Количество 25 045
Количество 25 045
CVE-2026-57453
Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction
CVE-2026-57452
Vim: Out-of-bounds Read with libsodium-encrypted Files
CVE-2026-57451
Vim: Out-of-bounds Read in Text Property Count
CVE-2026-57438
Nokogiri: Possible Use-After-Free in XInclude Processing
CVE-2026-57437
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
CVE-2026-57436
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
CVE-2026-57435
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
CVE-2026-57434
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
CVE-2026-57433
Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
CVE-2026-57432
Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack
CVE-2026-57236
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
CVE-2026-57235
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
CVE-2026-57234
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
CVE-2026-57231
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
CVE-2026-57220
RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
CVE-2026-57219
RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
CVE-2026-57217
RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
CVE-2026-57216
RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
CVE-2026-57215
RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom
CVE-2026-57213
RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-57453 Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57452 Vim: Out-of-bounds Read with libsodium-encrypted Files | CVSS3: 5.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57451 Vim: Out-of-bounds Read in Text Property Count | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57438 Nokogiri: Possible Use-After-Free in XInclude Processing | CVSS3: 6.6 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57437 Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57436 Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57435 Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=` | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57434 Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record | CVSS3: 9.8 | 0% Низкий | 13 дней назад | |
CVE-2026-57432 Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack | CVSS3: 7.5 | 0% Низкий | 19 дней назад | |
CVE-2026-57236 Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception | CVSS3: 8.2 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57235 Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` | CVSS3: 8.2 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57234 Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247 | CVSS3: 2.6 | 0% Низкий | около 1 месяца назад | |
CVE-2026-57231 Podman: Malformed Image can trick podman run into leaking host environment variables into the container | 0% Низкий | около 1 месяца назад | ||
CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS | CVSS3: 7.5 | 1% Низкий | 19 дней назад | |
CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations | CVSS3: 7.5 | 1% Низкий | 19 дней назад | |
CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass | CVSS3: 6.5 | 0% Низкий | 12 дней назад | |
CVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks | CVSS3: 6.8 | 1% Низкий | 19 дней назад | |
CVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom | 0% Низкий | 19 дней назад | ||
CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering | CVSS3: 4.8 | 0% Низкий | 19 дней назад |
Уязвимостей на страницу