Where
AND
-Infinity
0

pypi/aiohttpAIOHTTP vulnerable to cross-origin redirect with per-request cookies

Risk 43
Severity
6.6
First published (updated )

npm/react-routerReact Router has stored XSS via unescaped Location header in prerendered redirect HTML

Risk 34
Severity
5.4
First published (updated )

npm/axiosAxios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix

Risk 27
Severity
5.3
First published (updated )

Python Software Foundation CPythonThe expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

Risk 32
Severity
6.3
EPSS
0.06%
First published (updated )

npm/ip-addressip-address: XSS in Address6 HTML-emitting methods

Risk 59
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

musl musl libcmusl libc GB18030 4-byte Decoder iconv.c iconv algorithmic complexity

Risk 17
Severity
4.8
EPSS
0.01%
First published (updated )

OpenSSL OpenSSLOpenSSL TLS 1.3 server may choose unexpected key agreement group

Risk 43
Severity
6.5
First published (updated )

redhat/libcurlwrong proxy connection reuse with credentials

Risk 29
Severity
6.5
EPSS
0.01%
First published (updated )

redhat/curltoken leak with redirect and netrc

Risk 20
Severity
5.3
EPSS
0.02%
First published (updated )

golang.org/x/net/htmlQuadratic parsing complexity in golang.org/x/net/html

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/libcurllibssh global known_hosts override

Risk 34
Severity
5.3
First published (updated )

redhat/libcurlOpenSSL partial chain store policy bypass

Risk 34
Severity
5.3
First published (updated )

Apple iOSbearer token leak on cross-protocol redirect

Risk 34
Severity
5.3
First published (updated )

redhat/libcurlbroken TLS options for threaded LDAPS

Risk 50
Severity
6.3
First published (updated )

libcurlNo QUIC certificate pinning with GnuTLS

Risk 38
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Kubernetes gitRepo volume[kubernetes] CVE-2025-1767: Gitpo Volume Inadvertent Local pository Access

Risk 53
Severity
6.5
First published (updated )

IBM API ConnectIBM API Connect HOST header injection

Risk 35
Severity
5.4
First published (updated )

coredns.io CoreDNSA flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for exte…

Risk 39
Severity
6.1
First published (updated )

coredns.io CoreDNSA flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some int…

Risk 29
Severity
4.4
First published (updated )

IBM Guardium Data EncryptionIBM Guardium Data Encryption (GDE) could disclose internal IP address information when the web backe…

Risk 28
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM Guardium Data EncryptionIBM Guardium Data Encryption (GDE) could allow a remote attacker to obtain sensitive information, ca…

Risk 36
Severity
5.9
First published (updated )

IBM API Connect on cloudXSS

Risk 35
Severity
5.5
First published (updated )

IBM API ConnectXSS

Risk 34
Severity
5.4
First published (updated )

IBM API ConnectInput Validation

Risk 41
Severity
6.5
First published (updated )

IBM API ConnectInfoleak

Risk 28
Severity
4.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM API ConnectXSS

Risk 35
Severity
5.4
First published (updated )

IBM API Connect  V5.0.0.0-5.0.8.7IBM API Connect could reveal sensitive information to an attacker using a specially crafted HTTP req…

Risk 27
Severity
5.3
First published (updated )

IBM API ConnectInfoleak

Risk 27
Severity
5.3
First published (updated )

IBM API ConnectInput Validation

Risk 34
Severity
5.4
First published (updated )

IBM 5.0.0.0-5.0.8.3IBM API Connect information disclosure

Risk 36
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203