Vulnerabilities
Summary — last 7 days
New vulnerabilities2,537▼ 360 vs. last week
Critical / high1,344▲ 80 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (10) | 0.62% | — | Linuxfoundation Loopback-connector-postgresql | 8/12/2022 | 6/17/2026 | Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to inject arbitrary SQL which may affect the confidentiality and integrity of data stored on the… | |
| Modified | Medium (6) | 0.33% | — | V4l2loopback Project V4l2loopback | 8/4/2022 | 6/17/2026 | Depending on the way the format strings in the card label are crafted it's possible to leak kernel stack memory. There is also the possibility for DoS due to the v4l2loopback kernel module crashing when providing the card label on request (reproduce e.g. with many %s modifiers in a row). | |
| Modified | Critical (9.8) | 1.5% | — | IBM Loopback | 12/21/2020 | 6/17/2026 | Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and cause a denial of service or possibly execute code. IBM X-Force ID: 192706. |