Vulnerabilities

Summary — last 7 days

New vulnerabilities2,768▼ 428 vs. last week
Critical / high1,324▼ 116 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)265▼ 243 vs. last week
–

951 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisMedium (5.3)0.37%—Yawkat LZ4 JavaAI10/6/202610/7/2026
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to…
Awaiting AnalysisMedium (5.3)0.37%—Yawkat LZ4 JavaAI10/6/202610/7/2026
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only…
Awaiting AnalysisHigh (7.3)0.08%—Yawkat LZ4 JavaAI10/6/202610/7/2026
yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation,…
Awaiting AnalysisMedium (5.3)0.37%—Yawkat LZ4 JavaAI10/6/202610/7/2026
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames…
Awaiting AnalysisLow (3.7)0.34%—Yawkat LZ4 JavaAI10/6/202610/7/2026
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust…
Awaiting AnalysisMedium (5.7)0.14%—Rabbitmq Java ClientAI10/6/202610/6/2026
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.35.0, ConnectionFactoryConfigurator.load() includes the raw uri value in wrapped exceptions when AMQP URI parsing fails. Because the URI may contain a plaintext username and password,…
Awaiting AnalysisMedium (6)0.41%—Rabbitmq Java Client LibraryAI10/6/202610/6/2026
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An…
Awaiting AnalysisMedium (4.9)0.49%—Rabbitmq Java ClientAI10/6/202610/6/2026
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at…
DeferredLow (2.9)0.40%—Linlinjava LitemallAI10/5/202610/6/2026
A vulnerability was detected in linlinjava litemall up to 1.8.0. This affects an unknown part of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminAuthController.java of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts.…
DeferredHigh (7.5)0.69%—Handlebars.javaAI9/30/20269/30/2026
Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application…
Awaiting AnalysisLow (2.3)0.30%—Serialize JavascriptAI9/29/20269/30/2026
Serialize JavaScript serializes JavaScript values to a superset of JSON that includes regular expressions and functions. From 7.1.1 until 7.1.2, function values serialized by serialize-javascript are not fully protected against script-closing tags in attacker-influenced function source because SCRIPT_CLOSE_REGEXP can…
DeferredMedium (6.4)0.16%—CSS Javascript ToolboxAI9/25/20269/25/2026
The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbox shortcode in all versions up to, and including, 12.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
DeferredMedium (5.5)0.25%—Java110 MicrocommunityAI9/24/20269/24/2026
A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBack of the file BusinessApi.java of the component fallBack API Endpoint. Such manipulation of the argument fallBackSql leads to sql injection. The attack may be launched remotely. The exploit is…
Awaiting AnalysisHigh (7.5)0.37%—IBM MQAIIBM MQ Java ClientAIIBM MQ JMS ClientAI9/18/20269/21/2026
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
DeferredMedium (4.4)0.19%—CSS Javascript ToolboxAI9/18/20269/18/2026
The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 12.0.6 via the Assignment Engine fields. This is due to insufficient input sanitization and output escaping on assignment data fields including Expressions, URLs, and Advanced assignment…
Awaiting AnalysisHigh (8.7)0.68%—Xerial Snappy-javaAI9/17/20269/22/2026
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination.
Awaiting AnalysisMedium (6.9)0.50%—Xerial Snappy-javaAI9/17/20269/22/2026
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. Attackers controlling compressed input can cause misaligned length values to write…
Awaiting AnalysisCritical (10)0.62%—Prebid Server JavaAI9/17/20269/23/2026
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request parameters can cause the server to send…
Awaiting AnalysisHigh (8.7)0.55%—Rabbitmq Java Client LibraryAI9/16/20269/24/2026
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySize, frameMax) after Connection.Tune negotiation even though AMQP defines frameMax value zero as unlimited and…
Awaiting AnalysisCritical (10)0.48%—Oracle Platform Security FOR JavaAI9/15/20269/17/2026
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
Awaiting AnalysisHigh (8.1)0.37%—Oracle Platform Security FOR JavaAIOracle Fusion MiddlewareAI9/15/20269/16/2026
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
Awaiting AnalysisHigh (7.8)0.14%—Oracle Platform Security FOR JavaAI9/15/20269/16/2026
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Platform…
Awaiting AnalysisCritical (9.8)0.48%—Oracle Platform Security FOR JavaAI9/15/20269/16/2026
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle…
Awaiting AnalysisCritical (9.8)0.48%—Oracle Platform Security FOR JavaAI9/15/20269/16/2026
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle…
Awaiting AnalysisHigh (8.1)0.45%—Oracle Graalvm FOR JDKAIOracle GraalvmAIOracle Java SEAI9/15/20269/22/2026
Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker…