

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially…

3.9 CVSS
0.3% EPSS
redhat 2024-09-03
CVE-2024-31636 ⚪ Do wiadomości

An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component.

3.9 CVSS
0.2% EPSS
lief-projectexploit 2024-05-03
CVE-2010-0801 ⚪ Do wiadomości

Directory traversal vulnerability in the AutartiTarot (com_autartitarot) component 1.0.3 for Joomla! allows remote authenticated users, with "Public Back-end" group permissions, to read arbitrary files via directory trav…

3.5 CVSS
2.2% EPSS
CVE-2026-15028 ⚪ Do wiadomości

A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing…

3.9 CVSS
0.2% EPSS
CVE-2026-18280 ⚪ Do wiadomości

Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authenti…

3.9 CVSS
0.2% EPSS
buffer-overflowrce 2026-08-20
CVE-2025-59700 ⚪ Do wiadomości

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with root access to modify the Recovery Partition (beca…

3.9 CVSS
0.2% EPSS
entrustexploit 2025-12-02
CVE-2025-5916 ⚪ Do wiadomości
os

A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content by…

3.9 CVSS
0.2% EPSS
redhat 2025-06-09
CVE-2020-26623 ⚪ Do wiadomości

SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.

3.8 CVSS
0.7% EPSS
CVE-2020-26624 ⚪ Do wiadomości

A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.

3.8 CVSS
0.7% EPSS
CVE-2020-26625 ⚪ Do wiadomości

A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.

3.8 CVSS
0.7% EPSS
CVE-2021-38365 ⚪ Do wiadomości

Winner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the power-indicator LED via a telescope and an electro-optical sensor, aka a "Glowworm" attack.

3.7 CVSS
1.1% EPSS
tonewinnerexploit 2021-08-10
CVE-2026-3632 ⚪ Do wiadomości
os

A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP h…

3.9 CVSS
0.1% EPSS
redhatexploitssrf 2026-03-17
CVE-2026-34768 ⚪ Do wiadomości

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true…

3.9 CVSS
0.1% EPSS
electronjs 2026-04-04
CVE-2025-1939 ⚪ Do wiadomości

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actual…

3.9 CVSS
0.1% EPSS
mozilla 2025-03-04
CVE-2026-8029 ⚪ Do wiadomości

The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone nu…

3.9 CVSS
0.1% EPSS
sql-injection 2026-08-05
CVE-2026-59846 ⚪ Do wiadomości
os

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

3.9 CVSS
0.1% EPSS
redhat 2026-07-21
CVE-2026-45642 ⚪ Do wiadomości
appscloud

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.

3.9 CVSS
0.1% EPSS
microsoft 2026-06-09
CVE-2026-27964 ⚪ Do wiadomości

FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The application reflects the…

3.9 CVSS
0.1% EPSS
xss 2026-05-18
CVE-2026-14971 ⚪ Do wiadomości

IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions.

3.9 CVSS
0.1% EPSS
ibm 2026-07-17
CVE-2026-19411 ⚪ Do wiadomości

A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI …

3.9 CVSS
0.1% EPSS
dos 2026-08-10
CVE-2026-44069 ⚪ Do wiadomości

An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a minor service disruption via crafted volume tran…

3.9 CVSS
0.1% EPSS
2026-05-21
CVE-2026-16791 ⚪ Do wiadomości

A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-ge…

3.9 CVSS
0.1% EPSS
2026-08-04
CVE-2017-3321 ⚪ Do wiadomości
appsos

Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: General). Supported versions that are affected are 7.2.19 and earlier, 7.3.8 and earlier and 7.4.5 and earlier. Difficult to exploit vu…

3.7 CVSS
1.1% EPSS
oracledos 2017-01-27
CVE-2026-23734 ⚪ Do wiadomości

XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/…

0.0 CVSS
19.6% EPSS
path-traversal 2026-05-20
CVE-2026-30963 ⚪ Do wiadomości

Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to validate update requests targe…

