VulnSea

Tagged “vex”

CVEs tagged vex, newest first.

2912 CVEsRSS

CVE-2026-79680Medium· 4.5⚖ disputed
3d ago

Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module

Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication…

▾ Sunlitqt · qtEPSS 0.34%via NVD
CVE-2026-97177Medium· 6.6
3d ago

A flaw was found in the user update mechanism of the Keycloak Admin REST API

A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. Thi…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.24%via NVD
CVE-2026-97176Medium· 4.2
3d ago

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an act…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.17%via NVD
CVE-2026-59980Medium· 6.3
4d ago

hpack is an HTTP/2 Header Encoding for Python

hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively blocking further processing with large en…

▾ Sunlitpython-hyper · hpackEPSS 0.30%via NVD
CVE-2026-75887High· 7.5
4d ago

A flaw was found in the OpenShift console

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to r…

▾ TwilightRed Hat · openshift4/ose-consoleEPSS 0.36%via NVD
CVE-2026-75886High· 7.2
4d ago

A flaw was found in openshift/console

A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows t…

▾ TwilightRed Hat · openshift4/ose-consoleEPSS 0.25%via NVD
CVE-2026-67405Medium· 5.3⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the Web-MQTT handler (deps/rabbitmq_web_mqtt/src/rabbit_web_mqtt_handler.erl:104) nor the Web-STOMP handler (deps/rabbitmq…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.13%via NVD
CVE-2026-67235High· 7.1
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15, The content-header BodySize (a uint64) was stored without validation against max_message_size. The size check ran only when assemb…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.26%via NVD
CVE-2026-67232High· 8.2
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The cowboy WebSocket options at line 117 set compress => true, enabling RFC 7692 permessage-deflate negotiation. The handler does …

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.37%via NVD
CVE-2026-67231Critical· 9.1
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presente…

▾ Midnightrabbitmq · rabbitmq-serverEPSS 0.25%via NVD
CVE-2026-67229Medium· 6.9PoC⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_vhost/2 calls rabbit_data_coercion:atomize_keys/1 (the unsafe variant using binary_to_atom) on the vhost metadata map. The 20 …

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.28%via NVD
CVE-2026-67228Medium· 6.9⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The runtime-parameters lookup path coerces the URL :component segment to an atom with rabbit_data_coercion:to_atom/1 in lookup_component/1 (deps/rabbit/src/…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.28%via NVD
CVE-2026-67221Medium· 5.9
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The AMQP 0-9-1 shovel calls amqp_uri:remove_credentials before storing its connection URI, but the AMQP 1.0 shovel stores the raw …

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.20%via NVD
CVE-2026-67219Medium· 6.0
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_binding/3 parses the routing key as an integer weight N and computes ring positions with lists:seq(NextN0, NextN0 + N - 1). va…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.26%via NVD
CVE-2026-67218Low· 2.1⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.0.22, 4.1.11, 4.2.6, and 4.3.0, accept_content/2 at line 56 calls rabbit_stream_manager:create_super_stream/... directly after is_authorized (which only checks the managem…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.34%via NVD
CVE-2026-66075Low· 2.3⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, is_authorized/2 for the /federation-links/.../restart route uses is_authorized_monitor (accepts the monitoring tag), while allowed…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.24%via NVD
CVE-2026-66074Medium· 6.0
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, match_value/3 passes the user-supplied ?name= regular expression to re:run with no match_limit option, and executes it once per re…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.33%via NVD
CVE-2026-66068Medium· 5.6
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, ?LOG_DEBUG("shutting down Shovel '~ts', ... Shovel state: ~tp", [Name, State]) formats the entire state map. The 'uris' field hold…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.12%via NVD
CVE-2026-66072Medium· 6.0PoC
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, get_chunk_selector/1 calls binary_to_atom on the raw client-supplied <<"chunk_selector">> property from post-auth subscribe and re…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.33%via NVD
CVE-2026-66069Low· 2.3⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13, 4.2.7, and 4.3.0, is_authorized/2 uses is_authorized_monitor for all methods. DELETE resets rabbit_core_metrics:reset_auth_attempt_metrics(). Impact is cosmetic (cou…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.40%via NVD
CVE-2026-66067Medium· 6.0
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The stream open handler calls only check_vhost_access; it omits the node/vhost/user connection-limit checks that rabbit_reader performs for AMQP. A develope…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.35%via NVD
CVE-2026-67224Low· 2.1⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The trace consumer constructs the output path as filename:join(TraceDir, Name ++ ".log") where Name comes from PUT /api/traces/:vh…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.38%via NVD
CVE-2026-66077High· 7.3
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, The management UI uses EJS 1.0 in which <%= ... %> does NOT HTML-escape. connection.ejs:135 renders <%= connection.ssl_details.peer_cert_…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.30%via NVD
CVE-2026-67240Low· 2.3PoC⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, pattern_to_regex maps % -> .*? and _ -> ., then compiles ^...$ with only [unicode]; re:run is called with only [{capture, none}] - no explicit match_limit. …

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.26%via NVD
CVE-2026-67220Medium· 6.0
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, 4.3.0, When a binding is created on an x-jms-topic exchange, add_binding/3 reads the rjms_erlang_selector argument and passes it through erl_…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.29%via NVD
CVE-2026-66080Medium· 5.9
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.11, 4.2.6, and 4.3.0, validate_partitions only checks that the requested partition count is at least 1, with no upper bound. A large count such as lists:seq(0, 500000000…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.28%via NVD
CVE-2026-96889High· 7.8PoC
4d ago

A flaw was found in librsvg

A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly fre…

▾ MidnightRed Hat · glycin-loadersEPSS 0.13%via NVD
CVE-2026-85475High· 7.2
4d ago

A flaw was found in the Ansible Automation Platform automation controller

A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and …

▾ TwilightRed Hat · ansible-automation-platform-27/controller-rhel9EPSS 0.43%via NVD
CVE-2026-84724Medium· 6.6
4d ago

An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem

An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation def…

▾ SunlitRed Hat · automation-controllerEPSS 0.29%via NVD
CVE-2026-84721Medium· 6.4
4d ago

A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend

A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and port from a notification template directly to the …

▾ SunlitRed Hat · ansible-automation-platform-27/controller-rhel9EPSS 0.17%via NVD
CVEs tagged “vex” — page 4 · VulnSea