<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OpenSSL (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/openssl.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/openssl-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OpenSSL (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2022-49036 – An inclusion of functionality from untrusted control sphere vulnerability in Ope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49036</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49036</strong></p>
  <p>An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4991 – Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4991</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4991</strong></p>
  <p>Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate path may be able to achieve arbitrary code execution with SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52945 – Uncontrolled search path element vulnerability in OpenSSL DLL component in Synol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52945</guid>
    <pubDate>Wed, 27 May 2026 09:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52945</strong></p>
  <p>Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48697 – FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48697</guid>
    <pubDate>Tue, 26 May 2026 17:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48697</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl::context with tls_client mode and calls set_default_verify_paths() to load CA certificates, but never calls set_verify_mode(boost::asio::ssl::verify_peer). Without this call, OpenSSL performs the TLS…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32253 – Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32253</guid>
    <pubDate>Fri, 22 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32253</strong></p>
  <p>Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY, X509_V_ERR_CERT_NOT_YET_VALID, and X509_V_ERR_CERT_HAS_EXPIRED as success. This can allow an…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8721 – Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8721</guid>
    <pubDate>Sun, 17 May 2026 19:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8721</strong></p>
  <p>Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs.  Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen.  The Perl length is discarded.  The C code (or OpenSSL internally) calls strlen() on the buffer.  Any password byte at or after the first NULL is silently dropped. Binary / KDF-derived / HMA…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-170</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8507 – Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8507</guid>
    <pubDate>Sun, 17 May 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8507</strong></p>
  <p>Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws.  When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution potential (RCE) due to a signed integer overflow in the size calculation passed to Renew().</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44699 – LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44699</guid>
    <pubDate>Fri, 15 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44699</strong></p>
  <p>LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key for an HS256/HS384/HS512 token. In the OpenSSL backend, this causes HMAC verification to run with a zero-length key, so an attacker can forge a valid JWT without knowing any secret or RSA private key. This is an algorithm-confusion authentication bypa…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7373 – Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7373</guid>
    <pubDate>Fri, 15 May 2026 03:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7373</strong></p>
  <p>Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When started the metasploitPostgreSQL service would start the postgres.exe child process which would in turn load an OpenSSL configuration file from a static location. This static location would be writable by a pre-existing "vagrant" user, if they already…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42327 – rust-openssl provides OpenSSL bindings for the Rust programming language. From 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42327</guid>
    <pubDate>Thu, 14 May 2026 21:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42327</strong></p>
  <p>rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unchecked. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OC…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62628 – Unsafe OpenSSL initialization within some AMD optional tools may allow a local u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62628</guid>
    <pubDate>Thu, 14 May 2026 15:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62628</strong></p>
  <p>Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a malicious DLL, potentially resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37554 – An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37554</guid>
    <pubDate>Fri, 01 May 2026 16:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37554</strong></p>
  <p>An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attackers to cause a denial of service. The vulnerability exists in the GeoNetworking packet processing pipeline where OpenSSL exceptions from ECC point validation (invalid compressed point, point not on curve) are not properly caught by the Router::indicate() call chain. The openssl_wrapper.cpp check() function (line 19)…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41898 – rust-openssl provides OpenSSL bindings for the Rust programming language.  From ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41898</guid>
    <pubDate>Fri, 24 Apr 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41898</strong></p>
  <p>rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41681 – rust-openssl provides OpenSSL bindings for the Rust programming language.  From ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41681</guid>
    <pubDate>Fri, 24 Apr 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41681</strong></p>
  <p>rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the stack. This is reachable from safe Rust. This vulnerability is fixed in 0.10.78.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41678 – rust-openssl provides OpenSSL bindings for the Rust programming language.  From ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41678</guid>
    <pubDate>Fri, 24 Apr 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41678</strong></p>
  <p>rust-openssl provides OpenSSL bindings for the Rust programming language.  From  to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or belo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41677 – rust-openssl provides OpenSSL bindings for the Rust programming language.  From ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41677</guid>
    <pubDate>Fri, 24 Apr 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41677</strong></p>
  <p>rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed i…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41676 – rust-openssl provides OpenSSL bindings for the Rust programming language.  From ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41676</guid>
    <pubDate>Fri, 24 Apr 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41676</strong></p>