3.9 CVSS
0.1% EPSS
CVE-2020-1968 ⚪ Do wiadomości

The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case…

3.7 CVSS
1.0% EPSS
fujitsu 2020-09-09
CVE-2026-3633 ⚪ Do wiadomości
os

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Car…

3.9 CVSS
0.0% EPSS
redhatexploit 2026-03-17
CVE-2026-3634 ⚪ Do wiadomości
os

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_se…

3.9 CVSS
0.0% EPSS
redhatexploit 2026-03-17
CVE-2025-31974 ⚪ Do wiadomości

HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modifications to critical system components, potentially i…

3.9 CVSS
0.0% EPSS
hcltech 2026-05-06
CVE-2025-66037 ⚪ Do wiadomości

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling …

3.9 CVSS
0.0% EPSS
2026-03-30
CVE-2025-66038 ⚪ Do wiadomości

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and val…

3.9 CVSS
0.0% EPSS
2026-03-30
CVE-2016-1551 ⚪ Do wiadomości

ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that impersonate reference clocks. Because reference clocks are treated like o…

3.7 CVSS
1.0% EPSS
ntp 2017-01-27
CVE-2017-3322 ⚪ Do wiadomości
appsos

Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: NDBAPI). Supported versions that are affected are 7.2.25 and earlier, 7.3.14 and earlier, 7.4.12 and earlier and . Difficult to exploit…

3.7 CVSS
0.9% EPSS
oracledos 2017-01-27
CVE-2017-3323 ⚪ Do wiadomości
appsos

Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: General). Supported versions that are affected are 7.2.25 and earlier, 7.3.14 and earlier and 7.4.12 and earlier. Difficult to exploit …

3.7 CVSS
0.9% EPSS
oracledos 2017-01-27
CVE-2026-15326 ⚪ Do wiadomości

A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the component Theme Installation. Such manipulation of the argument metadata.…

3.8 CVSS
0.4% EPSS
path-traversal 2026-07-10
CVE-2026-17043 ⚪ Do wiadomości

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.

3.8 CVSS
0.4% EPSS
path-traversal 2026-08-13
CVE-2022-4031 ⚪ Do wiadomości

The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.8 via the 'file' parameter which does not properly restrict files to be edited in the context of the…

3.8 CVSS
0.3% EPSS
simple-press 2022-11-29
CVE-2026-3470 ⚪ Do wiadomości
network

A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by pro…

3.8 CVSS
0.3% EPSS
sonicwall 2026-03-31
CVE-2026-6816 ⚪ Do wiadomości

An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 throug…

3.8 CVSS
0.3% EPSS
CVE-2025-8889 ⚪ Do wiadomości

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (…

3.8 CVSS
0.3% EPSS
eliehannaexploit 2025-09-09
CVE-2026-70467 ⚪ Do wiadomości

A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all vers…

3.8 CVSS
0.3% EPSS
ssrf 2026-08-12
CVE-2026-62532 ⚪ Do wiadomości
appsos

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privilege…

3.8 CVSS
0.3% EPSS
oracle 2026-08-18
CVE-2026-3832 ⚪ Do wiadomości
os

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnut…

3.7 CVSS
0.7% EPSS
redhatexploit 2026-04-30
CVE-2026-14222 ⚪ Do wiadomości

The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configura…

3.8 CVSS
0.2% EPSS
2026-07-30
CVE-2026-8823 ⚪ Do wiadomości

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote…

3.8 CVSS
0.2% EPSS
mattermost 2026-06-22
CVE-2026-76348 ⚪ Do wiadomości

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capability could send a read request to Search Head Clus…

3.8 CVSS
0.2% EPSS
splunkdos 2026-08-19
CVE-2026-40510 ⚪ Do wiadomości

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption…

3.8 CVSS
0.2% EPSS
CVE-2026-56212 ⚪ Do wiadomości

Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authentication for all team members without first enabl…

