Where
AND
-Infinity
0

npm/node-forgeForge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

Risk 47
Severity
9.1
EPSS
0.02%
First published (updated )

pip/onnxONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack

Risk 71
Severity
9.1
First published (updated )

npm/undiciundici is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Risk 86
Severity
9.8
First published (updated )

npm/fast-xml-parserfast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

Risk 43
Severity
9.3
EPSS
0.04%
First published (updated )

Apache Commons TextCode Injection

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Eclipse JerseyRace Condition allows Bypass of Trust Restrictions

Risk 61
Severity
9.4
First published (updated )

redhat JBoss Enterprise Application PlatformUndertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf

Risk 76
Severity
9.6
First published (updated )

sha.js sha.jsMissing type checks leading to hash rewind and passing on crafted data

Risk 44
Severity
9.1
EPSS
0.06%
First published (updated )

cipher-base cipher-baseMissing type checks leading to hash rewind and passing on crafted data

Risk 44
Severity
9.1
EPSS
0.19%
First published (updated )

npm/form-dataUsage of unsafe random function in form-data for choosing boundary

Risk 46
Severity
9.4
EPSS
0.02%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Node.js pbkdf2On Node.js < 3, pbkdf2 silently disregards Uint8Array input, returning static keys

Risk 55
Severity
9.1
EPSS
0.10%
First published (updated )

pbkdf2 pbkdf2pbkdf2 silently returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos supported by Node.js

Risk 57
Severity
9.1
EPSS
0.09%
First published (updated )

maven/net.sourceforge.pmd:pmd-uiPMD Designer's release key passphrase (GPG) available on Maven Central in cleartext

Risk 59
Severity
9.3
EPSS
0.04%
First published (updated )

npm/dompurifyDOMPurify vulnerable to tampering by prototype polution

Risk 62
Severity
9.8
EPSS
0.07%
First published (updated )

npm/dompurifyDOMPurify nesting-based mXSS

Risk 87
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Snakeyaml Project SnakeyamlRemote Code execution in SnakeYAML

Risk 93
Severity
9.8
First published (updated )

Juniper Security Threat Response ManagerApache commons_text(CVE-2022-42889) and commons_configuration (CVE-2022-33980) vulnerability

Risk 99
Severity
9.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203