29 entries matching curl — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-67598 | Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that all | CRITICAL | 9.1 | 6%ile | NVD | 2026-08-03 |
| CVE-2026-69246 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and | HIGH | 7.2 | 12%ile | NVD | 2026-08-03 |
| CVE-2026-69245 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of | MEDIUM | 6.5 | 4%ile | NVD | 2026-08-03 |
| CVE-2026-67339 | guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cUR | MEDIUM | 6.9 | 14%ile | NVD | 2026-08-01 |
| CVE-2026-53608 | @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag | HIGH | 8.7 | 11%ile | GitHub | 2026-07-31 |
| CVE-2026-57862 | Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass | HIGH | 8.4 | 22%ile | NVD | 2026-07-30 |
| CVE-2026-9547 | SSH improper host validation | CRITICAL | 9.1 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-8924 | trailing dot domain super cookie | CRITICAL | 9.1 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-8926 | password leak with netrc and user in URL | CRITICAL | 9.1 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-8286 | wrong STARTTLS connection reuse | HIGH | 8.1 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-9545 | exposing HTTP/3 early data | HIGH | 7.5 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-8932 | incomplete mTLS config matching in conn reuse | HIGH | 7.5 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-12064 | proto-default skips SSH verification | HIGH | 7.5 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-8458 | wrong reuse for different services | MEDIUM | 6.5 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-10536 | HTTP/2 stream-dependency tree UAF | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-11856 | cross-origin Digest auth state leak | MEDIUM | 5.3 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-8927 | env-set cross-proxy Digest auth state leak | MEDIUM | 5.3 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-9079 | stale proxy password leak | UNKNOWN | — | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-5773 | wrong reuse of SMB connection | HIGH | 7.5 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-6276 | stale custom cookie host causes cookie leak | HIGH | 7.5 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-5545 | wrong reuse of HTTP Negotiate connection | MEDIUM | 6.5 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-4873 | connection reuse ignores TLS requirement | MEDIUM | 5.9 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-6253 | proxy credentials leak over redirect-to proxy | MEDIUM | 5.9 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-6429 | netrc credential leak with reused proxy connection | MEDIUM | 5.3 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-7168 | cross-proxy Digest auth state leak | MEDIUM | 5.3 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2025-10148 | predictable WebSocket mask | MEDIUM | 6.5 | 38%ile | Microsoft | 2025-09-09 |
| CVE-2025-9086 | Out of bounds read for cookie path | MEDIUM | 4.3 | 68%ile | Microsoft | 2025-09-09 |
| CVE-2025-4947 | QUIC certificate check skip with wolfSSL | MEDIUM | 6.5 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2025-5025 | No QUIC certificate pinning with wolfSSL | MEDIUM | 4.8 | 17%ile | Microsoft | 2025-05-13 |