3.8 CVSS
0.2% EPSS
2026-06-20
CVE-2026-0934 ⚪ Do wiadomości
dev

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom r…

3.8 CVSS
0.2% EPSS
gitlab 2026-06-25
CVE-2026-56281 ⚪ Do wiadomości

Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Ana…

3.8 CVSS
0.2% EPSS
sql-injection 2026-07-12
CVE-2026-67334 ⚪ Do wiadomości

better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse d…

3.8 CVSS
0.2% EPSS
2026-08-01
CVE-2026-8074 ⚪ Do wiadomości

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integratio…

3.8 CVSS
0.2% EPSS
mattermost 2026-06-22
CVE-2025-14779 ⚪ Do wiadomości

The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal …

3.8 CVSS
0.2% EPSS
wso2 2026-08-06
CVE-2026-14221 ⚪ Do wiadomości

The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with …

3.8 CVSS
0.2% EPSS
2026-07-30
CVE-2026-2110 ⚪ Do wiadomości

A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing a manipulation resul…

3.7 CVSS
0.7% EPSS
swiftbuyexploit 2026-02-07
CVE-2026-59269 ⚪ Do wiadomości

A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions were true: the Pinniped Supervisor server is runn…

3.8 CVSS
0.2% EPSS
2026-07-09
CVE-2026-12730 ⚪ Do wiadomości

IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow…

3.8 CVSS
0.2% EPSS
ibm 2026-08-05
CVE-2026-24656 ⚪ Do wiadomości
apps

Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configu…

3.7 CVSS
0.7% EPSS
CVE-2026-44987 ⚪ Do wiadomości

SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissions can change the email addresses of users with "Superuser" permissions. If the SysReptor installat…

3.8 CVSS
0.2% EPSS
2026-05-08
CVE-2026-40528 ⚪ Do wiadomości

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memory by supplying a craf…

3.8 CVSS
0.1% EPSS
opensc_project 2026-05-29
CVE-2026-60405 ⚪ Do wiadomości
appsos

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability al…

3.8 CVSS
0.1% EPSS
oracle 2026-07-21
CVE-2026-14197 ⚪ Do wiadomości

The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in th…

3.8 CVSS
0.1% EPSS
2026-08-01
CVE-2026-14211 ⚪ Do wiadomości

The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee wit…

3.8 CVSS
0.1% EPSS
2026-08-10
CVE-2026-17011 ⚪ Do wiadomości

The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site…

3.8 CVSS
0.1% EPSS
2026-08-09
CVE-2025-51591 ⚪ Do wiadomości

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can…

3.7 CVSS
0.6% EPSS
ssrf 2025-07-11
CVE-2026-53809 ⚪ Do wiadomości

OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can ex…

3.8 CVSS
0.1% EPSS
openclaw 2026-06-11
CVE-2026-13322 ⚪ Do wiadomości

A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character is received, with no len…

3.8 CVSS
0.1% EPSS
kubevirt 2026-06-26
CVE-2025-4527 ⚪ Do wiadomości

A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enfo…

3.7 CVSS
0.6% EPSS
digitro 2025-05-11
CVE-2016-8328 ⚪ Do wiadomości
appsos

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unauthenticated attacker …

3.7 CVSS
0.6% EPSS
oracle 2017-01-27
CVE-2026-26080 ⚪ Do wiadomości

HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.

3.7 CVSS
0.5% EPSS
haproxy 2026-07-20
CVE-2023-2434 ⚪ Do wiadomości

The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated…

3.8 CVSS
0.1% EPSS
kylephillips 2023-05-31
CVE-2024-29948 ⚪ Do wiadomości

There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending specially crafted messages to a vulnerable device, causing a service abnormality.

3.8 CVSS
0.1% EPSS
2024-04-02
CVE-2025-64350 ⚪ Do wiadomości

Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.

