24h | 7d | 30d

Overview

  • libexpat project
  • libexpat

16 Mar 2026
Published
16 Mar 2026
Updated

CVSS v3.1
MEDIUM (4.0)
EPSS
0.00%

KEV

Description

libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

Statistics

  • 1 Post

Last activity: 10 hours ago

Bluesky

Profile picture fallback
#SUSE mozjs60 DoS vulnerabilities (CVE-2026-32776, CVE-2026-32777, CVE-2026-32778). Check your system, automate patching with a script, and harden with iptables/AppArmor Read more -> tinyurl.com/5xxr7ecx #Security
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • libexpat project
  • libexpat

16 Mar 2026
Published
17 Mar 2026
Updated

CVSS v3.1
LOW (2.9)
EPSS
0.00%

KEV

Description

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

Statistics

  • 1 Post

Last activity: 10 hours ago

Bluesky

Profile picture fallback
#SUSE mozjs60 DoS vulnerabilities (CVE-2026-32776, CVE-2026-32777, CVE-2026-32778). Check your system, automate patching with a script, and harden with iptables/AppArmor Read more -> tinyurl.com/5xxr7ecx #Security
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • libexpat project
  • libexpat

16 Mar 2026
Published
16 Mar 2026
Updated

CVSS v3.1
MEDIUM (4.0)
EPSS
0.00%

KEV

Description

libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.

Statistics

  • 1 Post

Last activity: 10 hours ago

Bluesky

Profile picture fallback
#SUSE mozjs60 DoS vulnerabilities (CVE-2026-32776, CVE-2026-32777, CVE-2026-32778). Check your system, automate patching with a script, and harden with iptables/AppArmor Read more -> tinyurl.com/5xxr7ecx #Security
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Microsoft
  • .NET 10.0

12 May 2026
Published
13 May 2026
Updated

CVSS v3.1
HIGH (7.3)
EPSS
0.09%

KEV

Description

Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 14 hours ago

Overview

  • Microsoft
  • .NET 10.0

12 May 2026
Published
13 May 2026
Updated

CVSS v3.1
MEDIUM (4.3)
EPSS
0.08%

KEV

Description

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 14 hours ago

Overview

  • Microsoft
  • .NET 10.0

12 May 2026
Published
13 May 2026
Updated

CVSS v3.1
HIGH (7.3)
EPSS
0.11%

KEV

Description

Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 14 hours ago

Overview

  • Microsoft
  • .NET 10.0

12 May 2026
Published
13 May 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.04%

KEV

Description

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 14 hours ago

Overview

  • PHP Group
  • PHP

10 May 2026
Published
11 May 2026
Updated

CVSS v4.0
MEDIUM (6.3)
EPSS
0.04%

KEV

Description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Bluesky

Profile picture fallback
🛡️ Security updates: Modules: - php-7.3.33-20 - php-7.2.34-27 Software Collections: - php73-php-7.3.33-20 - php72-php-7.2.34-27 With recent important security fixes backported from 8.2.31 (CVE-2026-6735, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568)
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
🛡️ Security updates: Software Collections: - php71-php-7.1.33-33 - php70-php-7.0.33-46 With recent important security fixes backported from 8.2.31 (CVE-2026-6735, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568)
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • PHP Group
  • PHP

10 May 2026
Published
11 May 2026
Updated

CVSS v4.0
HIGH (7.3)
EPSS
0.03%

KEV

Description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Bluesky

Profile picture fallback
🛡️ Security updates: Modules: - php-7.3.33-20 - php-7.2.34-27 Software Collections: - php73-php-7.3.33-20 - php72-php-7.2.34-27 With recent important security fixes backported from 8.2.31 (CVE-2026-6735, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568)
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
🛡️ Security updates: Software Collections: - php71-php-7.1.33-33 - php70-php-7.0.33-46 With recent important security fixes backported from 8.2.31 (CVE-2026-6735, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568)
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • PHP Group
  • PHP
  • soap

10 May 2026
Published
11 May 2026
Updated

CVSS v4.0
MEDIUM (6.3)
EPSS
0.04%

KEV

Description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Bluesky

Profile picture fallback
🛡️ Security updates: Modules: - php-7.3.33-20 - php-7.2.34-27 Software Collections: - php73-php-7.3.33-20 - php72-php-7.2.34-27 With recent important security fixes backported from 8.2.31 (CVE-2026-6735, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568)
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
🛡️ Security updates: Software Collections: - php71-php-7.1.33-33 - php70-php-7.0.33-46 With recent important security fixes backported from 8.2.31 (CVE-2026-6735, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568)
  • 0
  • 0
  • 0
  • 16h ago
Showing 71 to 80 of 82 CVEs