- EPSS 0.76%
- Veröffentlicht 20.07.2026 14:18:18
- Zuletzt bearbeitet 22.07.2026 19:16:54
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated ad...
CVE-2026-42055
- EPSS 4.02%
- Veröffentlicht 17.06.2026 14:04:32
- Zuletzt bearbeitet 11.08.2026 15:12:52
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_in...
CVE-2026-48864
- EPSS 0.23%
- Veröffentlicht 26.05.2026 16:16:07
- Zuletzt bearbeitet 11.08.2026 10:17:12
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, ...
CVE-2026-9256
- EPSS 9.96%
- Veröffentlicht 22.05.2026 14:11:41
- Zuletzt bearbeitet 11.08.2026 14:48:32
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for ex...
CVE-2026-9149
- EPSS 0.31%
- Veröffentlicht 20.05.2026 23:34:56
- Zuletzt bearbeitet 31.07.2026 18:17:37
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a ...
CVE-2026-9150
- EPSS 0.41%
- Veröffentlicht 20.05.2026 23:16:36
- Zuletzt bearbeitet 31.07.2026 18:17:38
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA51...
CVE-2023-50782
- EPSS 1.12%
- Veröffentlicht 05.02.2024 21:15:11
- Zuletzt bearbeitet 24.03.2026 12:16:08
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
CVE-2023-50781
- EPSS 1.12%
- Veröffentlicht 05.02.2024 21:15:10
- Zuletzt bearbeitet 12.05.2026 11:16:16
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
CVE-2022-3644
- EPSS 0.28%
- Veröffentlicht 25.10.2022 18:15:10
- Zuletzt bearbeitet 07.05.2025 20:15:21
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
CVE-2013-4518
- EPSS 0.26%
- Veröffentlicht 04.11.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 01:55:43
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates