CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 5d ago | 6.5 | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1. |
| Exploit 5d ago | 9.8 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers. This issue is fixed in version 1.5.3. |
| Exploit 5d ago | 7.4 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq background jobs remain unaffected. This issue is fixed in versions 4.4.19 and 4.5.12. |
| Exploit 5d ago | 7.5 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-free that can crash the server or potentially allow remote code execution when TLS is enabled. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1. |
| Exploit 5d ago | 8.8 | Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell commands in the file to execute with the current account's privileges, including without a prompt when ZSH_DOTENV_PROMPT=false or after the default prompt accepts an empty Enter response. This issue is fixed in versions released after 2026-05-28. |
| Exploit 5d ago | 5.9 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the check, and all are served — exceeding the operator's intended cap. Version 2.1.0 patches the issue. |
| Exploit 5d ago | 8.1 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no equivalent guard, so an authenticated WebDAV client can `PUT`, `DELETE`, `MKCOL`, `MOVE`, and `COPY` despite the operator's stated intent. Version 2.1.0 patches the issue. |
| Exploit 5d ago | 7.1 | SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to create or overwrite files anywhere writable by the client process. This issue is fixed in version 2026.0.0. |
| Exploit 5d ago | 8.3 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron enables nodeIntegration and disables contextIsolation, run operating-system commands as the victim. This issue is fixed in version 0.103.0. |
| 5d ago | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. |
| 5d ago | 7.5 | Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. |
| 5d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. |
| 5d ago | 7.5 | Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. |
| 5d ago | 9.9 | Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. |
| 5d ago | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. |
| 5d ago | 7.5 | Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. |
| 5d ago | 9.8 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. |
| 5d ago | 7.4 | ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk. |
| 5d ago | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| Exploit 5d ago | 7.7 | BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available. |
| 5d ago | 7.5 | Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. |
| 5d ago | 6 | Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. |
| 5d ago | 8.5 | Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. |
| 5d ago | 8.8 | Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. |
| 5d ago | 8.1 | Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. |
| 5d ago | 9.9 | Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. |
| Exploit 5d ago | 9.9 | Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. |
| 5d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. |
| 5d ago | 7.5 | Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. |
| 5d ago | 8.1 | Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. |