40 entries matching curl — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-92992 | A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown functio | LOW | 2.1 | 20%ile | NVD | 2026-09-17 |
| CVE-2025-56563 | A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts | CRITICAL | 9.8 | 34%ile | NVD | 2026-09-16 |
| CVE-2026-91992 | Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused acr | HIGH | 8.2 | 11%ile | NVD | 2026-09-15 |
| CVE-2024-58384 | Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return | MEDIUM | 6.3 | 16%ile | NVD | 2026-09-15 |
| CVE-2026-48737 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/p | MEDIUM | 4.9 | 8%ile | NVD | 2026-09-15 |
| CVE-2026-54182 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | HIGH | 8.1 | 38%ile | NVD | 2026-09-14 |
| CVE-2026-90583 | A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected | MEDIUM | 5.3 | 21%ile | NVD | 2026-09-13 |
| CVE-2026-81913 | Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft | MEDIUM | 5.3 | 47%ile | NVD | 2026-09-11 |
| CVE-2026-82209 | domain-scoped PSL domain cookie | HIGH | 8.2 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-82208 | wolfSSL CA-cache hit overrides callback | HIGH | 7.4 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-19931 | Negotiate ambient user conn reuse | MEDIUM | 6.5 | 66%ile | Microsoft | 2026-09-08 |
| CVE-2026-18924 | HTTP/2 server push UAF | MEDIUM | 5.9 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-13608 | OpenLDAP SASL authentication bypass | LOW | 3.7 | 49%ile | Microsoft | 2026-09-08 |
| CVE-2026-80230 | OpenSSL pinning bypass | LOW | 3.7 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-80231 | native CA store conn reuse | LOW | 3.7 | 59%ile | Microsoft | 2026-09-08 |
| OSSN-0073 | OSSN-0073: = Horizon dashboard leaks internal information through cookies = | UNKNOWN | — | — | OpenStack | 2026-08-27 |
| CVE-2026-8924 | trailing dot domain super cookie | CRITICAL | 9.1 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-8286 | wrong STARTTLS connection reuse | HIGH | 8.1 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-8932 | incomplete mTLS config matching in conn reuse | HIGH | 7.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-9545 | exposing HTTP/3 early data | HIGH | 7.5 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-12064 | proto-default skips SSH verification | HIGH | 7.4 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-8458 | wrong reuse for different services | MEDIUM | 6.5 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-8926 | password leak with netrc and user in URL | MEDIUM | 5.9 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-10536 | HTTP/2 stream-dependency tree UAF | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-11856 | cross-origin Digest auth state leak | MEDIUM | 5.3 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-8927 | env-set cross-proxy Digest auth state leak | MEDIUM | 5.3 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-9079 | stale proxy password leak | UNKNOWN | — | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-6276 | stale custom cookie host causes cookie leak | HIGH | 7.5 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-5773 | wrong reuse of SMB connection | HIGH | 7.5 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-5545 | wrong reuse of HTTP Negotiate connection | MEDIUM | 6.5 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-4873 | connection reuse ignores TLS requirement | MEDIUM | 5.9 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-6253 | proxy credentials leak over redirect-to proxy | MEDIUM | 5.9 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-6429 | netrc credential leak with reused proxy connection | MEDIUM | 5.3 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-7168 | cross-proxy Digest auth state leak | MEDIUM | 5.3 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2025-11563 | wcurl path traversal with percent-encoded slashes | MEDIUM | 4.6 | 30%ile | Microsoft | 2026-02-10 |
| CVE-2025-13034 | No QUIC certificate pinning with GnuTLS | MEDIUM | 5.9 | 16%ile | Microsoft | 2026-01-13 |
| CVE-2025-14017 | broken TLS options for threaded LDAPS | MEDIUM | 5.9 | 2%ile | Microsoft | 2026-01-13 |
| CVE-2025-14819 | OpenSSL partial chain store policy bypass | MEDIUM | 5.3 | 53%ile | Microsoft | 2026-01-13 |
| CVE-2025-10148 | predictable WebSocket mask | MEDIUM | 6.5 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-9086 | Out of bounds read for cookie path | MEDIUM | 4.3 | 71%ile | Microsoft | 2025-09-09 |