24h | 7d | 30d

Overview

  • rails
  • activesupport

23 Mar 2026
Published
24 Mar 2026
Updated

CVSS v4.0
MEDIUM (6.6)
EPSS
0.02%

KEV

Description

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which `BigDecimal` expands into extremely large decimal representations. This can cause excessive memory allocation and CPU consumption when the expanded number is formatted, possibly resulting in a DoS vulnerability. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2026-33176 CVE-2025-61594 CVE-2025-24294 CVE-2023-33953 CVE-2022-32511 CVE-2022-29181 CVE-2022-24839 CVE-2022-24836 CVE-2022-0759 CVE-2021-41817 CVE-2021-31799 CVE-2021-30560 CVE-2021-28965 CVE-2021-23214 CVE-2020-25695
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

06 Sep 2011
Published
06 Aug 2024
Updated

CVSS
Pending
EPSS
3.93%

KEV

Description

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2010-4756 CVE-2011-3389 CVE-2013-4392 CVE-2015-3276 CVE-2017-14159 CVE-2017-17740 CVE-2018-20796 CVE-2018-5709 CVE-2018-6829 CVE-2019-1010022 CVE-2019-1010023 CVE-2019-1010024 CVE-2019-1010025 CVE-2019-9192 CVE-2020-15719
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Google
  • Chrome

03 Aug 2021
Published
05 May 2025
Updated

CVSS
Pending
EPSS
0.08%

KEV

Description

Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2026-33176 CVE-2025-61594 CVE-2025-24294 CVE-2023-33953 CVE-2022-32511 CVE-2022-29181 CVE-2022-24839 CVE-2022-24836 CVE-2022-0759 CVE-2021-41817 CVE-2021-31799 CVE-2021-30560 CVE-2021-28965 CVE-2021-23214 CVE-2020-25695
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • kubeclient

25 Mar 2022
Published
02 Aug 2024
Updated

CVSS
Pending
EPSS
0.14%

KEV

Description

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2026-33176 CVE-2025-61594 CVE-2025-24294 CVE-2023-33953 CVE-2022-32511 CVE-2022-29181 CVE-2022-24839 CVE-2022-24836 CVE-2022-0759 CVE-2021-41817 CVE-2021-31799 CVE-2021-30560 CVE-2021-28965 CVE-2021-23214 CVE-2020-25695
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • postgresql

04 Mar 2022
Published
03 Aug 2024
Updated

CVSS
Pending
EPSS
0.19%

KEV

Description

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2026-33176 CVE-2025-61594 CVE-2025-24294 CVE-2023-33953 CVE-2022-32511 CVE-2022-29181 CVE-2022-24839 CVE-2022-24836 CVE-2022-0759 CVE-2021-41817 CVE-2021-31799 CVE-2021-30560 CVE-2021-28965 CVE-2021-23214 CVE-2020-25695
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

16 Jan 2018
Published
05 Aug 2024
Updated

CVSS
Pending
EPSS
1.19%

KEV

Description

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a "u4" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2010-4756 CVE-2011-3389 CVE-2013-4392 CVE-2015-3276 CVE-2017-14159 CVE-2017-17740 CVE-2018-20796 CVE-2018-5709 CVE-2018-6829 CVE-2019-1010022 CVE-2019-1010023 CVE-2019-1010024 CVE-2019-1010025 CVE-2019-9192 CVE-2020-15719
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Google
  • gRPC

09 Aug 2023
Published
27 Sep 2024
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.12%

KEV

Description

gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were found that allow the following DOS attacks: - Unbounded memory buffering in the HPACK parser - Unbounded CPU consumption in the HPACK parser The unbounded CPU consumption is down to a copy that occurred per-input-block in the parser, and because that could be unbounded due to the memory copy bug we end up with an O(n^2) parsing loop, with n selected by the client. The unbounded memory buffering bugs: - The header size limit check was behind the string reading code, so we needed to first buffer up to a 4 gigabyte string before rejecting it as longer than 8 or 16kb. - HPACK varints have an encoding quirk whereby an infinite number of 0’s can be added at the start of an integer. gRPC’s hpack parser needed to read all of them before concluding a parse. - gRPC’s metadata overflow check was performed per frame, so that the following sequence of frames could cause infinite buffering: HEADERS: containing a: 1 CONTINUATION: containing a: 2 CONTINUATION: containing a: 3 etc…

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2026-33176 CVE-2025-61594 CVE-2025-24294 CVE-2023-33953 CVE-2022-32511 CVE-2022-29181 CVE-2022-24839 CVE-2022-24836 CVE-2022-0759 CVE-2021-41817 CVE-2021-31799 CVE-2021-30560 CVE-2021-28965 CVE-2021-23214 CVE-2020-25695
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

14 Jul 2020
Published
04 Aug 2024
Updated

CVSS
Pending
EPSS
0.22%

KEV

Description

libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2010-4756 CVE-2011-3389 CVE-2013-4392 CVE-2015-3276 CVE-2017-14159 CVE-2017-17740 CVE-2018-20796 CVE-2018-5709 CVE-2018-6829 CVE-2019-1010022 CVE-2019-1010023 CVE-2019-1010024 CVE-2019-1010025 CVE-2019-9192 CVE-2020-15719
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

26 Feb 2019
Published
05 Aug 2024
Updated

CVSS
Pending
EPSS
1.49%

KEV

Description

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2010-4756 CVE-2011-3389 CVE-2013-4392 CVE-2015-3276 CVE-2017-14159 CVE-2017-17740 CVE-2018-20796 CVE-2018-5709 CVE-2018-6829 CVE-2019-1010022 CVE-2019-1010023 CVE-2019-1010024 CVE-2019-1010025 CVE-2019-9192 CVE-2020-15719
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

21 Apr 2021
Published
03 Aug 2024
Updated

CVSS
Pending
EPSS
0.36%

KEV

Description

The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2026-33176 CVE-2025-61594 CVE-2025-24294 CVE-2023-33953 CVE-2022-32511 CVE-2022-29181 CVE-2022-24839 CVE-2022-24836 CVE-2022-0759 CVE-2021-41817 CVE-2021-31799 CVE-2021-30560 CVE-2021-28965 CVE-2021-23214 CVE-2020-25695
  • 0
  • 0
  • 0
  • 4h ago
Showing 71 to 80 of 132 CVEs