8.8

CVSS3.1

CVE-2025-66001 - NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)

NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.

πŸ“… Published: Jan. 8, 2026, 10:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS3.1

CVE-2025-14459 - Virt-cdi-controller: unauthorized pvc cloning via dataimportcron

A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC source mechanism.

πŸ“… Published: Jan. 8, 2026, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.1

CVSS3.1

CVE-2025-15224 - libssh key passphrase bypass without agent set

When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.

πŸ“… Published: Jan. 8, 2026, 10:08 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 2:47 p.m.

5.3

CVSS3.1

CVE-2025-15079 - libssh global known_hosts override

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.

πŸ“… Published: Jan. 8, 2026, 10:08 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 2:50 p.m.

5.3

CVSS3.1

CVE-2025-14819 - OpenSSL partial chain store policy bypass

When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make lib…

πŸ“… Published: Jan. 8, 2026, 10:07 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 2:51 p.m.

5.3

CVSS3.1

CVE-2025-14524 - bearer token leak on cross-protocol redirect

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

πŸ“… Published: Jan. 8, 2026, 10:07 a.m. πŸ”„ Last Modified: April 2, 2026, 1:20 p.m.

6.3

CVSS3.1

CVE-2025-14017 - broken TLS options for threaded LDAPS

When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionall…

πŸ“… Published: Jan. 8, 2026, 10:07 a.m. πŸ”„ Last Modified: Jan. 27, 2026, 9:29 p.m.

5.9

CVSS3.1

CVE-2025-13034 - No QUIC certificate pinning with GnuTLS

When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the public key of the server certificate to verify the peer. This check was skipped in a certain condition that would then make curl allow the connection without performing the proper …

πŸ“… Published: Jan. 8, 2026, 10 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 2:54 p.m.

4.9

CVSS3.1

CVE-2026-22242 - CoreShop Vulnerable to SQL Injection via Admin Reports

CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based or time-based techniques. The database account used by the …

πŸ“… Published: Jan. 8, 2026, 9:59 a.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

6.5

CVSS3.1

CVE-2026-21894 - n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks

n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Trigger node allows unauthenticated parties to trigger workflows by sending forged Stripe webhook events. The Stripe Trigger creates and stores a Stripe…

πŸ“… Published: Jan. 8, 2026, 9:56 a.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.
Total resulsts: 348436
Page 2152 of 34,844
Β« previous page Β» next page
Filters