CVE zaktualizowane w ostatnich 24 godzinach — 175 wpisów. Mogą zawierać nowe CVSS, EPSS, informacje o patchu lub zmiany statusu KEV.

CVE-2026-56211 🟡 Monitoruj

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to su…

7.1 CVSS
0.4% EPSS
rce 2026-06-19
CVE-2026-56209 🟡 Monitoruj

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an ar…

7.1 CVSS
0.3% EPSS
dos 2026-06-19
CVE-2026-56210 🟡 Monitoruj

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id…

7.1 CVSS
0.3% EPSS
dos 2026-06-19
CVE-2026-56208 🟡 Monitoruj

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to …

7.6 CVSS
0.4% EPSS
buffer-overflowdos 2026-06-19
CVE-2026-53362 🔴 Łataj teraz KEV
os

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / larg…

7.8 CVSS
0.3% EPSS
linux 2026-07-04
CVE-2026-48293 🟡 Monitoruj

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue require…

7.8 CVSS
0.1% EPSS
adoberce 2026-06-09
CVE-2026-42011 🟡 Monitoruj

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could ex…

7.4 CVSS
0.5% EPSS
2026-05-07
CVE-2026-34708 🟡 Monitoruj

InCopy versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires u…

7.8 CVSS
0.2% EPSS
CVE-2026-34706 🟡 Monitoruj

InCopy versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user int…

7.8 CVSS
0.1% EPSS
adoberce 2026-06-09
CVE-2026-34707 🟡 Monitoruj

InCopy versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires us…

7.8 CVSS
0.2% EPSS
CVE-2026-34705 ⚪ Do wiadomości

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitiv…

5.5 CVSS
0.2% EPSS
adobe 2026-06-09
CVE-2026-34703 ⚪ Do wiadomości

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…

5.5 CVSS
0.2% EPSS
adobe 2026-06-09
CVE-2026-34704 ⚪ Do wiadomości

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…

5.5 CVSS
0.1% EPSS
adobe 2026-06-09
CVE-2026-34701 🟡 Monitoruj

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue r…

7.8 CVSS
0.2% EPSS
CVE-2026-34702 🟡 Monitoruj

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue …

7.8 CVSS
0.2% EPSS
CVE-2026-34699 🟡 Monitoruj

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue r…

7.8 CVSS
0.2% EPSS
CVE-2026-34700 🟡 Monitoruj

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue require…

7.8 CVSS
0.1% EPSS
adoberce 2026-06-09
CVE-2026-34697 🟡 Monitoruj

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue …

7.8 CVSS
0.2% EPSS
CVE-2026-34698 🟡 Monitoruj

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue r…

7.8 CVSS
0.2% EPSS
CVE-2026-34695 🟡 Monitoruj

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue …

7.8 CVSS
0.2% EPSS
CVE-2026-34696 🟡 Monitoruj

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

7.8 CVSS
0.2% EPSS
adoberce 2026-06-09
CVE-2026-34686 🟡 Monitoruj

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

8.7 CVSS
0.4% EPSS
adobexss 2026-05-12
CVE-2026-34688 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this v…

6.2 CVSS
0.3% EPSS
adobe 2026-05-12
CVE-2026-34687 🟡 Monitoruj

Illustrator versions 29.8.6, 30.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requir…