3.8 CVSS
0.1% EPSS
2025-10-31
CVE-2025-69015 ⚪ Do wiadomości

Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crowdsignal Forms: from n/a through <= 1.7.…

3.8 CVSS
0.1% EPSS
2025-12-30
CVE-2026-10299 ⚪ Do wiadomości

A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper…

3.8 CVSS
0.1% EPSS
2026-06-01
CVE-2025-4945 ⚪ Do wiadomości

A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted …

3.7 CVSS
0.5% EPSS
2025-05-19
CVE-2026-48001 ⚪ Do wiadomości

Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the attacker's control. Exploitation of this issu…

3.7 CVSS
0.5% EPSS
adobe 2026-07-14
CVE-2026-44459 ⚪ Do wiadomości

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-co…

3.8 CVSS
0.0% EPSS
hono 2026-05-13
CVE-2025-12656 ⚪ Do wiadomości

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all …

3.8 CVSS
0.0% EPSS
2026-06-06
CVE-2026-32715 ⚪ Do wiadomości

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-preferences endpoints allow manager role access, w…

3.8 CVSS
0.0% EPSS
mintplexlabsexploit 2026-03-16
CVE-2026-26230 ⚪ Do wiadomości

Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API endpoint which allows team administrators to demote members to guest role. Mattermost Advisory ID: MM…

3.8 CVSS
0.0% EPSS
mattermost 2026-03-16
CVE-2023-42419 ⚪ Do wiadomości

Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & acces…

3.8 CVSS
0.0% EPSS
2024-03-05
CVE-2025-47555 ⚪ Do wiadomości

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4.

3.8 CVSS
0.0% EPSS
2026-01-22
CVE-2013-6219 ⚪ Do wiadomości

Unspecified vulnerability in HP HP-UX Whitelisting (aka WLI) before A.01.02.02 on HP-UX B.11.31 allows local users to bypass intended access restrictions via unknown vectors.

3.8 CVSS
0.0% EPSS
hp 2014-04-19
CVE-2026-34094 ⚪ Do wiadomości

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

3.8 CVSS
0.0% EPSS
mediawiki 2026-05-11
CVE-2026-3495 ⚪ Do wiadomości

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configurat…

3.8 CVSS
0.0% EPSS
mattermost 2026-05-18
CVE-2026-44410 ⚪ Do wiadomości

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks.

3.8 CVSS
0.0% EPSS
2026-05-26
CVE-2026-75773 ⚪ Do wiadomości

A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation results in improper re…

3.7 CVSS
0.5% EPSS
2026-08-18
CVE-2026-43964 ⚪ Do wiadomości

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

3.7 CVSS
0.5% EPSS
postfix 2026-05-04
CVE-2026-0849 ⚪ Do wiadomości

Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel memory and potentially hijack exec…

3.8 CVSS
0.0% EPSS
2026-03-16
CVE-2026-33585 ⚪ Do wiadomości

Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affect…

3.8 CVSS
0.0% EPSS
2026-05-13
CVE-2026-6923 ⚪ Do wiadomości

A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.

3.8 CVSS
0.0% EPSS
2026-05-14
CVE-2026-45683 ⚪ Do wiadomości

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_probe_read instead of b…

3.8 CVSS
0.0% EPSS
CVE-2026-34166 ⚪ Do wiadomości

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly accounts for memory usage when the memoryLimit option is enabled. It charge…

3.7 CVSS
0.5% EPSS
liquidjsdosexploit 2026-04-08
CVE-2022-40696 ⚪ Do wiadomości

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2.

3.7 CVSS
0.5% EPSS
CVE-2025-49010 ⚪ Do wiadomości

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write i…

3.8 CVSS
0.0% EPSS
2026-03-30
CVE-2025-66215 ⚪ Do wiadomości

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE i…

3.8 CVSS
0.0% EPSS
2026-03-30
CVE-2026-9820 ⚪ Do wiadomości

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and u…

3.8 CVSS
0.0% EPSS
mattermost 2026-07-13
CVE-2026-25224 ⚪ Do wiadomości

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Appl…

3.7 CVSS
0.5% EPSS
fastify 2026-02-03
CVE-2026-2391 ⚪ Do wiadomości

### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the arr…

3.7 CVSS
0.5% EPSS
CVE-2026-19898 ⚪ Do wiadomości

A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in imp…

3.7 CVSS
0.5% EPSS
2026-08-15
CVE-2026-35537 ⚪ Do wiadomości

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted ses…

3.7 CVSS
0.5% EPSS
CVE-2017-3259 ⚪ Do wiadomości
appsos

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112. Difficult to exploit vulnerability allows unauthenticated att…

