← Back to feed Search feed

curl vulnerabilities

29 entries matching curl — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-67598Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allCRITICAL9.16%ileNVD2026-08-03
CVE-2026-69246Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text andHIGH7.212%ileNVD2026-08-03
CVE-2026-69245Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of MEDIUM6.54%ileNVD2026-08-03
CVE-2026-67339guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURMEDIUM6.914%ileNVD2026-08-01
CVE-2026-53608@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script TagHIGH8.711%ileGitHub2026-07-31
CVE-2026-57862Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypassHIGH8.422%ileNVD2026-07-30
CVE-2026-9547SSH improper host validationCRITICAL9.125%ileMicrosoft2026-07-14
CVE-2026-8924trailing dot domain super cookieCRITICAL9.143%ileMicrosoft2026-07-14
CVE-2026-8926password leak with netrc and user in URLCRITICAL9.130%ileMicrosoft2026-07-14
CVE-2026-8286wrong STARTTLS connection reuseHIGH8.123%ileMicrosoft2026-07-14
CVE-2026-9545exposing HTTP/3 early dataHIGH7.519%ileMicrosoft2026-07-14
CVE-2026-8932incomplete mTLS config matching in conn reuseHIGH7.532%ileMicrosoft2026-07-14
CVE-2026-12064proto-default skips SSH verificationHIGH7.526%ileMicrosoft2026-07-14
CVE-2026-8458wrong reuse for different servicesMEDIUM6.524%ileMicrosoft2026-07-14
CVE-2026-10536HTTP/2 stream-dependency tree UAFMEDIUM5.540%ileMicrosoft2026-07-14
CVE-2026-11856cross-origin Digest auth state leakMEDIUM5.346%ileMicrosoft2026-07-14
CVE-2026-8927env-set cross-proxy Digest auth state leakMEDIUM5.336%ileMicrosoft2026-07-14
CVE-2026-9079stale proxy password leakUNKNOWN45%ileMicrosoft2026-07-14
CVE-2026-5773wrong reuse of SMB connectionHIGH7.546%ileMicrosoft2026-05-12
CVE-2026-6276stale custom cookie host causes cookie leakHIGH7.522%ileMicrosoft2026-05-12
CVE-2026-5545wrong reuse of HTTP Negotiate connectionMEDIUM6.534%ileMicrosoft2026-05-12
CVE-2026-4873connection reuse ignores TLS requirementMEDIUM5.925%ileMicrosoft2026-05-12
CVE-2026-6253proxy credentials leak over redirect-to proxyMEDIUM5.950%ileMicrosoft2026-05-12
CVE-2026-6429netrc credential leak with reused proxy connectionMEDIUM5.341%ileMicrosoft2026-05-12
CVE-2026-7168cross-proxy Digest auth state leakMEDIUM5.338%ileMicrosoft2026-05-12
CVE-2025-10148predictable WebSocket maskMEDIUM6.538%ileMicrosoft2025-09-09
CVE-2025-9086Out of bounds read for cookie pathMEDIUM4.368%ileMicrosoft2025-09-09
CVE-2025-4947QUIC certificate check skip with wolfSSLMEDIUM6.516%ileMicrosoft2025-05-13
CVE-2025-5025No QUIC certificate pinning with wolfSSLMEDIUM4.817%ileMicrosoft2025-05-13