7.8 CVSS
0.2% EPSS
CVE-2026-34684 🟡 Monitoruj

Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue require…

7.8 CVSS
0.1% EPSS
adoberce 2026-05-12
CVE-2026-34685 ⚪ Do wiadomości

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A high-privi…

3.4 CVSS
0.4% EPSS
adobe 2026-05-12
CVE-2026-34681 🟡 Monitoruj

Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue require…

7.8 CVSS
0.1% EPSS
adoberce 2026-05-12
CVE-2026-34682 🟡 Monitoruj

Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue require…

7.8 CVSS
0.1% EPSS
adoberce 2026-05-12
CVE-2026-34683 🟡 Monitoruj

Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue require…

7.8 CVSS
0.1% EPSS
adoberce 2026-05-12
CVE-2026-34678 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit thi…

6.2 CVSS
0.3% EPSS
adobe 2026-05-12
CVE-2026-34679 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this v…

6.2 CVSS
0.2% EPSS
adobe 2026-05-12
CVE-2026-34680 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit t…

6.2 CVSS
0.3% EPSS
adobe 2026-05-12
CVE-2026-34677 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit thi…

6.2 CVSS
0.2% EPSS
adobe 2026-05-12
CVE-2026-34675 🟡 Monitoruj

Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…

7.8 CVSS
0.1% EPSS
adoberce 2026-05-12
CVE-2026-34676 🟡 Monitoruj

Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…

7.8 CVSS
0.1% EPSS
adoberce 2026-05-12
CVE-2026-34672 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could e…

6.2 CVSS
0.3% EPSS
adobe 2026-05-12
CVE-2026-34673 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit thi…

6.2 CVSS
0.2% EPSS
adobe 2026-05-12
CVE-2026-34669 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this v…

6.2 CVSS
0.2% EPSS
adobe 2026-05-12
CVE-2026-34670 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this v…

6.2 CVSS
0.3% EPSS
adobe 2026-05-12
CVE-2026-34671 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit t…

6.2 CVSS
0.2% EPSS
adobe 2026-05-12
CVE-2026-34666 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this v…

6.2 CVSS
0.3% EPSS
adobe 2026-05-12
CVE-2026-34667 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could e…

6.2 CVSS
0.3% EPSS
adobe 2026-05-12
CVE-2026-34668 ⚪ Do wiadomości

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this v…

6.2 CVSS
0.2% EPSS
adobe 2026-05-12
CVE-2026-34665 🟡 Monitoruj

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit thi…

7.5 CVSS
0.8% EPSS
adobe 2026-05-12
CVE-2026-34664 ⚪ Do wiadomości

Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacke…

6.3 CVSS
0.2% EPSS
adobepath-traversal 2026-05-12
CVE-2026-34662 ⚪ Do wiadomości

Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the appl…

5.5 CVSS
0.2% EPSS
adobe 2026-05-12
CVE-2026-34661 🟡 Monitoruj

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires use…

7.8 CVSS
0.2% EPSS
adoberce 2026-05-12
CVE-2026-34663 ⚪ Do wiadomości

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive inf…

5.5 CVSS
0.2% EPSS
adobe 2026-05-12
CVE-2026-34659 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker cou…

9.6 CVSS
0.6% EPSS
CVE-2026-34660 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploi…

9.3 CVSS
0.4% EPSS
adoberce 2026-05-12
CVE-2026-34658 ⚪ Do wiadomości

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to…

4.8 CVSS
0.3% EPSS
adobexss 2026-05-12
CVE-2026-34655 ⚪ Do wiadomości

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to…

4.8 CVSS
0.4% EPSS
adobexss 2026-05-12
CVE-2026-34656 ⚪ Do wiadomości

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker cou…

4.3 CVSS
0.4% EPSS
adobe 2026-05-12
CVE-2026-34653 🟡 Monitoruj

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that co…

8.7 CVSS
0.6% EPSS
adobepath-traversal 2026-05-12
CVE-2026-34652 🟡 Monitoruj

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in an application deni…

7.5 CVSS
0.5% EPSS
adobe 2026-05-12
CVE-2026-34654 ⚪ Do wiadomości

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in an application deni…

5.3 CVSS
0.6% EPSS
adobe 2026-05-12
CVE-2026-34651 🟡 Monitoruj

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An…

7.5 CVSS
0.7% EPSS
adobe 2026-05-12
CVE-2026-34650 🟡 Monitoruj

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An…

7.5 CVSS
15.9% EPSS
adobe 2026-05-12
CVE-2026-34649 🟡 Monitoruj

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An…

7.5 CVSS
14.4% EPSS
adobe 2026-05-12
CVE-2026-34648 🟡 Monitoruj

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An…

7.5 CVSS
22.6% EPSS
adobe 2026-05-12
CVE-2026-34646 🟡 Monitoruj

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker co…

7.5 CVSS
0.4% EPSS
adobe 2026-05-12
CVE-2026-34647 🟡 Monitoruj

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An a…

7.4 CVSS
0.6% EPSS
adobessrf 2026-05-12
CVE-2026-34644 🟡 Monitoruj

After Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

7.8 CVSS
0.2% EPSS
adoberce 2026-05-12
CVE-2026-34645 🟡 Monitoruj

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker co…

7.5 CVSS
0.6% EPSS
adobe 2026-05-12
CVE-2026-34640 🟡 Monitoruj

Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this iss…

7.8 CVSS
0.2% EPSS
adoberce 2026-05-12
CVE-2026-34642 🟡 Monitoruj

After Effects versions 26.0, 25.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requ…

7.8 CVSS
0.2% EPSS
CVE-2026-34643 🟡 Monitoruj

After Effects versions 26.0, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires u…

7.8 CVSS
0.1% EPSS
adoberce 2026-05-12
CVE-2026-34638 🟡 Monitoruj

Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user i…

7.8 CVSS
0.2% EPSS
adoberce 2026-05-12
CVE-2026-34639 🟡 Monitoruj

Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…

7.8 CVSS
0.1% EPSS
adoberce 2026-05-12
CVE-2026-34636 🟡 Monitoruj

Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires …

7.8 CVSS
0.1% EPSS
adoberce 2026-05-12
CVE-2026-34637 🟡 Monitoruj

Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires …

7.8 CVSS
0.1% EPSS
adoberce 2026-05-12
CVE-2026-16745 🟡 Monitoruj

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by p…

8.8 CVSS
0.4% EPSS
CVE-2026-15378 🟠 Łataj w tym tygodniu

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) st…

9.3 CVSS
0.4% EPSS
ssrf 2026-07-10
CVE-2026-15154 ⚪ Do wiadomości
os

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular ex…

6.5 CVSS
0.5% EPSS
redhatdos 2026-07-08
CVE-2026-10573 ⚪ Do wiadomości

A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to …

0.0 CVSS
0.4% EPSS
2026-07-14
CVE-2021-47983 ⚪ Do wiadomości

WordPress Plugin Stripe Payments before 2.0.40 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code]…

6.4 CVSS
0.2% EPSS
xss 2026-06-08
CVE-2023-43900 ⚪ Do wiadomości

Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocume…

6.5 CVSS
0.6% EPSS
emudhraexploit 2023-11-14
CVE-2023-43901 🟡 Monitoruj

Incorrect access control in the AdHoc User creation form of EMSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user.

7.5 CVSS
0.5% EPSS
emudhraexploit 2023-11-14
CVE-2023-43902 🔴 Łataj teraz

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted pa…

9.8 CVSS
0.9% EPSS
emudhraexploit 2023-11-14
CVE-2026-66299 ⚪ Do wiadomości
apps

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Us…

5.3 CVSS
0.4% EPSS
apache 2026-07-28
CVE-2026-44902 🟡 Monitoruj

opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default 0.0.0…

7.5 CVSS
0.5% EPSS
CVE-2025-43955 ⚪ Do wiadomości

TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Converti…

2.2 CVSS
0.4% EPSS
convertigoexploit 2025-04-20
CVE-2026-54285 ⚪ Do wiadomości

opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size limits when parsing inbound baggage HTTP headers. The W3C Baggage speci…

5.3 CVSS
0.3% EPSS
opentelemetry 2026-06-22
CVE-2026-9277 🟡 Monitoruj

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does no…

8.1 CVSS
0.9% EPSS
2026-05-22
CVE-2026-7163 ⚪ Do wiadomości
os

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obt…

6.1 CVSS
0.2% EPSS
redhat 2026-04-30
CVE-2026-6846 🟡 Monitoruj
os

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user int…

7.8 CVSS
0.2% EPSS
redhatdosrce 2026-04-22
CVE-2026-6322 🟡 Monitoruj

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and…

7.5 CVSS
0.5% EPSS
openjsf 2026-05-05
CVE-2026-64216 🟠 Łataj w tym tygodniu
os

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it is wanting…

9.8 CVSS
0.4% EPSS
linux 2026-07-24
CVE-2026-64561 🟡 Monitoruj

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root,…

8.8 CVSS
0.4% EPSS
2026-08-04
CVE-2026-64581 🟡 Monitoruj

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(), i.e. the non-atomic __s…

7.8 CVSS
0.1% EPSS
2026-08-05
CVE-2026-5946 🟡 Monitoruj

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in…

7.5 CVSS
1.9% EPSS
isc 2026-05-20
CVE-2026-5588 🟡 Monitoruj

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion o…

7.5 CVSS
0.6% EPSS
2026-04-15
CVE-2026-57281 🟡 Monitoruj
dev

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code o…

7.5 CVSS
0.9% EPSS
jenkins 2026-06-24
CVE-2026-53437 ⚪ Do wiadomości
dev

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to …

4.3 CVSS
0.4% EPSS
jenkins 2026-06-10
CVE-2026-54371 🟡 Monitoruj

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during…

7.1 CVSS
0.1% EPSS
CVE-2026-53435 🟠 Łataj w tym tygodniu
dev

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a …

8.8 CVSS
44.3% EPSS
jenkins 2026-06-10
CVE-2026-52923 🟡 Monitoruj
os

In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysctl path can request the next SysV IPC id through ids->next_id. ipc_idr…

7.8 CVSS
0.1% EPSS
linux 2026-06-24
CVE-2026-4800 🟡 Monitoruj

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both path…

8.1 CVSS
2.8% EPSS
lodash 2026-03-31
CVE-2026-4408 🟠 Łataj w tym tygodniu
os

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u subs…

9.0 CVSS
2.5% EPSS
redhat 2026-05-28
CVE-2026-46385 🟡 Monitoruj

iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. Re…

7.5 CVSS
0.5% EPSS
2026-05-29
CVE-2026-46384 🟡 Monitoruj

iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed them to platform-sized int before bounds-checking, or s…

7.5 CVSS
0.5% EPSS
2026-05-29
CVE-2026-46158 ⚪ Do wiadomości
os

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(). It should then be released…

5.5 CVSS
0.1% EPSS
linux 2026-05-28
CVE-2026-46170 ⚪ Do wiadomości
os

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: free sk if last When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(), and released at the end. If at that m…

5.5 CVSS
0.1% EPSS
linux 2026-05-28
CVE-2026-45839 🟡 Monitoruj
os

In the Linux kernel, the following vulnerability has been resolved: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() CO-RE accessor strings are colon-separated indices that describe a path from a ro…

7.8 CVSS
0.1% EPSS
linux 2026-05-27
CVE-2026-44990 🟠 Łataj w tym tygodniu

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can tur…

9.3 CVSS
0.5% EPSS
xss 2026-06-12
CVE-2026-44293 🟡 Monitoruj

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controll…

8.8 CVSS
0.4% EPSS
protobufjs_project 2026-05-13
CVE-2026-44432 🟡 Monitoruj
dev

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response…

7.5 CVSS
0.7% EPSS
python 2026-05-13
CVE-2026-44393 🟡 Monitoruj

An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file is configure…

7.4 CVSS
0.2% EPSS
2026-06-04
CVE-2026-43329 🟡 Monitoruj
os

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum number of flowtable hardware offload actions in IPv6 is: * ethernet ma…

