Vulnerabilities
Summary — last 7 days
New vulnerabilities3,045▲ 455 vs. last week
Critical / high1,424▲ 188 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)389▲ 174 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (4) | 1.8% | — | Io-socket-ssl | 1/14/2011 | 6/16/2026 | The IO::Socket::SSL module 1.35 for Perl, when verify_mode is not VERIFY_NONE, fails open to VERIFY_NONE instead of throwing an error when a ca_file/ca_path cannot be verified, which allows remote attackers to bypass intended certificate restrictions. | |
| Modified | Medium (4.3) | 1.00% | — | Io-socket-ssl | 8/31/2009 | 6/16/2026 | The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate. |