Количество 25 065
Количество 25 065
CVE-2026-34073
cryptography has incomplete DNS name constraint enforcement on peer names
CVE-2026-34059
Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()
CVE-2026-34043
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
CVE-2026-34032
Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
CVE-2026-34003
Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access
CVE-2026-34001
Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption
CVE-2026-33999
Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling
CVE-2026-33948
jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input
CVE-2026-33947
jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()
CVE-2026-33941
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
CVE-2026-33940
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
CVE-2026-33939
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
CVE-2026-33938
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
CVE-2026-33937
Handlebars.js has JavaScript Injection via AST Type Confusion
CVE-2026-33936
python-ecdsa: Denial of Service via improper DER length validation in crafted private keys
CVE-2026-33916
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
CVE-2026-33896
Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
CVE-2026-33895
Forge has signature forgery in Ed25519 due to missing S > L check
CVE-2026-33891
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
CVE-2026-33857
Apache HTTP Server: Off-by-one OOB reads in AJP getter functions
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-34073 cryptography has incomplete DNS name constraint enforcement on peer names | 0% Низкий | 4 месяца назад | ||
CVE-2026-34059 Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data() | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-34043 Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects | 0% Низкий | 4 месяца назад | ||
CVE-2026-34032 Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string) | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-34003 Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access | 0% Низкий | 3 месяца назад | ||
CVE-2026-34001 Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption | 0% Низкий | 3 месяца назад | ||
CVE-2026-33999 Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling | 0% Низкий | 3 месяца назад | ||
CVE-2026-33948 jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input | 0% Низкий | 4 месяца назад | ||
CVE-2026-33947 jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted() | CVSS3: 6.2 | 0% Низкий | 4 месяца назад | |
CVE-2026-33941 Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options | 0% Низкий | 4 месяца назад | ||
CVE-2026-33940 Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial | 1% Низкий | 4 месяца назад | ||
CVE-2026-33939 Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation | 1% Низкий | 4 месяца назад | ||
CVE-2026-33938 Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block | 1% Низкий | 4 месяца назад | ||
CVE-2026-33937 Handlebars.js has JavaScript Injection via AST Type Confusion | 2% Низкий | 4 месяца назад | ||
CVE-2026-33936 python-ecdsa: Denial of Service via improper DER length validation in crafted private keys | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-33916 Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection | 0% Низкий | 4 месяца назад | ||
CVE-2026-33896 Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation) | 0% Низкий | 4 месяца назад | ||
CVE-2026-33895 Forge has signature forgery in Ed25519 due to missing S > L check | 1% Низкий | 4 месяца назад | ||
CVE-2026-33891 Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input | 1% Низкий | 4 месяца назад | ||
CVE-2026-33857 Apache HTTP Server: Off-by-one OOB reads in AJP getter functions | CVSS3: 5.3 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу