Recent Vulnerabilities

Sources: amazon_linux archlinux azure_linux bitnami_vulndb capec capec_enrichment_dashboard certeu certfr circl_kev cisa_known_exploited cna_scorecard cnvd csaf_abb csaf_adstecindustrialitgmbh csaf_amd csaf_aumariestergmbhcokg csaf_baadem2mproductsgmbh csaf_beckhoffautomationgmbhcokg csaf_bendergmbhcokg csaf_bosch csaf_bsi csaf_bsi_aggregator csaf_bsi_cvd_white csaf_bsi_white csaf_bsi_wid_white csaf_carlogavazziautomation csaf_certbund csaf_certvde csaf_cisa csaf_cisa_it csaf_cisa_ot csaf_cisco csaf_claaskgaa csaf_codesysgmbh csaf_dell csaf_duraggmbh csaf_endresshauserag csaf_ericsson csaf_euchnergmbhcokg csaf_festosecokg csaf_frauschersensortechnikgmbh csaf_hancom csaf_harmaninternational csaf_helmholzgmbhcokg csaf_himapaulhildebrandtgmbh csaf_hitachi csaf_hpe csaf_huawei csaf_hydacinternationalgmbh csaf_ibm csaf_ifmelectronicgmbh csaf_janitzaelectronicsgmbh csaf_jumogmbhcokg csaf_juniper csaf_kebautomationkg csaf_kukaag csaf_lenovo csaf_lenzese csaf_mbconnectlinegmbh csaf_mettlertoledogmbh csaf_metzconnectgmbh csaf_microsoft csaf_mieleciekg csaf_moxa csaf_murrelektronikgmbh csaf_ncscnl csaf_ndaal csaf_netapp csaf_nozomi csaf_nozominetworks csaf_nvidia csaf_opcfoundation csaf_openeuler csaf_opensuse csaf_oracle csaf_ox csaf_paloalto csaf_panasonic csaf_pentagrid csaf_pepperlfuchsse csaf_phoenix csaf_pilzgmbhcokg csaf_qnap csaf_redhat csaf_samsung csaf_sauterag csaf_schneider csaf_sick csaf_siemens csaf_smasolartechnologyag csaf_suse csaf_swarcotrafficsystemsgmbh csaf_synology csaf_tibco csaf_trend csaf_trumpfsecokg csaf_trustsource csaf_tuxcare csaf_ubiquiti csaf_vartastoragegmbh csaf_vegagrieshaberkg csaf_vmware csaf_wagogmbhcokg csaf_weidmuellerinterfacegmbhcokg csaf_welotecgmbh csaf_wiesemanntheisgmbh csaf_yaskawaeuropegmbh csaf_yokogawa csaf_zyxel cve_forecast cve_icu cve_vs_github_dashboard cvelistv5 cwe_dashboard cwe_enrichment cwec debian_security_tracker drupal emb3d emb3d_dashboard epss_dashboard epss_history epss_kev_enrichment euvd_kev fedora fkie_nvd freebsd gcve gcve_enriched gcve_enrichment gcve_enrichment_dashboard gentoo github gsd jvn kev_ransomware mitre_attack moksha ndaal_kev netbsd nuclei_dashboard nuclei_enrichment nvd nvd_cpe_dictionary openbsd opencve oracle_linux ossf_malicious_packages osv_almalinux osv_alpine osv_bellsoft osv_chainguard osv_cran osv_github_actions osv_golang osv_haskell osv_hex osv_maven osv_npm osv_nuget osv_ocaml osv_ossfuzz osv_packagist osv_pub osv_rocky osv_rubygems osv_rustsec osv_swift osv_ubuntu osv_wolfi publish_stats pysec sadp_pilot ssvc ssvc_dashboard tailscale tsunami_enrichment variot vulnrichment Clear
ID Title Severity CVSS Source Updated
eef-cve-2026-89420 Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free UNKNOWN 7.1 osv_hex unknown
eef-cve-2026-87119 mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed UNKNOWN 8.2 osv_hex unknown
eef-cve-2025-48044 Authorization bypass when bypass policy condition evaluates to true UNKNOWN 8.6 osv_hex unknown
eef-cve-2025-48043 Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization UNKNOWN 8.6 osv_hex unknown
eef-cve-2025-48042 Before action hooks may execute in certain scenarios despite a request being forbidden UNKNOWN 7.1 osv_hex unknown
eef-cve-2025-4754 Missing Session Revocation on Logout in ash_authentication_phoenix UNKNOWN 2.3 osv_hex unknown
eef-cve-2026-82672 Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections UNKNOWN 6.3 osv_hex unknown
eef-cve-2026-86688 Session id is not renewed on authentication in ash_authentication, allowing session fixation UNKNOWN 7.4 osv_hex unknown
eef-cve-2026-76949 Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement UNKNOWN 9.1 osv_hex unknown
eef-cve-2026-91039 dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover UNKNOWN 9.1 osv_hex unknown
eef-cve-2026-88952 OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication UNKNOWN 9.1 osv_hex unknown
eef-cve-2026-86533 Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix UNKNOWN 9.1 osv_hex unknown
eef-cve-2026-82760 Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in UNKNOWN 8.2 osv_hex unknown
eef-cve-2026-82759 Reversible IP address pseudonymisation in AshAuthentication audit log hash mode UNKNOWN 1.8 osv_hex unknown
eef-cve-2026-82685 Confirmation token accepted on any record in AshAuthentication UNKNOWN 7.6 osv_hex unknown
eef-cve-2026-81632 Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix UNKNOWN 7.2 osv_hex unknown
eef-cve-2026-78223 Token revocation record built from unverified JWT claims in AshAuthentication UNKNOWN 6.9 osv_hex unknown
eef-cve-2026-86522 Log injection via an unescaped password reset identity in AshAuthentication UNKNOWN 6.3 osv_hex unknown
eef-cve-2026-85500 `require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication UNKNOWN 9.1 osv_hex unknown
eef-cve-2026-82761 Magic link single-use tokens replayable via TOCTOU race in AshAuthentication UNKNOWN 9.1 osv_hex unknown
eef-cve-2026-82723 Actor record with password digest stored in AshAuthentication audit log entries UNKNOWN 1.8 osv_hex unknown
eef-cve-2026-81637 Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication UNKNOWN 2.3 osv_hex unknown
eef-cve-2026-80218 Sign-in token minted for one resource accepted by another in AshAuthentication UNKNOWN 7.6 osv_hex unknown
eef-cve-2026-43971 Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1 UNKNOWN 6.3 osv_hex unknown
eef-cve-2026-89186 mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches UNKNOWN 6.3 osv_hex unknown
eef-cve-2026-88255 mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot UNKNOWN 6.3 osv_hex unknown
eef-cve-2026-86338 Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle UNKNOWN 6.0 osv_hex unknown
eef-cve-2026-77972 safeurl validated address is not bound to the request, allowing DNS rebinding UNKNOWN 9.0 osv_hex unknown
eef-cve-2026-77866 SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts UNKNOWN 9.0 osv_hex unknown
ghsa-76v6-f83q-pxvh Duplicate Advisory: Hackney has an Allocation of Resources Without Limits or Throttling vulnerabilit UNKNOWN 8.2 ghsa unknown