7.8 CVSS
0.1% EPSS
linux 2026-05-08
CVE-2026-44185 🟡 Monitoruj
apps

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade t…

7.3 CVSS
0.7% EPSS
apache 2026-06-08
CVE-2026-43112 🟡 Monitoruj
os

In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only d…

8.8 CVSS
0.4% EPSS
linux 2026-05-06
CVE-2026-42965 🟡 Monitoruj
os

A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud…

7.7 CVSS
0.3% EPSS
redhat 2026-05-29
CVE-2026-42536 🟡 Monitoruj
apps

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade …

7.5 CVSS
1.0% EPSS
CVE-2026-42499 🟡 Monitoruj

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

7.5 CVSS
0.8% EPSS
golangdos 2026-05-07
CVE-2026-42154 🟡 Monitoruj

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed re…

7.5 CVSS
0.8% EPSS
prometheus 2026-05-04
CVE-2026-42151 🟡 Monitoruj

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as …

7.5 CVSS
0.4% EPSS
prometheus 2026-05-04
CVE-2026-42010 🟡 Monitoruj
os

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this …

7.1 CVSS
1.1% EPSS
redhatauth-bypass 2026-05-07
CVE-2026-42009 🟡 Monitoruj
os

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence num…

7.5 CVSS
1.3% EPSS
redhatdos 2026-05-18
CVE-2026-41035 🟡 Monitoruj

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) co…

7.4 CVSS
0.4% EPSS
sambaexploit 2026-04-16
CVE-2026-40542 🟡 Monitoruj
apps

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to u…

7.3 CVSS
0.5% EPSS
apache 2026-04-22

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintain…

7.5 CVSS
0.4% EPSS
gnubuffer-overflow 2026-06-29
CVE-2026-3505 🟡 Monitoruj

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program …

7.5 CVSS
0.8% EPSS
2026-04-15
CVE-2026-3039 🟡 Monitoruj

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers …

7.5 CVSS
1.1% EPSS
isc 2026-05-20
CVE-2026-3012 🟡 Monitoruj
os

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the …

8.0 CVSS
0.3% EPSS
redhat 2026-05-27
CVE-2026-39821 🟠 Łataj w tym tygodniu

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an erro…

9.6 CVSS
0.7% EPSS
CVE-2026-39820 🟡 Monitoruj

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

7.5 CVSS
0.8% EPSS
golang 2026-05-07
CVE-2026-35469 ⚪ Do wiadomości

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three all…

6.5 CVSS
0.7% EPSS
2026-04-16
CVE-2026-34986 🟡 Monitoruj

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Pr…

7.5 CVSS
0.7% EPSS
go-jose_projectdos 2026-04-06
CVE-2026-34982 🟡 Monitoruj

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `pr…

8.2 CVSS
0.5% EPSS
vim 2026-04-06
CVE-2026-34355 🟡 Monitoruj
apps

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

7.5 CVSS
1.1% EPSS
CVE-2026-33846 🟡 Monitoruj

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely o…

7.5 CVSS
1.3% EPSS
buffer-overflow 2026-05-04
CVE-2026-33845 🟡 Monitoruj
os

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely ex…

7.5 CVSS
0.8% EPSS
redhatdos 2026-04-30
CVE-2026-33815 🟠 Łataj w tym tygodniu

Memory-safety vulnerability in github.com/jackc/pgx/v5.

