VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2026-58649Medium· 6.5
2w ago

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · .NET 10.0EPSS 0.27%via NVD
CVE-2026-57099High· 7.5
2w ago

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · AspNetCore.ODataEPSS 1.2%via NVD
CVE-2026-20293High· 7.1
2w ago

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user …

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user …

▾ TwilightCisco · Cisco Enterprise NFV Infrastructure SoftwareEPSS 0.16%via NVD
CVE-2026-79602High· 8.8⚖ disputed
2w ago

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.

▾ TwilightXen · XenEPSS 0.17%via NVD
CVE-2026-62437Medium· 6.5
2w ago

When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs relatively early…

When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs relatively early…

▾ SunlitXen · XenEPSS 0.12%via NVD
CVE-2026-19203High· 8.3
2w ago

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by…

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by…

▾ TwilightEclipse Foundation · Eclipse JettyEPSS 0.31%via NVD
CVE-2026-80219High· 8.7
2w ago

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

▾ TwilightRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.23%via NVD
CVE-2026-78234Critical· 9.9
2w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author o…

▾ MidnightRed Hat · rhbac-4/hawtio-gateway-rhel9EPSS 0.39%via NVD
CVE-2026-77968High· 8.2
2w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the Ser…

▾ TwilightRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.42%via NVD
CVE-2026-74860High· 8.5
2w ago

A flaw was found in libxml2 with Python bindings enabled

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This…

▾ TwilightRed Hat · libxml2EPSS 0.38%via NVD
CVE-2026-74859Medium· 6.8
2w ago

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or…

▾ SunlitRed Hat · gnome-tweaksEPSS 0.17%via NVD
CVE-2026-12611High· 8.7
2w ago

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race conditio…

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race conditio…

▾ TwilightEclipse Foundation · Eclipse JettyEPSS 0.25%via NVD
CVE-2026-11573High· 7.1
2w ago

Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase)

Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of elemen…

▾ Twilightqt · qtEPSS 0.39%via NVD
CVE-2026-86512Medium· 6.3PoC
2w ago

A vulnerability was identified in java-json-tools json-patch up to 1.13

A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move O…

▾ Twilightjava-json-tools · json-patchEPSS 0.37%via NVD
CVE-2026-78675High· 8.4⚖ disputed
2w ago

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables…

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

▾ Twilightgitpython · gitpythonEPSS 0.18%via OSV
CVE-2026-86425Low· 3.3
3w ago

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, result…

▾ Sunlitimagemagick · imagemagickEPSS 0.15%via NVD
CVE-2026-86424Low· 2.5
3w ago

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlin…

▾ Sunlitimagemagick · imagemagickEPSS 0.14%via NVD
CVE-2026-86422Low· 3.3
3w ago

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap sym…

▾ Sunlitimagemagick · imagemagickEPSS 0.13%via NVD
CVE-2026-86420Low· 3.7
3w ago

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.

▾ Sunlitimagemagick · imagemagickEPSS 0.32%via NVD
CVE-2026-86404High· 8.8
3w ago

EAP's Artemis deserialization configuration permits deserialization by default

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() met…

▾ TwilightRed Hat · eap7-activemq-artemisEPSS 0.85%via NVD
CVE-2026-18355High· 7.5
3w ago

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base)

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, …

▾ TwilightRed Hat · redhat-ds:11EPSS 0.84%via NVD
CVE-2026-84732High· 8.7
3w ago

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow

▾ TwilightOpenVPN · OpenVPNEPSS 0.54%via NVD
CVE-2026-16028High· 7.5
3w ago

Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream reaches the CLOSED state, stream_state returns the concurrency slot…

Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream reaches the CLOSED state, stream_state returns the concurrency slot…

▾ TwilightRed Hat · Protocol-HTTP2EPSS 0.36%via NVD
CVE-2026-86469Medium· 5.3PoC
3w ago

A flaw was found in GLib2

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation …

▾ TwilightRed Hat · glib2EPSS 0.14%via NVD
CVE-2026-86319Medium· 5.3PoC
3w ago

A vulnerability has been found in java-json-tools json-patch up to 1.13

A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Ha…

▾ Twilightjava-json-tools · json-patchEPSS 0.70%via NVD
CVE-2026-86318Medium· 5.3PoC
3w ago

A flaw has been found in java-json-tools json-patch up to 1.13

A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack ma…

▾ Twilightjava-json-tools · json-patchEPSS 0.76%via NVD
CVE-2026-86308Medium· 5.3PoC
3w ago

A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930

A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Common/Conf/config.php of the component Debug Mod…

▾ Twilightlight0011 · cmsEPSS 0.54%via NVD
CVE-2026-76560High· 7.5
3w ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access contr…

▾ TwilightRed Hat · redhat-ds:11EPSS 0.64%via NVD
CVE-2026-6377High· 7.5
3w ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Man…

▾ TwilightNext4Biz Information Technologies Inc. · CSM (Customer Service Management)EPSS 0.50%via NVD
CVE-2026-19843High· 8.4PoC
3w ago

A flaw was found in 389-ds-base

A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated…

▾ MidnightRed Hat · redhat-ds:11EPSS 0.48%via NVD
CVEs tagged “csaf” — page 53 · VulnSea