CVE-2025-40778High· 8.6▾ MidnightPoC availableUnder certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 th…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 47.3 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
3 GitHub repos (last check)
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48100High· 8.7Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory compliant transactions
CVE-2025-11411NoneNLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks
CVE-2026-32162High· 8.4Windows COM Elevation of Privilege Vulnerability
CVE-2026-95985High· 8.8The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context
CVE-2026-45602Critical· 9.1Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability
CVE-2026-62364Low· 2.3wlc is a Weblate command-line client using Weblate's REST API