Where
-Infinity
0

IBM API Connect V12 OnPremIBM API Connect Default Credentials

Risk 86
Severity
9.8
First published (updated )

IBM API Connect28 vulnerabilities

First published (updated )
Advisory
IBM-7278218

IBM API Connect SQL Injection

Risk 61
Severity
9.8
EPSS
0.28%
First published (updated )

AIOHTTP vulnerable to cross-origin redirect with per-request cookies

Risk 43
Severity
6.6
First published (updated )

React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets

Risk 58
Severity
8
First published (updated )

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

Risk 34
Severity
5.4
First published (updated )

Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

Risk 64
Severity
8.7
First published (updated )

Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

Risk 49
Severity
8.6
First published (updated )

Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions

Risk 54
Severity
8.2
First published (updated )

Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix

Risk 27
Severity
5.3
First published (updated )

yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation

Risk 75
Severity
8.6
First published (updated )

The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

Risk 32
Severity
6.3
EPSS
0.06%
First published (updated )

xfrm: esp: avoid in-place decrypt on shared skb frags

Risk 95
Severity
8.8
First published (updated )

ip-address: XSS in Address6 HTML-emitting methods

Risk 59
Severity
5.3
First published (updated )

Libxml2: libxml2: denial of service via crafted xsd-validated document

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )

musl libc GB18030 4-byte Decoder iconv.c iconv algorithmic complexity

Risk 17
Severity
4.8
EPSS
0.01%
First published (updated )

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur d…

Risk 69
Severity
8.1
First published (updated )

Heap Buffer Overflow in Hexadecimal Conversion

Risk 91
Severity
9.8
First published (updated )

Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo

Risk 46
Severity
7.5
First published (updated )

NULL Pointer Dereference When Processing a Delta CRL

Risk 46
Severity
7.5
First published (updated )

Potential Use-after-free in DANE Client Code

Risk 80
Severity
8.1
First published (updated )

Path traversal issue with zip.vim in Vim

Risk 51
Severity
7.1
First published (updated )

XZ Utils: Buffer overflow in lzma_index_append()

Risk 29
Severity
1.7
First published (updated )

pyasn1 Vulnerable to Denial of Service via Unbounded Recursion

Risk 47
Severity
7.5
First published (updated )

OpenSSL TLS 1.3 server may choose unexpected key agreement group

Risk 43
Severity
6.5
First published (updated )

PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)

Risk 31
Severity
7.5
EPSS
0.01%
First published (updated )

use after free in SMB connection reuse

Risk 32
Severity
7.5
EPSS
0.04%
First published (updated )

wrong proxy connection reuse with credentials

Risk 29
Severity
6.5
EPSS
0.01%
First published (updated )

token leak with redirect and netrc

Risk 20
Severity
5.3
EPSS
0.02%
First published (updated )

Quadratic parsing complexity in golang.org/x/net/html

Risk 27
Severity
5.3
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203