  <p>rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, X448, DH and HKDF-extract ignore the incoming *keylen, unconditionally writing the full shared secret (32/56/prime-siz…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6482 – The Rapid7 Insight Agent (versions &gt; 4.1.0.2) is vulnerable to a local privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6482</guid>
    <pubDate>Fri, 17 Apr 2026 06:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6482</strong></p>
  <p>The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup the agent service attempts to load an OpenSSL configuration file from a non-existent directory that is writable by standard users. By planting a crafted openssl.cnf file an attacker can trick the high-privilege service in…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4158 – KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4158</guid>
    <pubDate>Sat, 11 Apr 2026 01:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4158</strong></p>
  <p>KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of KeePassXC. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the configuration of…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5501 – wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5501</guid>
    <pubDate>Fri, 10 Apr 2026 04:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5501</strong></p>
  <p>wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately signed by a trusted root. An attacker who obtains any leaf certificate from a trusted CA (e.g. a free DV cert from Let's Encrypt) can forge a certificate for a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31789 – Issue summary: Converting an excessively large OCTET STRING value to
a hexadecim...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31789</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31789</strong></p>
  <p>Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions suc…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28390 – Issue summary: During processing of a crafted CMS EnvelopedData message
with Key...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28390</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28390</strong></p>
  <p>Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP enc…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28389 – Issue summary: During processing of a crafted CMS EnvelopedData message
with Key...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28389</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28389</strong></p>
  <p>Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optiona…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28388 – Issue summary: When a delta CRL that contains a Delta CRL Indicator extension
is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28388</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28388</strong></p>
  <p>Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28386 – Issue summary: Applications using AES-CFB128 encryption or decryption on
systems...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28386</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28386</strong></p>
  <p>Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmappe…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34054 – vcpkg is a free and open-source C/C++ package manager. Prior to version 3.6.1#3,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34054</guid>
    <pubDate>Tue, 31 Mar 2026 03:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34054</strong></p>
  <p>vcpkg is a free and open-source C/C++ package manager. Prior to version 3.6.1#3, vcpkg's Windows builds of OpenSSL set openssldir to a path on the build machine, making that path be attackable later on customer machines. This issue has been patched in version 3.6.1#3.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33895 – Forge (also called `node-forge`) is a native implementation of Transport Layer S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33895</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33895</strong></p>
  <p>Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signature and its `S + L` variant both verify in forge, while Node.js `crypto.verify` (OpenSSL-backed) rejects the `S + L` v…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27459 – pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27459</guid>
    <pubDate>Wed, 18 Mar 2026 00:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27459</strong></p>
  <p>pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24695 – An OS command injection 




vulnerability exists in XWEB Pro version 1.12.1 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24695</guid>
    <pubDate>Fri, 27 Feb 2026 01:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24695</strong></p>
  <p>An OS command injection      vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an  authenticated attacker to achieve remote code execution on the system by  injecting malicious input into OpenSSL argument fields within requests  sent to the utility route, leading to remote code execution.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1357 – The Migration, Backup, Staging – WPvivid Backup &amp; Migration plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1357</guid>
    <pubDate>Wed, 11 Feb 2026 06:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1357</strong></p>
  <p>The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writing uploaded files. When the plugin fails to decrypt a session key using openssl_private_decrypt(), it…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25892 – Adminer is open-source database management software. Adminer v5.4.1 and earlier ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25892</guid>
    <pubDate>Mon, 09 Feb 2026 22:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25892</strong></p>
  <p>Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version. This endpoint lacks origin validation and accepts POST data from any source. An attacker can POST version[] parameter which PHP converts to an array. On next page load,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69421 – Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer
de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69421</guid>
    <pubDate>Tue, 27 Jan 2026 16:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69421</strong></p>
  <p>Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.  Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files.  The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69420 – Issue summary: A type confusion vulnerability exists in the TimeStamp Response
v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69420</guid>
    <pubDate>Tue, 27 Jan 2026 16:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69420</strong></p>
  <p>Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.  Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dere…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69419 – Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously
craft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69419</guid>
    <pubDate>Tue, 27 Jan 2026 16:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69419</strong></p>
  <p>Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.  Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service.  The OPENSSL_uni2utf8() funct…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15467 – Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with
