Vulnerabilities
Vulnerable Software
Security Vulnerabilities
CVE-2026-93952
Known exploited
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
CVSS Score
9.5
EPSS Score
0.007
Published
2026-09-22
A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-09-21
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
CVSS Score
7.5
EPSS Score
0.004
Published
2026-09-19
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.
CVSS Score
4.0
EPSS Score
0.003
Published
2026-09-19
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
CVSS Score
7.0
EPSS Score
0.003
Published
2026-09-19
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
CVSS Score
3.7
EPSS Score
0.004
Published
2026-09-19
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
CVSS Score
8.1
EPSS Score
0.003
Published
2026-09-18
IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.
CVSS Score
3.7
EPSS Score
0.002
Published
2026-09-18
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
CVSS Score
9.2
EPSS Score
0.006
Published
2026-09-18
A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information.
CVSS Score
7.1
EPSS Score
0.002
Published
2026-09-18


Contact Us

Shodan ® - All rights reserved