9.8 CVSS
0.6% EPSS
jackc 2026-04-07
CVE-2026-33814 🟡 Monitoruj

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

7.5 CVSS
0.8% EPSS
golang 2026-05-07
CVE-2026-33811 🟡 Monitoruj

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

7.5 CVSS
0.8% EPSS
golang 2026-05-07
CVE-2026-33810 🟡 Monitoruj

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of oth…

8.2 CVSS
0.3% EPSS
golang 2026-04-08
CVE-2026-33186 🟠 Łataj w tym tygodniu

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in…

9.1 CVSS
1.6% EPSS
grpc 2026-03-20
CVE-2026-32283 🟡 Monitoruj

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. Th…

7.5 CVSS
0.6% EPSS
golangdos 2026-04-08
CVE-2026-29181 🟡 Monitoruj

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an …

7.5 CVSS
0.7% EPSS
CVE-2026-32280 🟡 Monitoruj

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affe…

7.5 CVSS
0.6% EPSS
golangdos 2026-04-08
CVE-2026-2332 🟡 Monitoruj

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * h…

7.4 CVSS
1.3% EPSS
eclipseexploit 2026-04-14
CVE-2026-27145 ⚪ Do wiadomości

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. Wi…

6.5 CVSS
0.6% EPSS
2026-06-02
CVE-2026-27140 🟡 Monitoruj

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

8.8 CVSS
0.7% EPSS
golangrce 2026-04-08
CVE-2026-27137 🟡 Monitoruj

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applie…

7.5 CVSS
0.6% EPSS
golang 2026-03-06
CVE-2026-25679 🟡 Monitoruj

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

7.5 CVSS
0.7% EPSS
golang 2026-03-06
CVE-2026-23490 🟡 Monitoruj
os

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is…

7.5 CVSS
0.7% EPSS
debian 2026-01-16
CVE-2026-1933 🟡 Monitoruj
os

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may cr…

7.1 CVSS
0.9% EPSS
redhat 2026-05-27
CVE-2026-1605 🟡 Monitoruj

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compr…

7.5 CVSS
0.7% EPSS
eclipse 2026-03-05
CVE-2026-17613 🟡 Monitoruj

Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full da…

7.5 CVSS
0.4% EPSS
2026-08-05
CVE-2026-13676 🟡 Monitoruj

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leavin…

7.5 CVSS
0.4% EPSS
openjsf 2026-06-29
CVE-2026-12143 🟡 Monitoruj

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposi…

7.5 CVSS
0.5% EPSS
2026-06-12
CVE-2026-0636 ⚪ Do wiadomości

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program…

6.5 CVSS
0.5% EPSS
2026-04-15
CVE-2025-68794 🟠 Łataj w tym tygodniu

In the Linux kernel, the following vulnerability has been resolved: iomap: adjust read range correctly for non-block-aligned positions iomap_adjust_read_range() assumes that the position and length passed in are block-…

9.8 CVSS
0.5% EPSS
2026-01-13
CVE-2025-67030 🟡 Monitoruj

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

8.8 CVSS
0.7% EPSS
CVE-2025-57847 ⚪ Do wiadomości
os

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certai…

6.4 CVSS
0.2% EPSS
CVE-2025-61726 🟡 Monitoruj

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.Pars…

7.5 CVSS
2.0% EPSS
golang 2026-01-28
CVE-2025-54518 🟡 Monitoruj

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege es…

7.0 CVSS
0.3% EPSS
CVE-2025-40074 🟠 Łataj w tym tygodniu

In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF. Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), …

9.8 CVSS
0.4% EPSS
2025-10-28
CVE-2025-38616 🟡 Monitoruj
os

In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS ULP TLS expects that it owns the receive queue of the TCP socket. This cannot be guaranteed in case t…

7.8 CVSS
0.2% EPSS
linux 2025-08-22
CVE-2025-14813 🟡 Monitoruj

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. Thi…

7.5 CVSS
0.3% EPSS
2026-04-15
CVE-2025-13465 ⚪ Do wiadomości

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue …

5.3 CVSS
1.6% EPSS
lodash 2026-01-21
CVE-2025-10263 🟠 Łataj w tym tygodniu

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A…

9.1 CVSS
0.6% EPSS
2026-06-09
CVE-2024-7341 🟡 Monitoruj
os

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. Thi…

7.1 CVSS
0.9% EPSS
redhat 2024-09-09
CVE-2024-46741 🟡 Monitoruj
os

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix double free of 'buf' in error path smatch warning: drivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf' In f…

7.8 CVSS
0.3% EPSS
linux 2024-09-18
CVE-2025-2399 ⚪ Do wiadomości

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Series M800W and M800S, M80 Series M80 and M8…

5.9 CVSS
0.5% EPSS
2026-03-10
CVE-2026-31153 ⚪ Do wiadomości

A stored cross-site scripting (XSS) vulnerability in Bynder v0.1.394 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: this is disputed by the Supplier because v0.1.394 was never a va…

5.4 CVSS
0.1% EPSS
xss 2026-04-06
CVE-2025-3511 🟡 Monitoruj

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converte…

7.5 CVSS
0.9% EPSS
dos 2025-04-25
CVE-2026-8452 🔴 Łataj teraz KEV

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or …

9.8 CVSS
1.6% EPSS
citrixdos 2026-06-30
CVE-2026-10090 🟠 Łataj w tym tygodniu

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub …

9.0 CVSS
0.4% EPSS
CVE-2022-0995 🔴 Łataj teraz KEV

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged a…

7.8 CVSS
9.5% EPSS
netappdosexploit 2022-03-25
CVE-2023-22460 🟡 Monitoruj

go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Encodin…

7.5 CVSS
1.0% EPSS
protocol 2023-01-04
CVE-2019-1068 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

8.8 CVSS
52.8% EPSS
microsoftrce 2019-07-15
CVE-2021-23758 🔴 Łataj teraz KEV

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

8.1 CVSS
83.6% EPSS
CVE-2015-5287 🔴 Łataj teraz KEV
os

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated b…

7.8 CVSS
5.0% EPSS
redhatexploit 2015-12-07
CVE-2015-3246 🔴 Łataj teraz KEV
os

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) b…

5.1 CVSS
8.8% EPSS
redhatdosexploit 2015-08-11