Browse vulnerabilities

155 results

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-74900 Medium 0.3% 9.8 openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM…
CVE-2026-59251 Medium 0.3% 7.5 Allocation of resources without limits in Erlang/OTP public_key certificate path validatio…
CVE-2026-81705 Medium 0.3% 7.5 openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump wh…
CVE-2026-28386 Medium 0.3% 7.5 Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-…
CVE-2026-58101 Medium 0.3% 7.5 Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL point…
CVE-2026-74880 Medium 0.3% 9.8 openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in key…
CVE-2026-74892 Medium 0.3% 7.5 openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standa…
CVE-2026-81719 Medium 0.3% 7.8 openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient cont…
CVE-2026-81701 Medium 0.3% 9.8 openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins,…
CVE-2026-66402 Medium 0.3% 9.8 FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate iden…
CVE-2026-74891 Medium 0.3% 9.8 openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone…
CVE-2026-81698 Medium 0.3% 7.5 openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info …
CVE-2026-74884 Medium 0.3% 7.5 openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_sa…
CVE-2026-74893 Medium 0.3% 8.8 openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in con…
CVE-2026-54876 Medium 0.3% 7.5 Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has ena…
CVE-2026-45363 Medium 0.3% 9.1 ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to …
CVE-2026-74879 Medium 0.3% 7.5 openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in t…
CVE-2026-74883 Medium 0.3% 8.8 openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plu…
CVE-2026-74874 Medium 0.3% 7.5 openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for ste…
CVE-2022-4991 Medium 0.3% 7.4 Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirecto…
CVE-2026-74877 Medium 0.2% 8.8 openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerabili…
CVE-2026-31789 Medium 0.2% 9.8 Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string …
CVE-2026-81700 Medium 0.2% 9.8 openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gp…
CVE-2026-34181 Medium 0.2% 7.4 Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation fo…
CVE-2026-57163 Medium 0.2% 9.1 PJSIP is a free and open source multimedia communication library written in C. Prior to co…
CVE-2026-74901 Medium 0.2% 9.8 openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pq…
CVE-2026-75803 Medium 0.2% 9.1 Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can repor…
CVE-2026-52767 Medium 0.2% 8.2 YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpS…
CVE-2026-74876 Medium 0.2% 9.8 openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict…
CVE-2026-74889 Medium 0.2% 9.8 openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in k…
CVE-2026-81688 Medium 0.2% 7.5 openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in th…
CVE-2026-81689 Medium 0.2% 7.5 openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKD…
CVE-2026-81691 Medium 0.2% 7.5 openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_w…
CVE-2026-81704 Medium 0.2% 7.5 openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D…
CVE-2026-70454 Medium 0.2% 8.0 rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contai…
CVE-2026-74875 Medium 0.2% 9.8 openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonsc…
CVE-2026-74888 Medium 0.2% 7.5 openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation constructio…
CVE-2026-48697 Medium 0.2% 7.4 FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HT…
CVE-2026-62243 Medium 0.2% 7.5 Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions…
CVE-2026-84975 Medium 0.2% 7.4 PJSIP is a free and open source multimedia communication library written in C. In 2.17 and…
CVE-2026-6958 Medium 0.1% 7.8 Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability i…
CVE-2026-81702 Medium 0.1% 9.8 openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading ide…
CVE-2026-81714 Medium 0.1% 7.0 openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint m…
CVE-2026-45784 Medium 0.1% 7.1 rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 unt…
CVE-2026-81718 Medium 0.1% 7.5 openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only…
CVE-2026-45221 Medium 0.1% 7.8 Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privilege…
CVE-2026-74882 Medium 0.1% 7.5 openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trust…
CVE-2022-49036 Medium 0.1% 7.8 An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL confi…
CVE-2026-41447 Medium 0.1% 7.8 FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows lo…
CVE-2026-41859 Medium 0.1% 7.8 A network man-in-the-middle between nats-sync and the BOSH director can steal the director…
← Prev Page 2 of 4 Next →