malic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15467</guid>
    <pubDate>Tue, 27 Jan 2026 16:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15467</strong></p>
  <p>Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.  Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.  When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encod…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59464 – A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` ce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59464</guid>
    <pubDate>Tue, 20 Jan 2026 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59464</strong></p>
  <p>A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing remote clients to trigger steady memory growth through repeated TLS connections. Over time this can lead to resource exhaustion and denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69217 – coturn is a free open source implementation of TURN and STUN Server. Versions 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69217</guid>
    <pubDate>Tue, 30 Dec 2025 01:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69217</strong></p>
  <p>coturn is a free open source implementation of TURN and STUN Server. Versions 4.6.2r5 through 4.7.0-r4 have a bad random number generator for nonces and port randomization after refactoring. Additionally, random numbers aren't generated with openssl's RAND_bytes but libc's random() (if it's not running on Windows). When fetching about 50 sequential nonces (i.e., through sending 50 unauthenticated…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14406 – Soda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation Vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14406</guid>
    <pubDate>Tue, 23 Dec 2025 22:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14406</strong></p>
  <p>Soda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Soda PDF Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the configuration of OpenSSL…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67900 – NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environmen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67900</guid>
    <pubDate>Sun, 14 Dec 2025 23:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67900</strong></p>
  <p>NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53841 – The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53841</guid>
    <pubDate>Wed, 03 Dec 2025 15:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53841</strong></p>
  <p>The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a non-existent location that standard Windows users have default write access to. This allows an unprivileged local user to crea…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65495 – Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65495</guid>
    <pubDate>Mon, 24 Nov 2025 14:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65495</strong></p>
  <p>Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate that causes i2d_X509() to return -1 and be misused as a malloc() size parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-195</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65494 – NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in O...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65494</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65494</guid>
    <pubDate>Mon, 24 Nov 2025 14:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65494</strong></p>
  <p>NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted X.509 certificate that causes sk_GENERAL_NAME_value() to return NULL.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65494">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65493 – NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65493</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65493</guid>
    <pubDate>Mon, 24 Nov 2025 14:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65493</strong></p>
  <p>NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS/TLS connection that triggers BIO_get_data() to return NULL.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65493">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27237 – In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27237</guid>
    <pubDate>Fri, 03 Oct 2025 12:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27237</strong></p>
  <p>In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9230 – Issue summary: An application trying to decrypt CMS messages encrypted using
pas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9230</guid>
    <pubDate>Tue, 30 Sep 2025 14:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9230</strong></p>
  <p>Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34203 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34203</guid>
    <pubDate>Fri, 19 Sep 2025 19:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34203</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1002 and Application versions prior to 20.0.2614 (VA and SaaS deployments) contain multiple Docker containers that include outdated, end-of-life, unsupported, or otherwise vulnerable third-party components (examples: Nginx 1.17.x, OpenSSL 1.1.1d, various EOL Alpine/Debian/Ubuntu base images, and EOL Laravel/PHP lib…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34192 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34192</guid>
    <pubDate>Fri, 19 Sep 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34192</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.893 and Application versions prior to 20.0.2140 (macOS/Linux client deployments) are built against OpenSSL 1.0.2h-fips (released May 2016), which has been end-of-life since 2019 and is no longer supported by the OpenSSL project. Continued use of this outdated cryptographic library exposes deployments to known vulne…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1104</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55118 – Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55118</guid>
    <pubDate>Tue, 16 Sep 2025 13:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55118</strong></p>
  <p>Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured.   The issue occurs in the following cases:    *  Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "use_openssl=n";   *  Control-M/Agent 9.0.21 and 9.0.22: Agent router configuration uses the non-default settings "JAVA_AR=N" and "use_openssl=n"</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10225 – Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10225</guid>
    <pubDate>Wed, 10 Sep 2025 13:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10225</strong></p>
  <p>Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cause application crashes or unpredictable behavior via triggering memory reallocation errors when handling expired session keys.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8614 – NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8614</guid>
    <pubDate>Tue, 02 Sep 2025 20:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8614</strong></p>
  <p>NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine.  An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the configuration of OpenSSL. The product…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-45765 – ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Suppl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45765</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45765</guid>
    <pubDate>Thu, 07 Aug 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-45765</strong></p>
  <p>ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforced by this library. Currently more recent versions of OpenSSL are enforcing some key sizes and those restrictions apply to the users of this gem also."</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45765">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8069 – During the AWS Client VPN client installation on Windows devices, the install pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8069</guid>
    <pubDate>Wed, 23 Jul 2025 16:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8069</strong></p>
  <p>During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\windows-x86_64-openssl-localbuild\ssl directory location to fetch the OpenSSL configuration file. As a result, a non-admin user could place arbitrary code in the configuration file. If an admin user starts the AWS Client VPN client installation process, that code could be executed wit…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-7394 – In the OpenSSL compatibility layer implementation, the function RAND_poll() was ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7394</guid>
    <pubDate>Fri, 18 Jul 2025 23:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-7394</strong></p>
  <p>In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both using RAND_bytes() and doing fork() operations. This only affects applications explicitly calling R…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5987 – A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5987</guid>
    <pubDate>Mon, 07 Jul 2025 15:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5987</strong></p>
  <p>A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. T…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5480 – Action1 Uncontrolled Search Path Element Local Privilege Escalation Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5480</guid>
    <pubDate>Fri, 06 Jun 2025 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5480</strong></p>
  <p>Action1 Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Action1.  An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the configuration of OpenSSL. The product loa…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-48057 – Icinga 2 is a monitoring system which checks the availability of network resourc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48057</guid>
    <pubDate>Tue, 27 May 2025 17:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-48057</strong></p>
  <p>Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious certificate request that is then treated as a renewal…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-296</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47276 – Actualizer is a single shell script solution to allow developers and embedded en...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47276</guid>
    <pubDate>Tue, 13 May 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47276</strong></p>
  <p>Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating systems (OS). Prior to version 1.2.0, Actualizer uses OpenSSL's  "-passwd" function, which uses SHA512 instead of a more suitable password hasher like Yescript/Argon2i. All Actualizer users building a full Debian Operating System are affected. Users should upgrade to version 1.2.0 of…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-328</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-35471 – conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-35471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-35471</guid>
    <pubDate>Tue, 13 May 2025 02:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-35471</strong></p>
  <p>conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privileged local user can execute arbitrary code with the privileges of the user or process loading openssl-feedstock DLLs. Miniforge before 24.5.…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-35471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2769 – Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2769</guid>
    <pubDate>Wed, 23 Apr 2025 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2769</strong></p>
  <p>Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the configuration of OpenSSL.…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2768 – Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2768</guid>
    <pubDate>Wed, 23 Apr 2025 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2768</strong></p>
  <p>Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the configuration of OpenSSL.…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-2263 – During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2263</guid>
    <pubDate>Thu, 13 Mar 2025 17:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-2263</strong></p>
  <p>During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_DecryptUpdate is called to decrypt the username and password. A fixed 0x80-byte stack-based buffer is passed to the function as the output buffer. A stack-based buffer overflow exists if a long encrypted username or password is supplied by an unauthenticated remote attacker.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2658 – A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2658</guid>
    <pubDate>Thu, 30 Jan 2025 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2658</strong></p>
  <p>A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24012 – An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24012</guid>
    <pubDate>Thu, 09 Jan 2025 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24012</strong></p>
  <p>An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24011 – An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24011</guid>
    <pubDate>Thu, 09 Jan 2025 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24011</strong></p>
  <p>An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24010 – An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24010</guid>
    <pubDate>Thu, 09 Jan 2025 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24010</strong></p>
  <p>An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4741 – Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause
memor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4741</guid>
    <pubDate>Wed, 13 Nov 2024 11:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4741</strong></p>
  <p>Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, only applications that directly call the SSL_free_buffers function are affected by this issue…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41594 – An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41594</guid>
    <pubDate>Thu, 03 Oct 2024 19:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41594</strong></p>
  <p>An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-49038 – Inclusion of functionality from untrusted control sphere vulnerability in OpenSS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49038</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49038</guid>
    <pubDate>Thu, 26 Sep 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49038</strong></p>
