Where
AND
-Infinity
0

npm/react-routerReact Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets

Risk 58
Severity
8
First published (updated )

npm/axiosAxios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

Risk 64
Severity
8.7
First published (updated )

npm/axiosAxios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

Risk 49
Severity
8.6
First published (updated )

npm/axiosAxios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions

Risk 54
Severity
8.2
First published (updated )

npm/yeoman-environmentyeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation

Risk 75
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Linux Linux kernelxfrm: esp: avoid in-place decrypt on shared skb frags

Risk 95
Severity
8.8
First published (updated )

redhat Enterprise LinuxLibxml2: libxml2: denial of service via crafted xsd-validated document

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )

musl musl libcAn issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur d…

Risk 69
Severity
8.1
First published (updated )

OpenSSL OpenSSLPossible NULL Dereference When Processing CMS KeyAgreeRecipientInfo

Risk 46
Severity
7.5
First published (updated )

OpenSSL OpenSSLNULL Pointer Dereference When Processing a Delta CRL

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenSSL OpenSSLPotential Use-after-free in DANE Client Code

Risk 80
Severity
8.1
First published (updated )

Microsoft azl3 vim 9.2.0240-1Path traversal issue with zip.vim in Vim

Risk 51
Severity
7.1
First published (updated )

pip/pyasn1pyasn1 Vulnerable to Denial of Service via Unbounded Recursion

Risk 47
Severity
7.5
First published (updated )

pypi/pyjwtPyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)

Risk 31
Severity
7.5
EPSS
0.01%
First published (updated )

redhat/libcurluse after free in SMB connection reuse

Risk 32
Severity
7.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/psy/psyshPsySH has Local Privilege Escalation via CWD .psysh.php auto-load

Risk 48
Severity
7.3
EPSS
0.01%
First published (updated )

redhat Enterprise Linux For X86 64Glib: integer overflow in in g_escape_uri_string()

Risk 56
Severity
7.7
First published (updated )

F5 BIG-IP Next SPKOut-of-bounds read & write in RFC 3211 KEK Unwrap

Risk 32
Severity
7.5
EPSS
0.03%
First published (updated )

go/github.com/coredns/corednsCoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses vi…

Risk 45
Severity
7.5
First published (updated )

IBM API ConnectIBM API Connect security bypass

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM API ConnectIBM API Connect uses weaker than expected cryptographic algorithms that could allow an attacker to d…

Risk 45
Severity
7.5
First published (updated )

IBM API ConnectIBM API Connect uses weaker than expected cryptographic algorithms that could allow an attacker to d…

Risk 45
Severity
7.5
First published (updated )

IBM API ConnectPath Traversal

Risk 43
Severity
7.5
First published (updated )

IBM API ConnectIBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover log…

Risk 54
Severity
8.2
First published (updated )

IBM API ConnectIBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the develop…

Risk 70
Severity
8.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM API ConnectIBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) wh…

Risk 75
Severity
8.1
First published (updated )

IBM API ConnectInput Validation

Risk 52
Severity
7.5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203