Common Vulnerabilities and Exposures (CVE)

CVE-2026-87742

Oct 9, 2026 15:37:02 UTC

A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded messag...

CVE-2026-57967

Oct 9, 2026 15:36:10 UTC

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 throug...

CVE-2026-56857

Oct 9, 2026 15:36:01 UTC

On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to oper...

CVE-2024-3656

Oct 9, 2026 15:35:14 UTC

A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to d...

CVE-2026-78659

Oct 9, 2026 15:34:24 UTC

When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2...

CVE-2026-97332

Oct 9, 2026 15:29:34 UTC

The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allow...

CVE-2026-107810

Oct 9, 2026 15:25:26 UTC

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Nginx...

CVE-2026-107735

Oct 9, 2026 15:24:14 UTC

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, InitializePolicies() starts the sumatrapdfrestrict.ini path with gPolicyRestrictions set to Perm::All and only ORs permission bits, so the INI file never revokes permiss...

CVE-2026-105673

Oct 9, 2026 15:18:26 UTC

An unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the RTSP streaming service on TCP port 554 when the Camera Account feature is enabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory corru...

CVE-2026-107290

Oct 9, 2026 15:15:26 UTC

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback process server-controlled responses with quad...

CVE-2026-107294

Oct 9, 2026 15:15:18 UTC

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileUrl media downloads buffer the complete HT...

CVE-2026-105436

Oct 9, 2026 15:15:11 UTC

Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.

CVE-2026-107299

Oct 9, 2026 15:15:00 UTC

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data re...

CVE-2026-107375

Oct 9, 2026 15:14:52 UTC

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. From 7.0.0 until 9.4.0, reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL da...

CVE-2026-107380

Oct 9, 2026 15:14:45 UTC

savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A ...