Vulnerabilities
Summary — last 7 days
New vulnerabilities2,635▼ 211 vs. last week
Critical / high1,376▲ 147 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)81▼ 449 vs. last week
21 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (7.7) | 0.67% | — | Kong API Gateway EnterpriseAI | 9/16/2026 | 9/18/2026 | A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing algorithm is compatible with the type of key used for verification. As a result, an… | |
| Awaiting Analysis | Critical (9.3) | 0.42% | — | Amazon OPS WheelAIAmazon API GatewayAIAmazon CognitoAI | 4/24/2026 | 6/17/2026 | Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the ability to read, modify, and delete all application data across tenants and manage Cognito user accounts within the deployment's User… | |
| Analyzed | Medium (6.5) | 0.47% | — | IBM Webmethods API Gateway | 3/3/2026 | 6/17/2026 | IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to properly validate user-supplied input passed to the url parameter on the /createapi endpoint. An attacker can modify this parameter to use a file:// URI schema instead of… | |
| Analyzed | High (7.8) | 1.1% | — | Bleon-ethical Api-gateway-deploy | 2/24/2026 | 6/17/2026 | bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involving OS Command Injection and Privilege Escalation. This allows an attacker to execute arbitrary commands with root privileges within the container, potentially leading to a container escape and… | |
| Modified | Medium (6.1) | 0.38% | — | Apiida API Gateway Manager | 1/3/2024 | 6/17/2026 | APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection. | |
| Modified | Medium (6.1) | 0.38% | — | Apiida API Gateway Manager | 1/3/2024 | 6/17/2026 | APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS). | |
| Modified | Medium (5.9) | 7.1% | — | OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+40 | 12/8/2020 | 6/17/2026 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both… | |
| Modified | High (7.5) | 11% | — | Apache BatikOracle API GatewayOracle Business IntelligenceOracle Communications Application Session Controller+14 | 11/12/2020 | 6/17/2026 | Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. | |
| Modified | High (7.5) | 8.0% | — | Apache ANTGradleFedoraproject FedoraOracle Agile Engineering Data Management+33 | 10/1/2020 | 6/17/2026 | As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still… | |
| Modified | Critical (9.8) | 2.3% | — | Mulesoft API GatewayMulesoft Mule Runtime | 12/2/2019 | 6/17/2026 | Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code. | |
| Modified | High (7.5) | 3.0% | — | Mulesoft API GatewayMulesoft Mule Runtime | 8/30/2019 | 6/17/2026 | Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to… | |
| Modified | Medium (5.9) | 17% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+78 | 2/27/2019 | 6/17/2026 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid… | |
| Modified | Medium (4.7) | 3.4% | — | Canonical Ubuntu LinuxDebian LinuxNodejs Node.jsOpenssl+16 | 11/15/2018 | 6/17/2026 | Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. | |
| Modified | Medium (5.9) | 12% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js+15 | 10/30/2018 | 6/17/2026 | The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected… | |
| Modified | Medium (5.9) | 4.7% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js+18 | 10/29/2018 | 6/17/2026 | The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1). | |
| Modified | Critical (9.8) | 4.8% | — | Bouncycastle Bc-javaNetapp Oncommand Workflow AutomationOpensuse LeapOracle API Gateway+20 | 7/9/2018 | 6/17/2026 | Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an… | |
| Modified | High (7.5) | 3.6% | — | Bouncycastle Bc-javaBouncycastle Fips Java APIDebian LinuxOracle API Gateway+16 | 6/5/2018 | 6/17/2026 | Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA… | |
| Modified | High (8.1) | 2.3% | — | Oracle API Gateway | 4/24/2017 | 6/17/2026 | Vulnerability in the Oracle API Gateway component of Oracle Fusion Middleware (subcomponent: Oracle API Gateway). The supported version that is affected is 11.1.2.4.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle API Gateway. Successful attacks… | |
| Modified | Critical (9.8) | 90% | — | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 4/17/2017 | 6/17/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modified | Medium (6.5) | 1.2% | — | Broadcom API Gateway | 4/6/2016 | 6/17/2026 | CRLF injection vulnerability in CA API Gateway (formerly Layer7 API Gateway) 7.1 before 7.1.04, 8.0 through 8.3 before 8.3.01, and 8.4 before 8.4.01 allows remote attackers to have an unspecified impact via unknown vectors. | |
| Modified | Medium (5.3) | 39% | — | Apple MAC OS XOracle API GatewayOracle Communications Webrtc Session ControllerOracle Exalogic Infrastructure+21 | 12/6/2015 | 6/17/2026 | The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a… |