Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
| ID | Description | Published | Updated |
|---|---|---|---|
| msrc_cve-2026-76844 | zlib 1.2.11 through 1.3.2 Heap Buffer Overflow via Stale gzwrite Pointer After Failed Write | 2026-10-02T01:02:06.000Z | 2026-10-02T01:02:06.000Z |
| msrc_cve-2026-92382 | Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write | 2026-10-01T01:27:04.000Z | 2026-10-01T14:58:04.000Z |
| msrc_cve-2026-100419 | gitoxide gix-fs before 0.23.0 Worktree Escape via Symlink | 2026-10-01T01:26:43.000Z | 2026-10-01T01:26:43.000Z |
| msrc_cve-2026-95519 | Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows) | 2026-10-01T01:26:05.000Z | 2026-10-01T01:26:05.000Z |
| msrc_cve-2026-95521 | Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm | 2026-10-01T01:25:41.000Z | 2026-10-01T01:25:41.000Z |
| msrc_cve-2026-67407 | RabbitMQ: Incomplete fix for CVE-2026-44838: `escape_regex_char/1` does not escape `-`, leaving room for an MQTT topic permission bypass | 2026-10-01T01:25:02.000Z | 2026-10-02T02:51:03.000Z |
| msrc_cve-2026-67224 | RabbitMQ: Admin path-traversal write via trace name | 2026-10-01T01:24:46.000Z | 2026-10-02T02:49:41.000Z |
| msrc_cve-2026-67413 | RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an Unbounded LIKE Regular Expression | 2026-10-01T01:24:29.000Z | 2026-10-02T02:48:09.000Z |
| msrc_cve-2026-67420 | RabbitMQ OAuth credential refresh retains revoked runtime tags | 2026-10-01T01:24:13.000Z | 2026-10-01T01:24:13.000Z |
| msrc_cve-2026-67410 | RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint | 2026-10-01T01:23:56.000Z | 2026-10-01T01:23:56.000Z |
| msrc_cve-2026-67223 | RabbitMQ: LDAP DN injection via unescaped substitution | 2026-10-01T01:23:32.000Z | 2026-10-01T14:56:55.000Z |
| msrc_cve-2026-66073 | RabbitMQ: Atom table exhaustion via management API node field | 2026-10-01T01:23:16.000Z | 2026-10-01T14:56:34.000Z |
| msrc_cve-2026-66071 | RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values | 2026-10-01T01:23:00.000Z | 2026-10-01T14:56:14.000Z |
| msrc_cve-2026-67411 | RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass | 2026-10-01T01:22:43.000Z | 2026-10-01T14:55:54.000Z |
| msrc_cve-2026-67227 | RabbitMQ: Atom exhaustion: to_atom on global-parameter :name | 2026-10-01T01:22:27.000Z | 2026-10-02T02:44:57.000Z |
| msrc_cve-2026-67231 | RabbitMQ: Trust-store whitelist by Issuer+Serial only | 2026-10-01T01:22:12.000Z | 2026-10-01T01:22:12.000Z |
| msrc_cve-2026-66078 | RabbitMQ: protected tag bypass via bulk-delete | 2026-10-01T01:21:46.000Z | 2026-10-01T01:21:46.000Z |
| msrc_cve-2026-67412 | RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message access | 2026-10-01T01:21:29.000Z | 2026-10-01T14:55:24.000Z |
| msrc_cve-2026-67230 | RabbitMQ: Web-STOMP unbounded pre-auth accumulation | 2026-10-01T01:21:13.000Z | 2026-10-01T14:55:04.000Z |
| msrc_cve-2026-93834 | Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape | 2026-10-01T01:20:57.000Z | 2026-10-01T01:20:57.000Z |
| msrc_cve-2026-81627 | Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram | 2026-10-01T01:20:35.000Z | 2026-10-01T01:20:35.000Z |
| msrc_cve-2026-101904 | Axios: Header Injection via Inherited headers After Minimal Interceptor | 2026-10-01T01:20:12.000Z | 2026-10-01T01:20:12.000Z |
| msrc_cve-2026-97058 | sprintf-js through 1.1.3 Denial of Service via Unbounded Precision | 2026-10-01T01:19:49.000Z | 2026-10-01T01:19:49.000Z |
| msrc_cve-2026-102277 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service | 2026-10-01T01:19:25.000Z | 2026-10-01T01:19:25.000Z |
| msrc_cve-2026-102276 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion | 2026-10-01T01:19:03.000Z | 2026-10-01T01:19:03.000Z |
| msrc_cve-2026-101902 | Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method | 2026-10-01T01:18:39.000Z | 2026-10-01T01:18:39.000Z |
| msrc_cve-2026-102278 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion | 2026-10-01T01:18:17.000Z | 2026-10-01T01:18:17.000Z |
| msrc_cve-2026-102266 | PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation | 2026-10-01T01:17:54.000Z | 2026-10-01T01:17:54.000Z |
| msrc_cve-2026-102274 | PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set | 2026-10-01T01:17:32.000Z | 2026-10-01T01:17:32.000Z |
| msrc_cve-2026-102275 | PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion | 2026-10-01T01:17:09.000Z | 2026-10-01T01:17:09.000Z |