|
2021
|
8.2 |
HIGH
Network
|
messagepack
|
messagepack
|
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes Lz4Block and Lz4…
|
CWE-20
Improper Input Validation
|
CVE-2026-48109
|
2026-06-24 02:25 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2022
|
7.5 |
HIGH
Network
|
messagepack
|
messagepack
|
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension len…
|
CWE-125 CWE-190 CWE-407 CWE-409 CWE-470 CWE-502 CWE-674 CWE-789 CWE-1188
Out-of-bounds Read Integer Overflow or Wraparound Inefficient Algorithmic Complexity Improper Handling of Highly Compressed Data (Data Amplification) Unsafe Reflection Deserialization of Untrusted Data Uncontrolled Recursion Memory Allocation with Excessive Size Value Insecure Default Initialization of Resource
|
CVE-2026-48502
|
2026-06-24 02:25 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2023
|
7.5 |
HIGH
Network
|
messagepack
|
messagepack
|
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursively descends into nested arrays and maps without incrementing the reader depth o…
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-48506
|
2026-06-24 02:24 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2024
|
8.1 |
HIGH
Network
|
-
|
-
|
piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() paths read the filename option via plain member access. Both reads fall through…
|
CWE-94 CWE-1321
Code Injection Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-55388
|
2026-06-24 02:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2025
|
6.1 |
MEDIUM
Network
|
astro
|
astro
|
Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterates over object keys and passes them directly to addAttribute, which interpolate…
|
CWE-79
Cross-site Scripting
|
CVE-2026-54298
|
2026-06-24 02:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2026
|
- |
|
-
|
-
|
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This…
|
CWE-200 CWE-522
Information Exposure Insufficiently Protected Credentials
|
CVE-2026-54276
|
2026-06-24 02:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2027
|
- |
|
-
|
-
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, a vulnerabilit…
|
CWE-524
Use of Cache Containing Sensitive Information
|
CVE-2026-50170
|
2026-06-24 02:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2028
|
6.9 |
MEDIUM
Local
|
libexpat_project
|
libexpat
|
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-56406
|
2026-06-24 01:29 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2029
|
6.9 |
MEDIUM
Local
|
libexpat_project
|
libexpat
|
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-56407
|
2026-06-24 01:28 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2030
|
6.9 |
MEDIUM
Local
|
libexpat_project
|
libexpat
|
libexpat before 2.8.2 has an integer overflow in copyString.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-56408
|
2026-06-24 01:27 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|