Where
AND
-Infinity
0

go/golang.org/x/crypto/sshInvoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

Risk 47
Severity
7.5
First published (updated )

Microsoft azl3 kubevirt 1.7.1-2Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

Risk 47
Severity
7.5
First published (updated )

go/golang.org/x/crypto/sshInvoking bypass of certificate restrictions in golang.org/x/crypto/ssh

Risk 85
Severity
8.8
First published (updated )

golang/golang.org/x/crypto/sshInvoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

Risk 47
Severity
7.5
First published (updated )

npm/brace-expansionbrace-expansion: Large numeric range defeats documented `max` DoS protection

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/urllib3urllib3: Sensitive headers forwarded across origins in proxied low-level redirects

Risk 41
Severity
8.2
First published (updated )

Golang GoInfinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Risk 46
Severity
7.5
First published (updated )

RedisBloom RedisBloomRedisBloom RESTORE invalid memory access may allow remote code execution

Risk 83
Severity
7.7
First published (updated )

Redis redis-serverredis-server RESTORE invalid memory access may allow remote code execution

Risk 84
Severity
7.7
First published (updated )

Redis redis-serverredis-server use-after-free in unblock client flow may allow remote code execution

Risk 84
Severity
7.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/clickPallets Click contains a command injection via Unsanitized Filename "click.edit()"

Risk 45
Severity
7.2
EPSS
0.03%
First published (updated )

Uuidjs Uuid Node.jsuuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided

Risk 80
Severity
8.1
First published (updated )

npm/axiosAxios: no_proxy bypass via IP alias allows SSRF

Risk 43
Severity
7.5
First published (updated )

npm/axiosAxios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy

Risk 54
Severity
8.2
First published (updated )

npm/axiosAxios: Header Injection via Prototype Pollution

Risk 56
Severity
7.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/axiosAxios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking

Risk 56
Severity
7.4
First published (updated )

pip/tornadoIn Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesi…

Risk 44
Severity
7.2
First published (updated )

pypi/tornadoTornado has a DoS due to too many multipart parts

Risk 33
Severity
8.7
EPSS
0.07%
First published (updated )

Microsoft azl3 tensorflow 2.16.1-10TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Risk 51
Severity
7.8
EPSS
0.01%
First published (updated )

Axios Axios Node.jsAxios affected by Denial of Service via __proto__ Key in mergeConfig

Risk 31
Severity
7.5
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/urllib3urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)

Risk 33
Severity
8.9
EPSS
0.02%
First published (updated )

pypi/tornadoTornado is Vulnerable to Quadratic DoS via Crafted Multipart Parameters

Risk 43
Severity
7.5
First published (updated )

pypi/tornadoTornado is Vulnerable to Quadratic DoS via Repeated Header Coalescing

Risk 43
Severity
7.5
First published (updated )

pypi/urllib3urllib3 Streaming API improperly handles highly compressed data

Risk 50
Severity
8.9
First published (updated )

pypi/urllib3urllib3 allows an unbounded number of links in the decompression chain

Risk 50
Severity
8.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Tornado TornadoTornado vulnerable to excessive logging caused by malformed multipart form data

Risk 31
Severity
7.5
EPSS
0.12%
First published (updated )

pip/tornadoTornado has HTTP cookie parsing DoS vulnerability

Risk 46
Severity
7.5
First published (updated )

pip/certifiCertifi removes GLOBALTRUST root certificate

Risk 45
Severity
7.5
First published (updated )

kjd Internationalized Domain Names In ApplicationsDenial of Service via Quadratic Complexity in kjd/idna

Risk 46
Severity
7.5
First published (updated )

Fedoraproject Fedora`Cookie` HTTP header isn't stripped on cross-origin redirects

Risk 64
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203