3.7 CVSS
0.5% EPSS
oracle 2017-01-27
CVE-2026-0989 ⚪ Do wiadomości
os

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially c…

3.7 CVSS
0.5% EPSS
redhatexploit 2026-01-15
CVE-2026-8196 ⚪ Do wiadomości

A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/LoginController.java of the compone…

3.7 CVSS
0.5% EPSS
2026-05-09
CVE-2026-75774 ⚪ Do wiadomości

A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper auth…

3.7 CVSS
0.5% EPSS
2026-08-18
CVE-2016-8330 ⚪ Do wiadomości
appsos

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with …

3.7 CVSS
0.4% EPSS
oracle 2017-01-27
CVE-2026-24883 ⚪ Do wiadomości

In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).

3.7 CVSS
0.4% EPSS
gnupgdos 2026-01-27
CVE-2025-3416 ⚪ Do wiadomości

A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, lead…

3.7 CVSS
0.4% EPSS
2025-04-08
CVE-2026-58187 ⚪ Do wiadomości
apps

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,…

3.7 CVSS
0.4% EPSS
apachedos 2026-07-29
CVE-2026-3184 ⚪ Do wiadomości

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could…

3.7 CVSS
0.4% EPSS
kernel 2026-04-03
CVE-2023-38546 ⚪ Do wiadomości

This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates "easy handles" th…

3.7 CVSS
0.4% EPSS
haxx 2023-10-18
CVE-2026-5360 ⚪ Do wiadomości

A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack may be launched remotely. This attack is character…

3.7 CVSS
0.4% EPSS
free5gc 2026-04-02
CVE-2021-36368 ⚪ Do wiadomości
os

An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None aut…

3.7 CVSS
0.4% EPSS
debianauth-bypass 2022-03-13
CVE-2023-32251 ⚪ Do wiadomości

A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can b…

3.7 CVSS
0.4% EPSS
2025-07-31
CVE-2026-7303 ⚪ Do wiadomości

A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Ex…

3.7 CVSS
0.4% EPSS
2026-04-28
CVE-2025-6052 ⚪ Do wiadomości

A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the syste…

3.7 CVSS
0.4% EPSS
gnome 2025-06-13
CVE-2026-55654 ⚪ Do wiadomości
os

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is …

3.7 CVSS
0.4% EPSS
redhatdosexploit 2026-06-23
CVE-2025-3360 ⚪ Do wiadomości

A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.

3.7 CVSS
0.4% EPSS
2025-04-07
CVE-2026-59842 ⚪ Do wiadomości
os

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap re…

3.7 CVSS
0.4% EPSS
redhat 2026-07-21
CVE-2026-10216 ⚪ Do wiadomości

A vulnerability was detected in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the file server/src/routes/pairing.ts of the component claim Endpoint. The manipulation results in improper…

3.7 CVSS
0.4% EPSS
2026-06-01
CVE-2026-13491 ⚪ Do wiadomości

A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetInstance of the file main/protocols/mqtt_protocol.cc of the component MQTT Goodbye Handler. Performing…

3.7 CVSS
0.4% EPSS
dos 2026-06-28
CVE-2026-60000 ⚪ Do wiadomości

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

3.7 CVSS
0.4% EPSS
openbsddos 2026-07-08
CVE-2026-16207 ⚪ Do wiadomości

A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. The manipulation results in use of get request method with sensitive que…

3.7 CVSS
0.4% EPSS
2026-07-19
CVE-2026-19895 ⚪ Do wiadomości

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in …

3.7 CVSS
0.4% EPSS
2026-08-15
CVE-2026-19965 ⚪ Do wiadomości

A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password…

3.7 CVSS
0.4% EPSS
2026-08-17
CVE-2026-54335 ⚪ Do wiadomości

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and earlier, the _.merge(target, source) utility exported by @feathersjs/commons recursively merges sour…

3.7 CVSS
0.4% EPSS
2026-07-17
CVE-2026-26013 ⚪ Do wiadomości

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token …

3.7 CVSS
0.4% EPSS
langchainssrf 2026-02-10
CVE-1999-1498 ⚪ Do wiadomości

Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.