  <p>Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client before 3.3.0-15082 allows local users to execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49038">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46809 – Node.js versions which bundle an unpatched version of OpenSSL or run against a d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46809</guid>
    <pubDate>Sat, 07 Sep 2024 16:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46809</strong></p>
  <p>Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-385</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45238 – An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45238</guid>
    <pubDate>Sat, 24 Aug 2024 23:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45238</strong></p>
  <p>An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a Subject Public Key. OpenSSL does not report this problem during parsing, and when compiled with OpenSSL libcrypto versions below 3, Fort recklessly dereferences the poi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-6975 – Cato Networks Windows SDP Client Local Privilege Escalation via openssl configur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6975</guid>
    <pubDate>Wed, 31 Jul 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-6975</strong></p>
  <p>Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-5535 – Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an
em...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5535</guid>
    <pubDate>Thu, 27 Jun 2024 11:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-5535</strong></p>
  <p>Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent to the peer.  Impact summary: A buffer overread can have a range of potential consequences such as unexpected application beahviour or a crash. In particular this issue could result in up to 255 bytes of arbitrary private data from m…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37305 – oqs-provider is a provider for the OpenSSL 3 cryptography library that adds supp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37305</guid>
    <pubDate>Mon, 17 Jun 2024 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37305</strong></p>
  <p>oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from liboqs. Flaws have been identified in the way oqs-provider handles lengths decoded with DECODE_UINT32 at the start of serialized hybrid (traditional + post-quantum) keys and signatures. Unchecked length values are later used…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4611 – The AppPresser plugin for WordPress is vulnerable to improper missing encryption...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4611</guid>
    <pubDate>Wed, 29 May 2024 05:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4611</strong></p>
  <p>The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they previously used the login via the plugin API. This can only be e…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-703</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27362 – 3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27362</guid>
    <pubDate>Fri, 03 May 2024 02:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27362</strong></p>
  <p>3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of 3CX. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL con…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-3729 – The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3729</guid>
    <pubDate>Thu, 02 May 2024 17:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-3729</strong></p>
  <p>The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling  on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible for unauthenticated attackers to manipulate the user processing forms, which can be used to add and edit administrator user for privilege escalation, or to automatically log in user…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-636</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0394 – Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0394</guid>
    <pubDate>Wed, 03 Apr 2024 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0394</strong></p>
  <p>Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated attacker can elevate privileges and execute arbitrary code with SYSTEM privilege.  The vulnerability is caused by the product's implementation of OpenSSL's`OPENSSLDIR` parameter where it is set to a path accessible to low-privileged users.  The vulnerability has been remediated and…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1394 – A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1394</guid>
    <pubDate>Thu, 21 Mar 2024 13:00:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1394</strong></p>
  <p>A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51787 – An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks ta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51787</guid>
    <pubDate>Thu, 15 Feb 2024 06:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51787</strong></p>
  <p>An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task memory is not freed, resulting in a memory leak.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-4123 – The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4123</guid>
    <pubDate>Tue, 12 Dec 2023 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-4123</strong></p>
  <p>The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-49210 – The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49210</guid>
    <pubDate>Thu, 23 Nov 2023 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-49210</strong></p>
  <p>The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41840 – A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41840</guid>
    <pubDate>Tue, 14 Nov 2023 18:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41840</strong></p>
  <p>A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46724 – Squid is a caching proxy for the Web. Due to an Improper Validation of Specified...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46724</guid>
    <pubDate>Wed, 01 Nov 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46724</strong></p>
  <p>Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafte…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5363 – Issue summary: A bug has been identified in the processing of key and
initialisa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5363</guid>
    <pubDate>Wed, 25 Oct 2023 18:17:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5363</strong></p>
  <p>Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths.  This can lead to potential truncation or overruns during the initialisation of some symmetric ciphers.  Impact summary: A truncation in the IV can result in non-uniqueness, which could result in loss of confidentiality for some cipher modes.  When calling EVP_EncryptInit_ex2(), EVP_DecryptIn…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-684</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5422 – The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMT...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5422</guid>
    <pubDate>Mon, 16 Oct 2023 09:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5422</strong></p>
  <p>The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the  SSL_get_verify_result() function is not used the certificated is trusted always and it can not be ensured that the certificate  satisfies all necessary security requirements.  This could allow an  attacker to use an invalid certificate to claim to be a t…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4807 – Issue summary: The POLY1305 MAC (message authentication code) implementation
