🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-63718 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-67172 HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages w... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-67171 HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal databa... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-63686 A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-63292 Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-63045 Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-59797 Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.
This issue affects Ap... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-59685 Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded.
This issue af... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-58415 Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allo... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-57941 Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy
This issue affects Apache HTTP Server... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-56449 Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.
This issue affects Apache HTTP Ser... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-56154 Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})
This issue affects Apache HTTP Server... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-56153 Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-48005 Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthentic... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-21833 HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks s... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-14316 The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-12540 A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-12541 A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-12544 A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where c... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-12423 A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logi... | HIGH | ????? | ????? | NVD | 6 days ago |