3.6 CVSS
0.9% EPSS
slackwareexploit 1998-04-06
CVE-2026-5419 ⚪ Do wiadomości

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding…

3.7 CVSS
0.4% EPSS
2026-06-01
CVE-2025-10939 ⚪ Do wiadomości

A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relati…

3.7 CVSS
0.4% EPSS
2025-10-28
CVE-1999-0141 ⚪ Do wiadomości

Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.

3.7 CVSS
0.4% EPSS
netscape 1996-03-29
CVE-2026-48931 ⚪ Do wiadomości

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**…

3.7 CVSS
0.4% EPSS
nodejsexploit 2026-06-22
CVE-2026-48082 ⚪ Do wiadomości

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/api/tenants/{id}/appointments/bootstrap-challenge`…

3.7 CVSS
0.4% EPSS
2026-08-06
CVE-2026-19897 ⚪ Do wiadomości

A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/auth.py of the component Login Endpoint. Such manipulation leads to improper restriction of excessive…

3.7 CVSS
0.4% EPSS
2026-08-15
CVE-2026-9373 ⚪ Do wiadomości

A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of the file /openapi/call/ of the component OpenAPI Endpoint. Such manipulation leads to improper authentication. The attack c…

3.7 CVSS
0.4% EPSS
2026-05-24
CVE-2026-42768 ⚪ Do wiadomości
apps

Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output.…

3.7 CVSS
0.4% EPSS
openssl 2026-06-09
CVE-2026-56355 ⚪ Do wiadomości

GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.

3.7 CVSS
0.4% EPSS
2026-06-20
CVE-2026-0976 ⚪ Do wiadomości

A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mis…

3.7 CVSS
0.4% EPSS
2026-01-15
CVE-2026-44071 ⚪ Do wiadomości

Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of service via memory errors t…

3.7 CVSS
0.3% EPSS
buffer-overflowdos 2026-05-21
CVE-1999-0717 ⚪ Do wiadomości
appscloud

A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.

2.6 CVSS
5.8% EPSS
microsoft 1999-05-07
CVE-2026-44074 ⚪ Do wiadomości

Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker to cause a minor ser…

3.7 CVSS
0.3% EPSS
2026-05-21
CVE-2026-44075 ⚪ Do wiadomości

A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session option handling that ma…

3.7 CVSS
0.3% EPSS
2026-05-21
CVE-2026-48709 ⚪ Do wiadomości

OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/api/api.go does not perform any authentication or authori…

3.7 CVSS
0.3% EPSS
2026-06-15
CVE-2025-60019 ⚪ Do wiadomości

glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location.

3.7 CVSS
0.3% EPSS
2025-09-25
CVE-2026-19906 ⚪ Do wiadomości

A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. Executing a manipulat…

3.7 CVSS
0.3% EPSS
2026-08-15
CVE-2026-35448 ⚪ Do wiadomości

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoint returns payment order data for any Bitcoin address without requiring authentication. The endpoint …

3.7 CVSS
0.3% EPSS
wwbnexploit 2026-04-06
CVE-2026-41848 ⚪ Do wiadomości
cloud

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPath…

3.7 CVSS
0.3% EPSS
vmwaredos 2026-06-09
CVE-2026-5413 ⚪ Do wiadomości

A vulnerability was identified in Newgen OmniDocs up to 12.0.00. Affected by this vulnerability is an unknown functionality of the file /omnidocs/GetWebApiConfiguration. The manipulation of the argument connectionDetails…

3.7 CVSS
0.3% EPSS
2026-04-02
CVE-1999-0401 ⚪ Do wiadomości
os

A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.

3.7 CVSS
0.3% EPSS
linux 1999-01-01
CVE-2026-44489 ⚪ Do wiadomości

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in thei…

3.7 CVSS
0.3% EPSS
axiosexploit 2026-06-11