| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-18378 | Hig | 0.49 | 7.6 | 0.00 | Jul 30, 2026 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer… | ||
| CVE-2026-17544 | Cri | 0.64 | 9.8 | 0.00 | Jul 30, 2026 | Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9. | ||
| CVE-2026-17543 | Cri | 0.64 | 9.8 | 0.00 | Jul 30, 2026 | Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9. | ||
| CVE-2026-15397 | Hig | 0.00 | 7.2 | 0.01 | Jul 30, 2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration… | ||
| CVE-2026-22622 | Hig | 0.00 | 8.8 | 0.01 | Jul 30, 2026 | Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device. | ||
| CVE-2026-22621 | Hig | 0.00 | 8.3 | 0.01 | Jul 30, 2026 | Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment. | ||
| CVE-2026-22620 | Hig | 0.00 | 8.6 | 0.01 | Jul 30, 2026 | Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device. | ||
| CVE-2026-18369 | Med | 0.38 | 5.8 | 0.00 | Jul 30, 2026 | A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to… | ||
| CVE-2026-18363 | Cri | 0.00 | — | 0.00 | Jul 30, 2026 | A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured… | ||
| CVE-2026-18362 | Med | 0.00 | 5.9 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks. | ||
| CVE-2026-18361 | Hig | 0.00 | 7.6 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function. | ||
| CVE-2026-18360 | Hig | 0.00 | 7.6 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function. | ||
| CVE-2026-16971 | Med | 0.00 | 5.9 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks. | ||
| CVE-2026-16970 | Med | 0.00 | 4.2 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time. | ||
| CVE-2026-16969 | Hig | 0.00 | 7.6 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function. | ||
| CVE-2022-4994 | 0.00 | — | 0.00 | Jul 30, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __emulator_pio_in() directly for fast PIO instead of bouncing through emulator_pio_in() now that __emulator_pio_in() fills "val" when handling in-kernel PIO. … | |||
| CVE-2026-18353 | Hig | 0.00 | — | 0.00 | Jul 30, 2026 | PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlparse` before performing OIDC discovery with `requests`. Because `urlparse` and `requests`/`urllib3` parse an authority string… | ||
| CVE-2026-7849 | Cri | 0.00 | 9.8 | 0.01 | Jul 30, 2026 | Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root. | ||
| CVE-2026-44108 | Cri | 0.00 | 9.8 | 0.01 | Jul 30, 2026 | Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to… | ||
| CVE-2026-44107 | Hig | 0.00 | 7.5 | 0.01 | Jul 30, 2026 | A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack. | ||
| CVE-2026-44106 | — | Hig | 0.00 | 7.8 | 0.00 | Jul 30, 2026 | A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. | |
| CVE-2026-44105 | — | Med | 0.00 | 6.6 | 0.00 | Jul 30, 2026 | The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted. | |
| CVE-2026-44104 | Cri | 0.00 | 9.8 | 0.00 | Jul 30, 2026 | The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise. | ||
| CVE-2026-44103 | Med | 0.00 | 5.3 | 0.00 | Jul 30, 2026 | An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected… | ||
| CVE-2026-44102 | — | Med | 0.00 | 5.3 | 0.00 | Jul 30, 2026 | An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process. | |
| CVE-2026-44101 | Cri | 0.00 | 9.8 | 0.01 | Jul 30, 2026 | Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker. | ||
| CVE-2026-44100 | Cri | 0.00 | 9.4 | 0.01 | Jul 30, 2026 | The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering. | ||
| CVE-2026-44099 | — | Hig | 0.00 | 7.8 | 0.00 | Jul 30, 2026 | A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. | |
| CVE-2026-44098 | Hig | 0.00 | 8.6 | 0.02 | Jul 30, 2026 | This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted. | ||
| CVE-2026-44097 | Hig | 0.00 | 7.1 | 0.00 | Jul 30, 2026 | A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service. | ||
| CVE-2026-44096 | Hig | 0.00 | 7.8 | 0.00 | Jul 30, 2026 | A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise. | ||
| CVE-2026-44095 | — | Hig | 0.00 | 7.8 | 0.00 | Jul 30, 2026 | A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. | |
| CVE-2026-44094 | — | Hig | 0.00 | 8.6 | 0.00 | Jul 30, 2026 | An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be… | |
| CVE-2026-44093 | — | Hig | 0.00 | 7.8 | 0.00 | Jul 30, 2026 | A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. | |
| CVE-2026-44092 | Cri | 0.00 | 9.1 | 0.01 | Jul 30, 2026 | An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss. | ||
| CVE-2026-44091 | — | Cri | 0.00 | 9.1 | 0.01 | Jul 30, 2026 | An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss. | |
| CVE-2026-44090 | — | Cri | 0.00 | 9.8 | 0.01 | Jul 30, 2026 | Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised. | |
| CVE-2026-13584 | Hig | 0.46 | — | 0.00 | Jul 30, 2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series… | ||
| CVE-2026-64635 | Med | 0.34 | 5.3 | 0.00 | Jul 30, 2026 | Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code… | ||
| CVE-2026-59328 | Med | 0.27 | 4.2 | 0.00 | Jul 30, 2026 | Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution… | ||
| CVE-2026-59327 | Med | 0.29 | 4.4 | 0.00 | Jul 30, 2026 | Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes as cleartext XML, either to workspace… | ||
| CVE-2026-59326 | Low | 0.21 | 3.3 | 0.00 | Jul 30, 2026 | The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently… | ||
| CVE-2026-58066 | Cri | 0.64 | 9.8 | 0.00 | Jul 30, 2026 | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity… | ||
