| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73566 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty… | ||
| CVE-2026-73564 | Hig | 0.50 | — | 0.00 | Aug 13, 2026 | frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF makes the uint32 addition wrap to 3, defeats… | ||
| CVE-2026-73561 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadDefaultConnectionEventListeners to call requestClientId, which calls rpc.send for the get-client-id action and pushes a request… | ||
| CVE-2026-72741 | Hig | 0.53 | 8.1 | 0.00 | Aug 13, 2026 | Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token… | ||
| CVE-2026-18428 | Hig | 0.57 | 8.8 | 0.01 | Aug 13, 2026 | A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint. | ||
| CVE-2024-58374 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet… | ||
| CVE-2019-25765 | Hig | 0.49 | 7.5 | 0.01 | Aug 13, 2026 | ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword… | ||
| CVE-2026-73266 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant.… | ||
| CVE-2026-59765 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata | ||
| CVE-2026-59109 | Hig | 0.57 | 8.8 | 0.00 | Aug 13, 2026 | SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement… | ||
| CVE-2026-58439 | Hig | 0.46 | 8.1 | 0.00 | Aug 13, 2026 | Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | ||
| CVE-2026-58438 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access | ||
| CVE-2026-58437 | Hig | 0.39 | 7.1 | 0.00 | Aug 13, 2026 | Repository Visibility Manipulation via Git Push Options | ||
| CVE-2026-58436 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | ||
| CVE-2026-58434 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | Private Repository Metadata Remains Accessible After Access Revocation | ||
| CVE-2026-58427 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | ||
| CVE-2026-58417 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | REST API exposes organization membership of private organizations to public | ||
| CVE-2026-58416 | Hig | 0.39 | 7.1 | 0.00 | Aug 13, 2026 | Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) | ||
| CVE-2026-58314 | Hig | 0.43 | 7.7 | 0.00 | Aug 13, 2026 | Two SSRF findings in Gitea 1.26.2 | ||
| CVE-2026-57894 | Hig | 0.55 | 8.5 | 0.00 | Aug 13, 2026 | Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration | ||
| CVE-2026-55987 | Hig | 0.53 | 8.1 | 0.00 | Aug 13, 2026 | OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) | ||
| CVE-2026-55402 | Hig | 0.57 | — | 0.00 | Aug 13, 2026 | CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service. | ||
| CVE-2026-54481 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) | ||
| CVE-2026-24791 | Hig | 0.46 | 8.1 | 0.00 | Aug 13, 2026 | Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes | ||
| CVE-2026-13048 | Hig | 0.53 | 8.2 | 0.00 | Aug 13, 2026 | Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by appending… | ||
| CVE-2026-73670 | Hig | 0.47 | 7.2 | 0.00 | Aug 13, 2026 | A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying unsanitized input through the table_name GET or POST parameter. Attackers can perform… | ||
| CVE-2026-73570 | Hig | 0.58 | 8.9 | 0.01 | Aug 13, 2026 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an… | ||
| CVE-2026-73515 | Hig | 0.53 | 8.1 | 0.00 | Aug 13, 2026 | PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails… | ||
| CVE-2026-73514 | Hig | 0.50 | 8.8 | 0.00 | Aug 13, 2026 | The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by… | ||
| CVE-2026-19710 | Hig | 0.47 | 7.3 | 0.00 | Aug 13, 2026 | A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is… | ||
| CVE-2026-73509 | Hig | 0.42 | 7.6 | 0.00 | Aug 13, 2026 | OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with… | ||
| CVE-2026-73507 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated remote attacker could… | ||
| CVE-2026-73505 | Hig | 0.44 | 7.8 | 0.00 | Aug 13, 2026 | Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an… | ||
| CVE-2026-70464 | Hig | 0.42 | 7.5 | 0.01 | Aug 13, 2026 | rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open… | ||
| CVE-2026-70463 | Hig | 0.46 | 8.1 | 0.00 | Aug 13, 2026 | rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The… | ||
| CVE-2026-70461 | Hig | 0.46 | 8.2 | 0.01 | Aug 13, 2026 | rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability… | ||
| CVE-2026-70460 | Hig | 0.46 | 8.1 | 0.00 | Aug 13, 2026 | rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under… | ||
| CVE-2026-70458 | Hig | 0.46 | 8.2 | 0.00 | Aug 13, 2026 | rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the… | ||
| CVE-2026-70456 | Hig | 0.46 | 8.2 | 0.00 | Aug 13, 2026 | rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the… | ||
| CVE-2026-70455 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers… | ||
| CVE-2026-70454 | Hig | 0.45 | 8.0 | 0.00 | Aug 13, 2026 | rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit… | ||
| CVE-2026-70453 | Hig | 0.42 | 7.5 | 0.01 | Aug 13, 2026 | rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash… | ||
| CVE-2026-70452 | Hig | 0.41 | 7.4 | 0.00 | Aug 13, 2026 | rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the… | ||
| CVE-2026-6387 | Hig | 0.45 | 7.0 | 0.00 | Aug 13, 2026 | A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges. | ||
| CVE-2026-68454 | Hig | 0.50 | 8.8 | 0.00 | Aug 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a summary bit specified, ensure that the associated GAITE then stores 0 for the guest AISB location instead… | ||
