Recent
Open Redirect in MISP Installer-Generated Apache Configuration
Published 2026-07-28 by CIRCL
Apache Tomcat: DoS via WebSocket chat example
Published 2026-07-28 by apache
Anchore Enterprise Privilege Escalation via User Management API
Published 2026-07-28 by VulnCheck
Search Order Hijacking in ArkSigner's ArkSigner Desktop Client
Published 2026-07-28 by TR-CERT
SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory
Published 2026-07-28 by Mattermost
DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick
Published 2026-07-28 by CIRCL
Apache Axis2/Java: deserialization of untrusted Data
Published 2026-07-28 by apache
Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Published 2026-07-28 by apache
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
Published 2026-07-28 by apache
Pivotick Unvalidated Node Image URLs Allow Unintended Client-Side Requests
Published 2026-07-28 by CIRCL
Pivotick Prototype-Key Collision in Tree Layout and Cycle Detection Allows Graph Manipulation and Denial of Service
Published 2026-07-28 by CIRCL
Pivotick - Stored DOM-Based Cross-Site Scripting via Unescaped Markdown Node References
Published 2026-07-28 by CIRCL
Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data
Published 2026-07-28 by CIRCL
Stored DOM-Based Cross-Site Scripting in Node Modal Headers
Published 2026-07-28 by CIRCL
nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure
Published 2026-07-28 by VulDB
Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication bypass via trailing slash
Published 2026-07-28 by redhat
DOM-Based Cross-Site Scripting via Unsanitized SVG Node Icons
Published 2026-07-28 by CIRCL
Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1
Published 2026-07-28 by Joomla
Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute
Published 2026-07-28 by Wordfence
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions <= 3.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Published 2026-07-28 by Wordfence
Load more ↓