| CVE-2026-58046 | Cri | 0.64 | 9.9 | 0.01 | Jul 30, 2026 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel. | ||
| CVE-2026-58043 | Hig | 0.55 | 8.4 | 0.00 | Jul 30, 2026 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem… | ||
| CVE-2026-58040 | Med | 0.41 | 6.3 | 0.00 | Jul 30, 2026 | An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. | ||
| CVE-2026-56850 | Med | 0.29 | 4.4 | 0.00 | Jul 30, 2026 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and… | ||
| CVE-2026-56847 | Med | 0.40 | 6.1 | 0.00 | Jul 30, 2026 | A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability… | ||
| CVE-2026-47882 | Hig | 0.54 | 8.3 | 0.00 | Jul 30, 2026 | When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed… | ||
| CVE-2026-47873 | Hig | 0.52 | 8.0 | 0.00 | Jul 30, 2026 | The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier |
- risk 0.49cvss 7.6epss 0.00
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer…
- risk 0.64cvss 9.8epss 0.00
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
- risk 0.64cvss 9.8epss 0.00
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
- risk 0.00cvss 7.2epss 0.01
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration…
- risk 0.00cvss 8.8epss 0.01
Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.
- risk 0.00cvss 8.3epss 0.01
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
- risk 0.00cvss 8.6epss 0.01
Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
- risk 0.38cvss 5.8epss 0.00
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to…
- risk 0.00cvss —epss 0.00
A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured…
- risk 0.00cvss 5.9epss 0.00
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.
- risk 0.00cvss 7.6epss 0.00
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.
- risk 0.00cvss 7.6epss 0.00
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.
- risk 0.00cvss 5.9epss 0.00
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
- risk 0.00cvss 4.2epss 0.00
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
- risk 0.00cvss 7.6epss 0.00
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.
- CVE-2022-4994Jul 30, 2026risk 0.00cvss —epss 0.00
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __emulator_pio_in() directly for fast PIO instead of bouncing through emulator_pio_in() now that __emulator_pio_in() fills "val" when handling in-kernel PIO. …
- risk 0.00cvss —epss 0.00
PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlparse` before performing OIDC discovery with `requests`. Because `urlparse` and `requests`/`urllib3` parse an authority string…
- risk 0.00cvss 9.8epss 0.01
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
- risk 0.00cvss 9.8epss 0.01
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to…
- risk 0.00cvss 7.5epss 0.01
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
- risk 0.00cvss 7.8epss 0.00
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
- risk 0.00cvss 6.6epss 0.00
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.
- risk 0.00cvss 9.8epss 0.00
The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
- risk 0.00cvss 5.3epss 0.00
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected…
- risk 0.00cvss 5.3epss 0.00
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.
- risk 0.00cvss 9.8epss 0.01
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
- risk 0.00cvss 9.4epss 0.01
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.
- risk 0.00cvss 7.8epss 0.00
A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
- risk 0.00cvss 8.6epss 0.02
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.
- risk 0.00cvss 7.1epss 0.00
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.
- risk 0.00cvss 7.8epss 0.00
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.
- risk 0.00cvss 7.8epss 0.00
A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
- risk 0.00cvss 8.6epss 0.00
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be…
- risk 0.00cvss 7.8epss 0.00
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
- risk 0.00cvss 9.1epss 0.01
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
- risk 0.00cvss 9.1epss 0.01
An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.
- risk 0.00cvss 9.8epss 0.01
Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.
- risk 0.46cvss —epss 0.00
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series…
- risk 0.34cvss 5.3epss 0.00
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code…
- risk 0.27cvss 4.2epss 0.00
Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution…
- risk 0.29cvss 4.4epss 0.00
Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes as cleartext XML, either to workspace…
- risk 0.21cvss 3.3epss 0.00
The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently…
- risk 0.64cvss 9.8epss 0.00
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity…
- risk 0.64cvss 9.9epss 0.01
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.
- risk 0.55cvss 8.4epss 0.00
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem…
- risk 0.41cvss 6.3epss 0.00
An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
- risk 0.29cvss 4.4epss 0.00
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and…
- risk 0.40cvss 6.1epss 0.00
A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability…
- risk 0.54cvss 8.3epss 0.00
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed…
- risk 0.52cvss 8.0epss 0.00
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier