24h | 7d | 30d

Overview

  • Pending

06 Jun 2022
Published
03 Aug 2024
Updated

CVSS
Pending
EPSS
2.10%

KEV

Description

jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2026-33176 CVE-2025-61594 CVE-2025-24294 CVE-2023-33953 CVE-2022-32511 CVE-2022-29181 CVE-2022-24839 CVE-2022-24836 CVE-2022-0759 CVE-2021-41817 CVE-2021-31799 CVE-2021-30560 CVE-2021-28965 CVE-2021-23214 CVE-2020-25695
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • GNU Libc
  • glibc

15 Jul 2019
Published
05 Aug 2024
Updated

CVSS
Pending
EPSS
0.86%

KEV

Description

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2010-4756 CVE-2011-3389 CVE-2013-4392 CVE-2015-3276 CVE-2017-14159 CVE-2017-17740 CVE-2018-20796 CVE-2018-5709 CVE-2018-6829 CVE-2019-1010022 CVE-2019-1010023 CVE-2019-1010024 CVE-2019-1010025 CVE-2019-9192 CVE-2020-15719
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • sparklemotion
  • nekohtml

11 Apr 2022
Published
23 Apr 2025
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.45%

KEV

Description

org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to upgrade to `>= 1.9.22.noko2`. Note: The upstream library `org.cyberneko.html` is no longer maintained. Nokogiri uses its own fork of this library located at https://github.com/sparklemotion/nekohtml and this CVE applies only to that fork. Other forks of nekohtml may have a similar vulnerability.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2026-33176 CVE-2025-61594 CVE-2025-24294 CVE-2023-33953 CVE-2022-32511 CVE-2022-29181 CVE-2022-24839 CVE-2022-24836 CVE-2022-0759 CVE-2021-41817 CVE-2021-31799 CVE-2021-30560 CVE-2021-28965 CVE-2021-23214 CVE-2020-25695
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Pending

02 Mar 2011
Published
03 Nov 2025
Updated

CVSS
Pending
EPSS
0.39%

KEV

Description

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2010-4756 CVE-2011-3389 CVE-2013-4392 CVE-2015-3276 CVE-2017-14159 CVE-2017-17740 CVE-2018-20796 CVE-2018-5709 CVE-2018-6829 CVE-2019-1010022 CVE-2019-1010023 CVE-2019-1010024 CVE-2019-1010025 CVE-2019-9192 CVE-2020-15719
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • postgresql

16 Nov 2020
Published
04 Aug 2024
Updated

CVSS
Pending
EPSS
23.76%

KEV

Description

A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2026-33176 CVE-2025-61594 CVE-2025-24294 CVE-2023-33953 CVE-2022-32511 CVE-2022-29181 CVE-2022-24839 CVE-2022-24836 CVE-2022-0759 CVE-2021-41817 CVE-2021-31799 CVE-2021-30560 CVE-2021-28965 CVE-2021-23214 CVE-2020-25695
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Pending

01 Jan 2022
Published
04 Aug 2024
Updated

CVSS
Pending
EPSS
0.50%

KEV

Description

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2026-33176 CVE-2025-61594 CVE-2025-24294 CVE-2023-33953 CVE-2022-32511 CVE-2022-29181 CVE-2022-24839 CVE-2022-24836 CVE-2022-0759 CVE-2021-41817 CVE-2021-31799 CVE-2021-30560 CVE-2021-28965 CVE-2021-23214 CVE-2020-25695
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Pending

26 Feb 2024
Published
14 Aug 2024
Updated

CVSS
Pending
EPSS
0.08%

KEV

Description

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
CVE-2022-27943 CVE-2023-2953 CVE-2023-31437 CVE-2023-31438 CVE-2023-31439 CVE-2023-45853 CVE-2024-2236 CVE-2024-2379 CVE-2024-26458 CVE-2024-26461 CVE-2025-0725 CVE-2025-10148 CVE-2025-27587 CVE-2025-62813 CVE-2025-9086 CVE-2025-9230 CVE-2025-9232 N/A Security fixes for
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Pending

13 Jun 2023
Published
03 Jan 2025
Updated

CVSS
Pending
EPSS
0.17%

KEV

Description

An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
CVE-2022-27943 CVE-2023-2953 CVE-2023-31437 CVE-2023-31438 CVE-2023-31439 CVE-2023-45853 CVE-2024-2236 CVE-2024-2379 CVE-2024-26458 CVE-2024-26461 CVE-2025-0725 CVE-2025-10148 CVE-2025-27587 CVE-2025-62813 CVE-2025-9086 CVE-2025-9230 CVE-2025-9232 N/A Security fixes for
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Pending

14 Oct 2023
Published
02 Aug 2024
Updated

CVSS
Pending
EPSS
1.29%

KEV

Description

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
CVE-2022-27943 CVE-2023-2953 CVE-2023-31437 CVE-2023-31438 CVE-2023-31439 CVE-2023-45853 CVE-2024-2236 CVE-2024-2379 CVE-2024-26458 CVE-2024-26461 CVE-2025-0725 CVE-2025-10148 CVE-2025-27587 CVE-2025-62813 CVE-2025-9086 CVE-2025-9230 CVE-2025-9232 N/A Security fixes for
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • libgcrypt

06 Mar 2024
Published
25 Feb 2026
Updated

CVSS
Pending
EPSS
0.59%

KEV

Description

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
CVE-2022-27943 CVE-2023-2953 CVE-2023-31437 CVE-2023-31438 CVE-2023-31439 CVE-2023-45853 CVE-2024-2236 CVE-2024-2379 CVE-2024-26458 CVE-2024-26461 CVE-2025-0725 CVE-2025-10148 CVE-2025-27587 CVE-2025-62813 CVE-2025-9086 CVE-2025-9230 CVE-2025-9232 N/A Security fixes for
  • 0
  • 0
  • 0
  • 6h ago
Showing 91 to 100 of 132 CVEs