Where
AND
-Infinity
0

npm/undiciundici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent

Risk 41
Severity
7.4
EPSS
0.46%
First published (updated )

npm/undiciundici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse

Risk 79
Severity
8.8
First published (updated )

npm/undiciundici WebSocket client vulnerable to denial of service via fragment count bypass

Risk 43
Severity
7.5
First published (updated )

IBM Maximo Application Suiteprotobufjs: Denial of service through unbounded Any expansion during JSON conversion

Risk 43
Severity
7.5
First published (updated )

IBM Maximo Application SuiteAxios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM Maximo Application SuiteAxios: Allocation of Resources Without Limits or Throttling in axios

Risk 43
Severity
7.5
First published (updated )

IBM Maximo Application SuiteAxios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter

Risk 43
Severity
8.2
First published (updated )

IBM Maximo Application SuiteAxios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

Risk 43
Severity
7.5
First published (updated )

IBM Maximo Application SuiteAxios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

Risk 64
Severity
8.7
First published (updated )

IBM Maximo Application SuiteAxios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

Risk 49
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM Maximo Application SuiteAxios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions

Risk 54
Severity
8.2
First published (updated )

npm/protobufjsprotobufjs: Denial of Service via unbounded recursive JSON descriptor expansion

Risk 43
Severity
7.5
First published (updated )

IBM Maximo Application SuiteIBM Maximo Application Suite privilege escalation

Risk 79
Severity
8.8
First published (updated )

IBM Maximo Application SuiteIBM Maximo Application Suite SQL injection

Risk 79
Severity
8.8
First published (updated )

IBM Maximo Application Suite - Manage ComponentIBM Maximo Application Suite information disclosure

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM Maximo Application Suite - Manage ComponentIBM Maximo Application Suite information disclosure

Risk 45
Severity
7.5
First published (updated )

IBM Maximo Application SuiteIBM Maximo Application Suite information disclosure

Risk 45
Severity
7.5
First published (updated )

IBM Maximo Application Suite - Manage ComponentIBM Maximo Asset Management cross-site request forgery

Risk 80
Severity
8.8
First published (updated )

IBM Maximo Asset ManagementIBM Maximo Asset Management information disclosure

Risk 45
Severity
7.5
First published (updated )

IBM Maximo Asset ManagementIBM Maximo Application Suite command injection

Risk 77
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM Maximo Asset ManagementIBM Maximo Asset Management is vulnerable to HTTP header injection, caused by improper validation of…

Risk 45
Severity
7.2
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203