Vulnerabilities

Summary — last 7 days

New vulnerabilities3,063▲ 557 vs. last week
Critical / high1,459▲ 279 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)382▲ 175 vs. last week
–

5 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (6.5)0.39%—Tinyxml2 Project Tinyxml210/27/20246/17/2026
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
AnalyzedMedium (6.5)0.42%—Tinyxml2 Project Tinyxml210/27/20246/17/2026
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
ModifiedHigh (7.5)1.4%—Tinyxml Project Tinyxml12/13/20236/17/2026
StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.
ModifiedHigh (7.5)3.3%—Tinyxml Project TinyxmlDebian Linux10/11/20216/17/2026
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.
ModifiedCritical (9.8)2.3%—Tinyxml2 Project Tinyxml25/16/20186/17/2026
TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use of the library and not a vulnerability in tinyxml2