con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4807</guid>
    <pubDate>Fri, 08 Sep 2023 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4807</strong></p>
  <p>Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on the Windows 64 platform when running on newer X86_64 processors supporting the AVX512-IFMA instructions.  Impact summary: If in an application that uses the OpenSSL library an attacker can influence whether the POLY1305 MAC algorithm is used, the app…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-440</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28133 – Local privilege escalation in Check Point Endpoint Security Client (version E87...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28133</guid>
    <pubDate>Sun, 23 Jul 2023 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28133</strong></p>
  <p>Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30586 – A privilege escalation vulnerability exists in Node.js 20 that allowed loading a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30586</guid>
    <pubDate>Sat, 01 Jul 2023 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30586</strong></p>
  <p>A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission model is enabled, which can bypass and/or disable the permission model. The attack complexity is high. However, the crypto.setEngine() API can be used to bypass the permission model when called with a compatible OpenSSL engine. The OpenSSL engine can, for examp…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-35784 – A double free or use after free could occur after SSL_clear in OpenBSD 7.2 befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35784</guid>
    <pubDate>Fri, 16 Jun 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-35784</strong></p>
  <p>A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43507 – Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43507</guid>
    <pubDate>Wed, 10 May 2023 14:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43507</strong></p>
  <p>Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-92</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0464 – A security vulnerability has been identified in all supported versions

of OpenS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0464</guid>
    <pubDate>Wed, 22 Mar 2023 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0464</strong></p>
  <p>A security vulnerability has been identified in all supported versions  of OpenSSL related to the verification of X.509 certificate chains that include policy constraints.  Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems.  Policy p…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26490 – mailcow is a dockerized email package, with multiple containers linked in one br...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26490</guid>
    <pubDate>Sat, 04 Mar 2023 00:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26490</strong></p>
  <p>mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - which can be made available to standard users by assigning them the necessary permission - suffers from a shell command injection. A malicious user can abuse this vulnerability to obtain shell access to the Docker container running dovecot. The imapsync Perl script implements all…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-23919 – A cryptographic vulnerability exists in Node.js &lt;19.2.0, &lt;18.14.1, &lt;16.19.1, &lt;14...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23919</guid>
    <pubDate>Thu, 23 Feb 2023 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-23919</strong></p>
  <p>A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent cryptographic operations that happen to be on the same thread. This in turn could be used to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0401 – A NULL pointer can be dereferenced when signatures are being
verified on PKCS7 s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0401</guid>
    <pubDate>Wed, 08 Feb 2023 20:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0401</strong></p>
  <p>A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest initialization will fail. There is a missing check for the return value from the initialization function which later leads to inva…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0286 – There is a type confusion vulnerability relating to X.400 address processing
ins...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0286</guid>
    <pubDate>Wed, 08 Feb 2023 20:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0286</strong></p>
  <p>There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING.…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0217 – An invalid pointer dereference on read can be triggered when an
application trie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0217</guid>
    <pubDate>Wed, 08 Feb 2023 20:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0217</strong></p>
  <p>An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. This function can be called on public keys supplied from untrusted sources which could allow an attacker to cause a denial of service attack.  The TLS implementation in OpenSSL does not ca…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0216 – An invalid pointer dereference on read can be triggered when an
application trie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0216</guid>
    <pubDate>Wed, 08 Feb 2023 20:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0216</strong></p>
  <p>An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions.  The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does not call this function however third party applications might call these functi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0215 – The public API function BIO_new_NDEF is a helper function used for streaming
ASN...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0215</guid>
    <pubDate>Wed, 08 Feb 2023 20:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0215</strong></p>
  <p>The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications.  The function receives a BIO from the caller, prepends a new BIO_f_asn1 filter BIO onto the front of it to form a BIO chain, and then retur…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4450 – The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and
decode...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4450</guid>
    <pubDate>Wed, 08 Feb 2023 20:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4450</strong></p>
  <p>The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing the relevant decoded data. The caller is responsible for freeing those buffers. It is possible to construct a PEM file t…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41141 – This vulnerability allows local attackers to escalate privileges on affected ins...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41141</guid>
    <pubDate>Thu, 26 Jan 2023 18:59:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41141</strong></p>
  <p>This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL configuration file from an unsecured location. An attacker can lever…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41141">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
