Vulnerabilities
Summary — last 7 days
New vulnerabilities2,738▲ 10 vs. last week
Critical / high1,458▲ 322 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)85▼ 441 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.7) | 0.32% | — | Catalyst Plugin Static SimpleAI | 8/20/2026 | 8/28/2026 | Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies that the content may be stored in a shared cache, and may be reused in responses to… | |
| Modified | High (7.5) | 2.4% | — | Catalyst-plugin-static-simple Project Catalyst-plugin-static-simple | 11/1/2017 | 6/17/2026 | The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself has a '.' character. |