Vulnerabilities
Summary — last 7 days
New vulnerabilities2,768▼ 428 vs. last week
Critical / high1,324▼ 116 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)265▼ 243 vs. last week
951 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (5.3) | 0.37% | — | Yawkat LZ4 JavaAI | 10/6/2026 | 10/7/2026 | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to… | |
| Awaiting Analysis | Medium (5.3) | 0.37% | — | Yawkat LZ4 JavaAI | 10/6/2026 | 10/7/2026 | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only… | |
| Awaiting Analysis | High (7.3) | 0.08% | — | Yawkat LZ4 JavaAI | 10/6/2026 | 10/7/2026 | yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation,… | |
| Awaiting Analysis | Medium (5.3) | 0.37% | — | Yawkat LZ4 JavaAI | 10/6/2026 | 10/7/2026 | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames… | |
| Awaiting Analysis | Low (3.7) | 0.34% | — | Yawkat LZ4 JavaAI | 10/6/2026 | 10/7/2026 | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust… | |
| Awaiting Analysis | Medium (5.7) | 0.14% | — | Rabbitmq Java ClientAI | 10/6/2026 | 10/6/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.35.0, ConnectionFactoryConfigurator.load() includes the raw uri value in wrapped exceptions when AMQP URI parsing fails. Because the URI may contain a plaintext username and password,… | |
| Awaiting Analysis | Medium (6) | 0.41% | — | Rabbitmq Java Client LibraryAI | 10/6/2026 | 10/6/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An… | |
| Awaiting Analysis | Medium (4.9) | 0.49% | — | Rabbitmq Java ClientAI | 10/6/2026 | 10/6/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at… | |
| Deferred | Low (2.9) | 0.40% | — | Linlinjava LitemallAI | 10/5/2026 | 10/6/2026 | A vulnerability was detected in linlinjava litemall up to 1.8.0. This affects an unknown part of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminAuthController.java of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts.… | |
| Deferred | High (7.5) | 0.69% | — | Handlebars.javaAI | 9/30/2026 | 9/30/2026 | Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application… | |
| Awaiting Analysis | Low (2.3) | 0.30% | — | Serialize JavascriptAI | 9/29/2026 | 9/30/2026 | Serialize JavaScript serializes JavaScript values to a superset of JSON that includes regular expressions and functions. From 7.1.1 until 7.1.2, function values serialized by serialize-javascript are not fully protected against script-closing tags in attacker-influenced function source because SCRIPT_CLOSE_REGEXP can… | |
| Deferred | Medium (6.4) | 0.16% | — | CSS Javascript ToolboxAI | 9/25/2026 | 9/25/2026 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbox shortcode in all versions up to, and including, 12.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Deferred | Medium (5.5) | 0.25% | — | Java110 MicrocommunityAI | 9/24/2026 | 9/24/2026 | A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBack of the file BusinessApi.java of the component fallBack API Endpoint. Such manipulation of the argument fallBackSql leads to sql injection. The attack may be launched remotely. The exploit is… | |
| Awaiting Analysis | High (7.5) | 0.37% | — | IBM MQAIIBM MQ Java ClientAIIBM MQ JMS ClientAI | 9/18/2026 | 9/21/2026 | IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling. | |
| Deferred | Medium (4.4) | 0.19% | — | CSS Javascript ToolboxAI | 9/18/2026 | 9/18/2026 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 12.0.6 via the Assignment Engine fields. This is due to insufficient input sanitization and output escaping on assignment data fields including Expressions, URLs, and Advanced assignment… | |
| Awaiting Analysis | High (8.7) | 0.68% | — | Xerial Snappy-javaAI | 9/17/2026 | 9/22/2026 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination. | |
| Awaiting Analysis | Medium (6.9) | 0.50% | — | Xerial Snappy-javaAI | 9/17/2026 | 9/22/2026 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. Attackers controlling compressed input can cause misaligned length values to write… | |
| Awaiting Analysis | Critical (10) | 0.62% | — | Prebid Server JavaAI | 9/17/2026 | 9/23/2026 | Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request parameters can cause the server to send… | |
| Awaiting Analysis | High (8.7) | 0.55% | — | Rabbitmq Java Client LibraryAI | 9/16/2026 | 9/24/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySize, frameMax) after Connection.Tune negotiation even though AMQP defines frameMax value zero as unlimited and… | |
| Awaiting Analysis | Critical (10) | 0.48% | — | Oracle Platform Security FOR JavaAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Awaiting Analysis | High (8.1) | 0.37% | — | Oracle Platform Security FOR JavaAIOracle Fusion MiddlewareAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Awaiting Analysis | High (7.8) | 0.14% | — | Oracle Platform Security FOR JavaAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Platform… | |
| Awaiting Analysis | Critical (9.8) | 0.48% | — | Oracle Platform Security FOR JavaAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle… | |
| Awaiting Analysis | Critical (9.8) | 0.48% | — | Oracle Platform Security FOR JavaAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle… | |
| Awaiting Analysis | High (8.1) | 0.45% | — | Oracle Graalvm FOR JDKAIOracle GraalvmAIOracle Java SEAI | 9/15/2026 | 9/22/2026 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker… |