CVE-2026-76235
- EPSS 0.36%
- Veröffentlicht 19.08.2026 12:44:55
- Zuletzt bearbeitet 20.08.2026 13:08:53
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial...
CVE-2026-12856
- EPSS 0.29%
- Veröffentlicht 29.06.2026 12:33:52
- Zuletzt bearbeitet 15.07.2026 02:18:11
A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user ...
CVE-2026-44495
- EPSS 0.78%
- Veröffentlicht 11.06.2026 15:33:12
- Zuletzt bearbeitet 24.08.2026 13:18:52
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already po...
CVE-2025-14969
- EPSS 0.38%
- Veröffentlicht 26.01.2026 19:36:40
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potenti...
- EPSS 1.18%
- Veröffentlicht 13.01.2026 15:35:01
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated J...
CVE-2025-57850
- EPSS 0.18%
- Veröffentlicht 02.12.2025 18:53:35
- Zuletzt bearbeitet 15.04.2026 00:35:42
A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute com...
CVE-2025-9566
- EPSS 1.08%
- Veröffentlicht 05.09.2025 19:54:30
- Zuletzt bearbeitet 24.08.2026 11:16:37
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful...
CVE-2023-48795
- EPSS 93.31%
- Veröffentlicht 18.12.2023 16:15:10
- Zuletzt bearbeitet 12.05.2026 11:16:15
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client a...
CVE-2023-44487
- EPSS 100%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 11.08.2026 19:37:30
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.