5.3

CVSS3.1

CVE-2026-22693 - Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at th…

📅 Published: Jan. 10, 2026, 5:53 a.m. 🔄 Last Modified: April 18, 2026, 7:15 a.m.

6.5

CVSS3.1

CVE-2026-22689 - Mailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to …

Mailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit WebSocket server is configured to accept connections from any origin. This lack of Origin header validation introduces a Cross-Site WebSocket Hijacking (CSWSH) vulnerability. An attacker can host a malicio…

📅 Published: Jan. 10, 2026, 5:46 a.m. 🔄 Last Modified: April 18, 2026, 7:15 a.m.

8.8

CVSS3.1

CVE-2026-22685 - DevToys Path Traversal (“Zip Slip”) Vulnerability in DevToys Extension Installation

DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exists in the DevToys extension installation mechanism. When processing extension packages (NUPKG archives), DevToys does not sufficiently validate file paths contained within the arc…

📅 Published: Jan. 10, 2026, 5:43 a.m. 🔄 Last Modified: April 18, 2026, 7:15 a.m.

3.7

CVSS3.1

CVE-2026-22611 - AWS SDK for .NET V4 adopted defense in depth enhancement for region parameter value

AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon Glacier, and more. From versions 4.0.0 to before 4.0.3.3, Customer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. This notif…

📅 Published: Jan. 10, 2026, 5:37 a.m. 🔄 Last Modified: April 18, 2026, 7:15 a.m.

7.5

CVSS3.1

CVE-2026-22700 - RustCrypto Has Insufficient Length Validation in decrypt() in SM2-PKE

RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a denial-of-service vulnerability e…

📅 Published: Jan. 10, 2026, 5:17 a.m. 🔄 Last Modified: April 18, 2026, 4:45 p.m.

7.5

CVSS3.1

CVE-2026-22699 - RustCrypto SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt()

RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a denial-of-service vulnerability e…

📅 Published: Jan. 10, 2026, 5:17 a.m. 🔄 Last Modified: April 18, 2026, 7:15 a.m.

8.7

CVSS4.0

CVE-2026-22698 - RustCrypto SM2-PKE has 32-bit Biased Nonce Vulnerability

RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a critical vulnerability exists in…

📅 Published: Jan. 10, 2026, 5:17 a.m. 🔄 Last Modified: April 18, 2026, 7:15 a.m.

2.7

CVSS4.0

CVE-2026-22691 - pypdf has possible long runtimes for malformed startxref

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for invalid startxref entries. When rebuilding the cross-reference…

📅 Published: Jan. 10, 2026, 4:46 a.m. 🔄 Last Modified: April 18, 2026, 7:15 a.m.

2.7

CVSS4.0

CVE-2026-22690 - pypdf has possible long runtimes for missing /Root object with large /Size values

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for missing /Root object with large /Size values. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for actually invalid files. This can be a…

📅 Published: Jan. 10, 2026, 4:41 a.m. 🔄 Last Modified: April 18, 2026, 7:15 a.m.

10

CVSS3.1

CVE-2026-22688 - WeKnora has Command Injection in MCP stdio test

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subproce…

📅 Published: Jan. 10, 2026, 3:41 a.m. 🔄 Last Modified: April 18, 2026, 7:30 p.m.
Total resulsts: 349182
Page 2202 of 34,919
« previous page » next page
Filters