Vulnerabilities

Summary — last 7 days

New vulnerabilities2,623▼ 224 vs. last week
Critical / high1,384▲ 157 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)56▼ 472 vs. last week
–

8 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.1)0.77%—BrunoAI9/4/20269/23/2026
Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../ sequences that resolve outside the…
AnalyzedCritical (9.8)0.32%—Usebruno Bruno4/6/20266/17/2026
Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran npm install between…
DeferredHigh (7.1)0.22%—Bruno Cavalcante GhostwriterAI5/19/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno Cavalcante Ghostwriter allows Reflected XSS.This issue affects Ghostwriter: from n/a through 1.4.
AnalyzedHigh (8.7)0.37%—Usebruno Bruno4/1/20256/17/2026
Bruno is an open source IDE for exploring and testing APIs. A bug in the assertion runtime caused assert expressions to run in Developer Mode, even if Safe Mode was selected. The bug resulted in the sandbox settings to be ignored for the particular case where a single request is run/sent. This vulnerability's attack…
AnalyzedHigh (8.7)0.35%—Usebruno Bruno4/1/20256/17/2026
Bruno is an open source IDE for exploring and testing APIs. Prior to 1.39.1, the custom tool-tip components which internally use react-tooltip were setting the content (in this case the Environment name) as raw HTML which then gets injected into DOM on hover. This, combined with loose Content Security Policy…
AnalyzedMedium (6.5)0.64%—Usebruno Bruno11/4/20246/17/2026
Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer.
ModifiedMedium (5.9)0.98%—Yaxim BrunoYaxim2/9/20176/17/2026
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for yaxim and Bruno (0.8.6 - 0.8.8; Android).
ModifiedHigh (7.5)1.4%—Bruno Massa WEB Services11/20/20096/16/2026
The Web Services module 6.x for Drupal does not perform the expected access control, which allows remote attackers to make unspecified use of an API via unknown vectors.