5.3

CVSS3.1

CVE-2026-32990 - Apache Tomcat: Fix for CVE-2025-66614 is incomplete

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116,…

πŸ“… Published: April 9, 2026, 7:23 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2026-29146 - Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recomme…

πŸ“… Published: April 9, 2026, 7:21 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

9.1

CVSS3.1

CVE-2026-29145 - Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Nati…

πŸ“… Published: April 9, 2026, 7:20 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2026-29129 - Apache Tomcat: TLS cipher order is not preserved

Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

πŸ“… Published: April 9, 2026, 7:19 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

6.9

CVSS4.0

CVE-2026-5973 - FoundationAgents MetaGPT common.py get_mime_type os command injection

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was i…

πŸ“… Published: April 9, 2026, 7:15 p.m. πŸ”„ Last Modified: April 10, 2026, 9:29 a.m.

6.1

CVSS3.1

CVE-2026-25854 - Apache Tomcat: Occasionally open redirect

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100. Other, uns…

πŸ“… Published: April 9, 2026, 7:13 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2026-24880 - Apache Tomcat: Request smuggling via invalid chunk extension

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, …

πŸ“… Published: April 9, 2026, 7:12 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

7.1

CVSS4.0

CVE-2026-39977 - flatpak-builder has a path traversal leading to arbitrary file read on host when installing licence…

flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key takes an array of paths to user defined licence files relative to the source directory of the module. The paths from that array are resolved using g_file_resolve_relative_path() and v…

πŸ“… Published: April 9, 2026, 7:05 p.m. πŸ”„ Last Modified: April 9, 2026, 7:05 p.m.

7.8

CVSS3.1

CVE-2026-34734 - HDF5: H5T__conv_struct Use After Free

HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed object is referenced in a memmove call from H5T__conv_struct. The original object wa…

πŸ“… Published: April 9, 2026, 7:01 p.m. πŸ”„ Last Modified: April 9, 2026, 7:01 p.m.

6.9

CVSS4.0

CVE-2026-5972 - FoundationAgents MetaGPT terminal.py Terminal.run_command os command injection

A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed t…

πŸ“… Published: April 9, 2026, 7 p.m. πŸ”„ Last Modified: April 10, 2026, 2:13 p.m.
Total resulsts: 343921
Page 38 of 34,393
Β« previous page Β» next page
Filters