Vulnerabilities

Summary — last 7 days

New vulnerabilities2,744▼ 91 vs. last week
Critical / high1,253▼ 291 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)250▲ 214 vs. last week
–

6 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.5)0.28%—MinizincAI3/27/20246/17/2026
An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is disputed because there is no common libminizinc use case in which an unattended process is supposed to run forever to process a series of atttacker-controlled .mzn files.
ModifiedHigh (8.8)1.3%—Zlib-ng Minizip-ng11/22/20236/17/2026
Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_has_slash function in the mz_os.c file.
ModifiedHigh (8.8)0.93%—Zlib-ng Minizip-ng11/22/20236/17/2026
Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_resolve function in the mz_os.c file.
ModifiedCritical (9.8)3.2%—ZlibSmihica Pyminizip10/14/20237/14/2026
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version,…
ModifiedHigh (7.5)1.5%—Miniz Project Miniz6/27/20186/17/2026
In Miniz 2.0.7, tinfl_decompress in miniz_tinfl.c has an infinite loop because sym2 and counter can both remain equal to zero.
ModifiedMedium (5.5)4.1%—Zlib-ng Minizip-ng1/16/20186/17/2026
Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.