Where
AND
-Infinity
0

Apache CXFApache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)

Risk 76
Severity
7.5
First published (updated )

Symfony TwigTwig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface

Risk 82
Severity
8.7
First published (updated )

maven/io.opentelemetry:opentelemetry-extension-trace-propagatorsopentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation

Risk 43
Severity
7.5
First published (updated )

npm/@opentelemetry/auto-instrumentations-nodeopentelemetry-js: Prometheus exporter process crash via malformed HTTP request

Risk 43
Severity
7.5
First published (updated )

npm/i18next-fs-backendi18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite

Risk 54
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/io.netty:netty-transport-native-epollNetty: epoll transport denial of service via RST on half-closed TCP connection

Risk 43
Severity
7.5
First published (updated )

pip/GitPythonGitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath

Risk 69
Severity
7.8
First published (updated )

pip/MakoMako: Path traversal via backslash URI on Windows in TemplateLookup

Risk 47
Severity
8.7
First published (updated )

pip/notebookjupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content

Risk 80
Severity
8.6
First published (updated )

pip/GitPythonGitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository

Risk 62
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/basic-ftpbasic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering

Risk 43
Severity
7.5
First published (updated )

pip/mistuneMistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles

Risk 47
Severity
8.7
First published (updated )

pip/jupyterlabJupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.

Risk 79
Severity
8.8
First published (updated )

npm/@jupyterlab/help-extensionJupyter Notebook and JupyterLab token theft via stored XSS in help command linker

Risk 70
Severity
8.4
First published (updated )

VMware Spring BootWeak RNG

Risk 54
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

VMware Spring BootA local attacker on the same host as the application may be able to take control of the directory us…

Risk 63
Severity
7
First published (updated )

go/github.com/Azure/go-ntlmsspgo-ntlmssp NTLM challenges can panic on malformed payloads

Risk 43
Severity
7.5
First published (updated )

pip/lxmllxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

Risk 43
Severity
7.5
First published (updated )

Oracle JRELast updated 2 June 2026

Risk 43
Severity
7.5
First published (updated )

maven/org.eclipse.jetty.ee10:jetty-ee10In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two Th…

Risk 41
Severity
7.4
EPSS
0.02%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Microsoft azl3 vim 9.2.0240-1Vim modeline bypass via various options affects Vim < 9.2.0276

Risk 62
Severity
8.2
First published (updated )

npm/handlebarsHandlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options

Risk 51
Severity
8.3
EPSS
0.02%
First published (updated )

npm/handlebarsHandlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial

Risk 54
Severity
8.1
EPSS
0.04%
First published (updated )

npm/handlebarsHandlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )

npm/handlebarsHandlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block

Risk 54
Severity
8.1
EPSS
0.07%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/io.netty:netty-codec-http2Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass

Risk 47
Severity
8.7
First published (updated )

npm/multerMulter vulnerable to Denial of Service via uncontrolled recursion

Risk 33
Severity
8.7
EPSS
0.06%
First published (updated )

npm/minimatchminimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

Risk 33
Severity
8.7
EPSS
0.05%
First published (updated )

GNU C Librarywordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

Risk 46
Severity
7.5
First published (updated )

GNU C Librarygetnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler

Risk 32
Severity
7.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203