CVE-2026-91142
- EPSS 0.09%
- Veröffentlicht 18.09.2026 16:44:09
- Zuletzt bearbeitet 18.09.2026 19:06:08
A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authentica...
CVE-2026-91147
- EPSS 0.33%
- Veröffentlicht 18.09.2026 16:43:51
- Zuletzt bearbeitet 22.09.2026 17:17:28
A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made to the exact U...
CVE-2026-91149
- EPSS 0.35%
- Veröffentlicht 18.09.2026 16:43:46
- Zuletzt bearbeitet 30.09.2026 22:16:34
A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of detac...
CVE-2026-76235
- EPSS 0.36%
- Veröffentlicht 19.08.2026 12:44:55
- Zuletzt bearbeitet 25.08.2026 03:16:58
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial...
CVE-2026-12856
- EPSS 0.29%
- Veröffentlicht 29.06.2026 12:33:52
- Zuletzt bearbeitet 15.07.2026 02:18:11
A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user ...
CVE-2026-44495
- EPSS 0.78%
- Veröffentlicht 11.06.2026 15:33:12
- Zuletzt bearbeitet 11.09.2026 13:18:08
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already po...
CVE-2025-14969
- EPSS 0.38%
- Veröffentlicht 26.01.2026 19:36:40
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potenti...
- EPSS 1.18%
- Veröffentlicht 13.01.2026 15:35:01
- Zuletzt bearbeitet 21.09.2026 17:17:24
A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated J...
CVE-2025-57850
- EPSS 0.18%
- Veröffentlicht 02.12.2025 18:53:35
- Zuletzt bearbeitet 15.04.2026 00:35:42
A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute com...
CVE-2025-9566
- EPSS 1.08%
- Veröffentlicht 05.09.2025 19:54:30
- Zuletzt bearbeitet 28.09.2026 02:17:17
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful...