Where
AND
-Infinity
0

Apache CXFApache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)

Risk 76
Severity
7.5
First published (updated )

Symfony TwigTwig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface

Risk 82
Severity
8.7
First published (updated )

maven/io.opentelemetry:opentelemetry-extension-trace-propagatorsopentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation

Risk 43
Severity
7.5
First published (updated )

npm/protobufjsprotobufjs: Denial of Service via unbounded recursive JSON descriptor expansion

Risk 43
Severity
7.5
First published (updated )

Apache TomcatApache Tomcat: LockOutRealm treats user names as case-sensitive

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache TomcatApache Tomcat: WebSocket authentication header exposure

Risk 55
Severity
7.3
First published (updated )

Apache TomcatApache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

Risk 46
Severity
7.5
First published (updated )

npm/@opentelemetry/auto-instrumentations-nodeopentelemetry-js: Prometheus exporter process crash via malformed HTTP request

Risk 43
Severity
7.5
First published (updated )

npm/i18next-fs-backendi18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite

Risk 54
Severity
8.2
First published (updated )

maven/io.netty:netty-transport-native-epollNetty: epoll transport denial of service via RST on half-closed TCP connection

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/GitPythonGitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath

Risk 69
Severity
7.8
First published (updated )

pip/python-multipartPython-Multipart: Denial of Service via unbounded multipart part headers

Risk 43
Severity
7.5
First published (updated )

pip/MakoMako: Path traversal via backslash URI on Windows in TemplateLookup

Risk 47
Severity
8.7
First published (updated )

pip/notebookjupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content

Risk 80
Severity
8.6
First published (updated )

pip/GitPythonGitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository

Risk 62
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/basic-ftpbasic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering

Risk 43
Severity
7.5
First published (updated )

pip/mistuneMistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles

Risk 47
Severity
8.7
First published (updated )

pip/jupyterlabJupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.

Risk 79
Severity
8.8
First published (updated )

npm/@jupyterlab/help-extensionJupyter Notebook and JupyterLab token theft via stored XSS in help command linker

Risk 70
Severity
8.4
First published (updated )

VMware Spring BootWeak RNG

Risk 54
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

VMware Spring BootA local attacker on the same host as the application may be able to take control of the directory us…

Risk 63
Severity
7
First published (updated )

go/github.com/Azure/go-ntlmsspgo-ntlmssp NTLM challenges can panic on malformed payloads

Risk 43
Severity
7.5
First published (updated )

pip/lxmllxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

Risk 43
Severity
7.5
First published (updated )

Oracle JRELast updated 2 June 2026

Risk 43
Severity
7.5
First published (updated )

Apache TomcatApache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache TomcatApache Tomcat: Incomplete escaping of JSON access logs

Risk 46
Severity
7.5
First published (updated )

Apache TomcatApache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default

Risk 46
Severity
7.5
First published (updated )

Apache TomcatApache Tomcat: Request smuggling via invalid chunk extension

Risk 46
Severity
7.5
First published (updated )

maven/org.eclipse.jetty.ee10:jetty-ee10In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two Th…

Risk 41
Severity
7.4
EPSS
0.02%
First published (updated )

Microsoft azl3 vim 9.2.0240-1Vim modeline bypass via various options affects Vim < 9.2.0276

Risk 62
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203