| CVE-2026-68453 | Hig | 0.39 | 7.1 | 0.00 | Aug 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in… | ||
| CVE-2026-68452 | Hig | 0.44 | 7.8 | 0.00 | Aug 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key requests cca_cipher2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early… | ||
| CVE-2026-68451 | Hig | 0.44 | 7.8 | 0.00 | Aug 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA ECC private key requests cca_ecc2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if… | ||
| CVE-2026-66256 | Hig | 0.47 | 7.2 | 0.01 | Aug 13, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. … | ||
| CVE-2026-65935 | Hig | 0.49 | — | 0.00 | Aug 13, 2026 | Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value. See vulnerability B-E3 in the related paper below. |
- risk 0.42cvss 7.5epss 0.00
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty…
- risk 0.50cvss —epss 0.00
frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF makes the uint32 addition wrap to 3, defeats…
- risk 0.42cvss 7.5epss 0.00
Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadDefaultConnectionEventListeners to call requestClientId, which calls rpc.send for the get-client-id action and pushes a request…
- risk 0.53cvss 8.1epss 0.00
Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token…
- risk 0.57cvss 8.8epss 0.01
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.
- risk 0.49cvss 7.5epss 0.00
Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet…
- risk 0.49cvss 7.5epss 0.01
ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword…
- risk 0.46cvss 7.1epss 0.00
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant.…
- risk 0.49cvss 7.5epss 0.00
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
- risk 0.57cvss 8.8epss 0.00
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement…
- risk 0.46cvss 8.1epss 0.00
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
- risk 0.49cvss 7.5epss 0.00
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
- risk 0.39cvss 7.1epss 0.00
Repository Visibility Manipulation via Git Push Options
- risk 0.42cvss 7.5epss 0.00
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
- risk 0.42cvss 7.5epss 0.00
Private Repository Metadata Remains Accessible After Access Revocation
- risk 0.42cvss 7.5epss 0.00
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
- risk 0.42cvss 7.5epss 0.00
REST API exposes organization membership of private organizations to public
- risk 0.39cvss 7.1epss 0.00
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
- risk 0.43cvss 7.7epss 0.00
Two SSRF findings in Gitea 1.26.2
- risk 0.55cvss 8.5epss 0.00
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
- risk 0.53cvss 8.1epss 0.00
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
- risk 0.57cvss —epss 0.00
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.
- risk 0.49cvss 7.5epss 0.00
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
- risk 0.46cvss 8.1epss 0.00
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
- risk 0.53cvss 8.2epss 0.00
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by appending…
- risk 0.47cvss 7.2epss 0.00
A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying unsanitized input through the table_name GET or POST parameter. Attackers can perform…
- risk 0.58cvss 8.9epss 0.01
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an…
- risk 0.53cvss 8.1epss 0.00
PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails…
- risk 0.50cvss 8.8epss 0.00
The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is…
- risk 0.42cvss 7.6epss 0.00
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with…
- risk 0.42cvss 7.5epss 0.00
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated remote attacker could…
- risk 0.44cvss 7.8epss 0.00
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an…
- risk 0.42cvss 7.5epss 0.01
rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open…
- risk 0.46cvss 8.1epss 0.00
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The…
- risk 0.46cvss 8.2epss 0.01
rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability…
- risk 0.46cvss 8.1epss 0.00
rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under…
- risk 0.46cvss 8.2epss 0.00
rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the…
- risk 0.46cvss 8.2epss 0.00
rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the…
- risk 0.42cvss 7.5epss 0.00
rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers…
- risk 0.45cvss 8.0epss 0.00
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit…
- risk 0.42cvss 7.5epss 0.01
rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash…
- risk 0.41cvss 7.4epss 0.00
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the…
- risk 0.45cvss 7.0epss 0.00
A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.
- risk 0.50cvss 8.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a summary bit specified, ensure that the associated GAITE then stores 0 for the guest AISB location instead…
- risk 0.39cvss 7.1epss 0.00
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in…
- risk 0.44cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key requests cca_cipher2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early…
- risk 0.44cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA ECC private key requests cca_ecc2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if…
- risk 0.47cvss 7.2epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. …
- risk 0.49cvss —epss 0.00
Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value. See vulnerability B-E3 in the related paper below.