Vulnerabilities
Summary — last 7 days
New vulnerabilities2,561▼ 314 vs. last week
Critical / high1,347▲ 83 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
6 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (6.1) | 0.42% | — | Redhat QuarkusAIQuarkus QuteAI | 9/18/2026 | 9/18/2026 | A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This vulnerability can lead to… | |
| Awaiting Analysis | High (8.8) | 0.37% | — | Redhat QuteAIRedhat QuarkusAI | 8/31/2026 | 9/11/2026 | A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive Java internal functions when processing… | |
| Modified | High (8.8) | 1.5% | — | Qutebrowser | 10/21/2021 | 6/17/2026 | qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially crafted `qutebrowserurl:...` URL can lead to execution of qutebrowser commands,… | |
| Modified | Low (3.5) | 1.5% | — | QutebrowserFedoraproject Fedora | 5/7/2020 | 6/17/2026 | In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affected website was subsequently loaded again, the URL was mistakenly… | |
| Modified | High (8.8) | 1.2% | — | Qutebrowser | 7/12/2018 | 6/17/2026 | qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, resulting in arbitrary code execution. | |
| Modified | Medium (6.1) | 1.5% | — | Qutebrowser | 6/26/2018 | 6/17/2026 | qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript code, a website can steal the user's browsing history. This attack appear to be exploitable via the… |