Known vulnerabilities in cURL 8.6.0 - page 2

Software: cURL
Version: 8.6.0
Software CPE: cpe:2.3:a:curl_haxx_se:curl:*:*:*:*:*:*:*:*
Total vulnerabilities: 39
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting cURL version 8.6.0 cURL 8.6.0 is affected by 39 vulnerabilities: 1 high, 20 medium, 18 low Critical High Medium Low

Vulnerabilities (39)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121030 - Improper Authentication
CVE-2025-15224
CWE-287 Low
No
No
8.18.0 07.01.2026 SB2026010741
SB2026010781
SB2026010782
and 14 more
#VU121029 - Improper Validation of Certificate with Host Mismatch
CVE-2025-15079
CWE-297 Low
No
No
8.18.0 07.01.2026 SB2026010741
SB2026010781
SB2026010782
and 15 more
#VU121027 - Improper Certificate Validation
CVE-2025-14819
CWE-295 Low
No
No
8.18.0 07.01.2026 SB2026010741
SB2026010781
SB2026010782
and 13 more
#VU121026 - Insufficiently Protected Credentials
CVE-2025-14524
CWE-522 Low
No
No
8.18.0 07.01.2026 SB2026010741
SB2026010781
SB2026010782
and 23 more
#VU118098 - Key Exchange without Entity Authentication
CVE-2025-10966
CWE-322 Low
No
No
8.17.0 05.11.2025 SB2025110509
SB2026012829
SB2026020656
#VU115138 - Out-of-bounds read
CVE-2025-9086
CWE-125 Low
No
No
8.16.0 10.09.2025 SB2025091034
SB2025091144
SB2025091301
and 44 more
#VU115137 - Use of Insufficiently Random Values
CVE-2025-10148
CWE-330 Low
No
No
8.16.0 10.09.2025 SB2025091034
SB2025091144
SB2025091301
and 10 more
#VU109885 - Improper Certificate Validation
CVE-2025-5025
CWE-295 Medium
No
No
8.14.0 28.05.2025 SB2025052805
SB2025060505
SB2025072409
and 4 more
#VU103648 - Exposure of sensitive information to an unauthorized actor
CVE-2025-0167
CWE-200 Low
No
No
8.12.0 05.02.2025 SB2025020531
SB2025020601
SB2025020658
and 20 more
#VU103646 - Integer overflow
CVE-2025-0725
CWE-190 High
No
No
8.12.0 05.02.2025 SB2025020531
SB2025020601
SB2025020658
and 25 more
#VU101654 - Exposure of sensitive information to an unauthorized actor
CVE-2024-11053
CWE-200 Low
No
No
8.11.1 11.12.2024 SB2024121137
SB2024121189
SB2024121190
and 32 more
#VU99865 - Comparison using wrong factors
CVE-2024-9681
CWE-1025 Low
No
No
8.11.0 06.11.2024 SB2024110621
SB2024110655
SB2024110656
and 30 more
#VU97150 - Improper Certificate Validation
CVE-2024-8096
CWE-295 Low
No
No
8.10.0 11.09.2024 SB2024091127
SB2024091141
SB2024091142
and 11 more
#VU95131 - Out-of-bounds read
CVE-2024-7264
CWE-125 Medium
No
No
8.9.1 01.08.2024 SB2024080110
SB2024080117
SB20240805104
and 43 more
#VU94715 - Double Free
CVE-2024-6197
CWE-415 Medium
No
No
8.9.0 24.07.2024 SB2024072431
SB2024080568
SB20240806402
and 11 more
#VU87852 - Improper Validation of Certificate with Host Mismatch
CVE-2024-2466
CWE-297 Medium
No
No
8.7.0 27.03.2024 SB2024032713
SB2024032748
SB2024061844
and 14 more
#VU87850 - Missing Release of Resource after Effective Lifetime
CVE-2024-2398
CWE-772 Medium
No
No
8.7.0 27.03.2024 SB2024032713
SB2024032740
SB2024032744
and 106 more
#VU87848 - Improper Certificate Validation
CVE-2024-2379
CWE-295 Low
No
No
8.7.0 27.03.2024 SB2024032713
SB2024032748
SB2024061844
and 12 more
#VU87846 - Improper input validation
CVE-2024-2004
CWE-20 Low
No
No
8.7.0 27.03.2024 SB2024032713
SB2024032740
SB2024032748
and 28 more


Showing elements 21 - 40 out of 39