Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
Bitnami VulnDB is not individually searchable yet β the search will cover the sources available on the search page.
| ID | Description | Published | Updated |
|---|---|---|---|
| bit-parse-2026-100632 | Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery | 2026-10-01T10:36:21.879Z | 2026-10-01T10:55:19.103Z |
| bit-parse-2026-100631 | Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injection | 2026-10-01T10:36:20.756Z | 2026-10-01T10:55:19.103Z |
| bit-wordpress-2026-87902 | 2026-09-29T09:00:28.803Z | 2026-10-01T09:55:18.588Z | |
| bit-tomcat-2026-87022 | Apache Tomcat: WebSocket message smuggling with per-message-deflate | 2026-10-01T09:36:37.109Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-86350 | Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up | 2026-10-01T09:36:35.863Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-86248 | Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled | 2026-10-01T09:36:34.620Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-79677 | Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout | 2026-10-01T09:36:33.350Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-78437 | Apache Tomcat: HTTP/2 DoS via malformed request | 2026-10-01T09:36:32.198Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-78383 | Apache Tomcat: AJP DoS via missing request body | 2026-10-01T09:36:30.969Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-77791 | Apache Tomcat: DoS via busy wait during WebSocket close | 2026-10-01T09:36:29.754Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-77762 | Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request | 2026-10-01T09:36:28.552Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-77756 | Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests | 2026-10-01T09:36:27.286Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-76183 | Apache Tomcat: Bypass of security constraints for WebSocket endpoints | 2026-10-01T09:36:26.067Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-75973 | Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured | 2026-10-01T09:36:24.843Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-73581 | Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore | 2026-10-01T09:36:23.598Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67421 | RabbitMQ: Stored HTML Injection in RabbitMQ Management OAuth Error Handling | 2026-10-01T09:34:00.722Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67420 | RabbitMQ OAuth credential refresh retains revoked runtime tags | 2026-10-01T09:33:59.215Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67419 | RabbitMQ: Consecutive topic wildcards cause combinatorial routing work | 2026-10-01T09:33:57.784Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67415 | RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Service | 2026-10-01T09:33:56.453Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67413 | RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an Unbounded LIKE Regular Expression | 2026-10-01T09:33:55.170Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67412 | RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message access | 2026-10-01T09:33:53.667Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67411 | RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass | 2026-10-01T09:33:52.137Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67410 | RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint | 2026-10-01T09:33:50.763Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67409 | RabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication DoS | 2026-10-01T09:33:49.456Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67408 | RabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node Denial of Service | 2026-10-01T09:33:47.951Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67407 | RabbitMQ: Incomplete fix for CVE-2026-44838: `escape_regex_char/1` does not escape `-`, leaving room for an MQTT topic permission bypass | 2026-10-01T09:33:46.619Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67406 | RabbitMQ: Federation and Shovel Gen-Servers Lack format_status Callback β Plaintext Credentials Exposed in Crash Dumps and sys:get_status | 2026-10-01T09:33:45.070Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67405 | RabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation) | 2026-10-01T09:33:43.575Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67404 | RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch | 2026-10-01T09:33:41.987Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67242 | RabbitMQ: OAuth2 is_integer(Exp) guard skips token-expiry checks for float exp | 2026-10-01T09:33:40.589Z | 2026-10-01T09:55:18.588Z |