VulnSea

Tagged “vex”

CVEs tagged vex, newest first.

2892 CVEsRSS

CVE-2026-96745Medium· 5.6
3d ago

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers…

▾ SunlitMongoDB · PHP DriverEPSS 0.30%via NVD
CVE-2026-93541Medium· 6.5
3d ago

An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a

An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a

▾ SunlitX.org · libXiEPSS 0.24%via NVD
CVE-2026-67233Medium· 6.0
3d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel management resource's is_authorized/2 delegates to rabbit_mgmt_util:is_authorized_monitor/2, which accepts the monitori…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.30%via NVD
CVE-2026-90959High· 8.1
3d ago

A path traversal vulnerability was found in pulpcore

A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme valida…

▾ TwilightRed Hat · ansible-automation-platform-24/hub-rhel8EPSS 0.32%via NVD
CVE-2026-77874High· 8.6
3d ago

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to vie…

▾ TwilightIBM · Enterprise Build of QuarkusEPSS 0.43%via NVD
CVE-2026-73064Low· 2.9
3d ago

In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream

In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.

▾ Sunlittrustedfirmware · Mbed TLSEPSS 0.10%via NVD
CVE-2026-97059High· 8.2
3d ago

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM inst…

▾ TwilightOFFIS · DCMTKEPSS 0.35%via NVD
CVE-2026-97058Medium· 5.3PoC
3d ago

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision value…

▾ Twilightalexei · sprintf-jsEPSS 0.37%via NVD
CVE-2026-97057High· 7.5
3d ago

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis e…

▾ TwilightNodeRedis · redis-parserEPSS 0.39%via NVD
CVE-2026-88360Medium· 5.5
3d ago

libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images

libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header length is not a multiple of four bytes, the mmap-based loader can expose pixel data at an address that is not properly…

▾ SunlitRed HatEPSS 0.14%via NVD
CVE-2026-88359Medium· 6.5PoC
3d ago

libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format()

libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer…

▾ TwilightRed HatEPSS 0.15%via NVD
CVE-2026-95521High· 7.8
3d ago

A command injection flaw was found in rpm

A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating th…

▾ TwilightRed Hat · rpmEPSS 0.58%via NVD
CVE-2026-95519High· 7.8
3d ago

A flaw was found in rpm

A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest …

▾ TwilightRed Hat · rpmEPSS 0.14%via NVD
CVE-2026-94416Medium· 6.8
3d ago

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not…

▾ SunlitRed Hat · ansible-automation-platform-25/gateway-rhel8EPSS 0.45%via NVD
CVE-2026-97311Medium· 4.3
3d ago

A flaw was found in the Admin REST API of Keycloak, an identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.24%via NVD
CVE-2026-79680Medium· 4.5⚖ disputed
3d ago

Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module

Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication…

▾ Sunlitqt · qtEPSS 0.34%via NVD
CVE-2026-97177Medium· 6.6
3d ago

A flaw was found in the user update mechanism of the Keycloak Admin REST API

A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. Thi…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.24%via NVD
CVE-2026-97176Medium· 4.2
3d ago

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an act…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.17%via NVD
CVE-2026-59980Medium· 6.3
4d ago

hpack is an HTTP/2 Header Encoding for Python

hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively blocking further processing with large en…

▾ Sunlitpython-hyper · hpackEPSS 0.30%via NVD
CVE-2026-75887High· 7.5
4d ago

A flaw was found in the OpenShift console

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to r…

▾ TwilightRed Hat · openshift4/ose-consoleEPSS 0.36%via NVD
CVE-2026-75886High· 7.2
4d ago

A flaw was found in openshift/console

A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows t…

▾ TwilightRed Hat · openshift4/ose-consoleEPSS 0.25%via NVD
CVE-2026-67405Medium· 5.3⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the Web-MQTT handler (deps/rabbitmq_web_mqtt/src/rabbit_web_mqtt_handler.erl:104) nor the Web-STOMP handler (deps/rabbitmq…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.13%via NVD
CVE-2026-67235High· 7.1
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15, The content-header BodySize (a uint64) was stored without validation against max_message_size. The size check ran only when assemb…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.26%via NVD
CVE-2026-67232High· 8.2
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The cowboy WebSocket options at line 117 set compress => true, enabling RFC 7692 permessage-deflate negotiation. The handler does …

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.37%via NVD
CVE-2026-67231Critical· 9.1
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presente…

▾ Midnightrabbitmq · rabbitmq-serverEPSS 0.25%via NVD
CVE-2026-67229Medium· 6.9PoC⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_vhost/2 calls rabbit_data_coercion:atomize_keys/1 (the unsafe variant using binary_to_atom) on the vhost metadata map. The 20 …

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.28%via NVD
CVE-2026-67228Medium· 6.9⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The runtime-parameters lookup path coerces the URL :component segment to an atom with rabbit_data_coercion:to_atom/1 in lookup_component/1 (deps/rabbit/src/…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.28%via NVD
CVE-2026-67221Medium· 5.9
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The AMQP 0-9-1 shovel calls amqp_uri:remove_credentials before storing its connection URI, but the AMQP 1.0 shovel stores the raw …

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.20%via NVD
CVE-2026-67219Medium· 6.0
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_binding/3 parses the routing key as an integer weight N and computes ring positions with lists:seq(NextN0, NextN0 + N - 1). va…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.26%via NVD
CVE-2026-67218Low· 2.1⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.0.22, 4.1.11, 4.2.6, and 4.3.0, accept_content/2 at line 56 calls rabbit_stream_manager:create_super_stream/... directly after is_authorized (which only checks the managem…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.34%via NVD
CVEs tagged “vex” — page 3 · VulnSea