Vulnerabilities

Recent vulnerabilities

Recent vulnerabilities from
Select from 81 available sources using the dropdown above.

CSAF Microsoft 🪟

Recent vulnerabilities · 21271 entries
ID Description Published Updated
msrc_cve-2026-76844 zlib 1.2.11 through 1.3.2 Heap Buffer Overflow via Stale gzwrite Pointer After Failed Write 2026-10-02T01:02:06.000Z 2026-10-02T01:02:06.000Z
msrc_cve-2026-92382 Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write 2026-10-01T01:27:04.000Z 2026-10-01T14:58:04.000Z
msrc_cve-2026-100419 gitoxide gix-fs before 0.23.0 Worktree Escape via Symlink 2026-10-01T01:26:43.000Z 2026-10-01T01:26:43.000Z
msrc_cve-2026-95519 Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows) 2026-10-01T01:26:05.000Z 2026-10-01T01:26:05.000Z
msrc_cve-2026-95521 Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm 2026-10-01T01:25:41.000Z 2026-10-01T01:25:41.000Z
msrc_cve-2026-67407 RabbitMQ: Incomplete fix for CVE-2026-44838: `escape_regex_char/1` does not escape `-`, leaving room for an MQTT topic permission bypass 2026-10-01T01:25:02.000Z 2026-10-02T02:51:03.000Z
msrc_cve-2026-67224 RabbitMQ: Admin path-traversal write via trace name 2026-10-01T01:24:46.000Z 2026-10-02T02:49:41.000Z
msrc_cve-2026-67413 RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an Unbounded LIKE Regular Expression 2026-10-01T01:24:29.000Z 2026-10-02T02:48:09.000Z
msrc_cve-2026-67420 RabbitMQ OAuth credential refresh retains revoked runtime tags 2026-10-01T01:24:13.000Z 2026-10-01T01:24:13.000Z
msrc_cve-2026-67410 RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint 2026-10-01T01:23:56.000Z 2026-10-01T01:23:56.000Z
msrc_cve-2026-67223 RabbitMQ: LDAP DN injection via unescaped substitution 2026-10-01T01:23:32.000Z 2026-10-01T14:56:55.000Z
msrc_cve-2026-66073 RabbitMQ: Atom table exhaustion via management API node field 2026-10-01T01:23:16.000Z 2026-10-01T14:56:34.000Z
msrc_cve-2026-66071 RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values 2026-10-01T01:23:00.000Z 2026-10-01T14:56:14.000Z
msrc_cve-2026-67411 RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass 2026-10-01T01:22:43.000Z 2026-10-01T14:55:54.000Z
msrc_cve-2026-67227 RabbitMQ: Atom exhaustion: to_atom on global-parameter :name 2026-10-01T01:22:27.000Z 2026-10-02T02:44:57.000Z
msrc_cve-2026-67231 RabbitMQ: Trust-store whitelist by Issuer+Serial only 2026-10-01T01:22:12.000Z 2026-10-01T01:22:12.000Z
msrc_cve-2026-66078 RabbitMQ: protected tag bypass via bulk-delete 2026-10-01T01:21:46.000Z 2026-10-01T01:21:46.000Z
msrc_cve-2026-67412 RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message access 2026-10-01T01:21:29.000Z 2026-10-01T14:55:24.000Z
msrc_cve-2026-67230 RabbitMQ: Web-STOMP unbounded pre-auth accumulation 2026-10-01T01:21:13.000Z 2026-10-01T14:55:04.000Z
msrc_cve-2026-93834 Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape 2026-10-01T01:20:57.000Z 2026-10-01T01:20:57.000Z
msrc_cve-2026-81627 Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram 2026-10-01T01:20:35.000Z 2026-10-01T01:20:35.000Z
msrc_cve-2026-101904 Axios: Header Injection via Inherited headers After Minimal Interceptor 2026-10-01T01:20:12.000Z 2026-10-01T01:20:12.000Z
msrc_cve-2026-97058 sprintf-js through 1.1.3 Denial of Service via Unbounded Precision 2026-10-01T01:19:49.000Z 2026-10-01T01:19:49.000Z
msrc_cve-2026-102277 brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service 2026-10-01T01:19:25.000Z 2026-10-01T01:19:25.000Z
msrc_cve-2026-102276 brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 2026-10-01T01:19:03.000Z 2026-10-01T01:19:03.000Z
msrc_cve-2026-101902 Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method 2026-10-01T01:18:39.000Z 2026-10-01T01:18:39.000Z
msrc_cve-2026-102278 brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 2026-10-01T01:18:17.000Z 2026-10-01T01:18:17.000Z
msrc_cve-2026-102266 PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation 2026-10-01T01:17:54.000Z 2026-10-01T01:17:54.000Z
msrc_cve-2026-102274 PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set 2026-10-01T01:17:32.000Z 2026-10-01T01:17:32.000Z
msrc_cve-2026-102275 PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion 2026-10-01T01:17:09.000Z 2026-10-01T01:17:09.000Z