#VU127955 - Allocation of Resources Without Limits or Throttling CVE-2026-22815 |
CWE-770 |
Medium |
No
|
No
|
3.6.0-150100.3.35.1, 3.9.3-150400.10.43.1 |
26.04.2026 |
SB2026042605
SB2026050302
SB2026050303
and 6 more
|
#VU127953 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2026-34514 |
CWE-93 |
Medium |
No
|
No
|
3.6.0-150100.3.35.1, 3.9.3-150400.10.43.1 |
26.04.2026 |
SB2026042605
SB2026050302
SB2026050303
and 7 more
|
#VU120998 - Resource exhaustion CVE-2025-69229 |
CWE-400 |
Medium |
No
|
No
|
3.6.0-150100.3.32.1, 3.9.3-150400.10.36.1 |
06.01.2026 |
SB2026010643
SB2026012919
SB20260216150
and 10 more
|
#VU120996 - Resource exhaustion CVE-2025-69228 |
CWE-400 |
Medium |
No
|
No
|
3.6.0-150100.3.32.1, 3.9.3-150400.10.36.1 |
06.01.2026 |
SB2026010643
SB2026012920
SB20260216150
and 9 more
|
#VU120995 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2025-69227 |
CWE-835 |
Medium |
No
|
No
|
3.6.0-150100.3.32.1, 3.9.3-150400.10.36.1 |
06.01.2026 |
SB2026010643
SB2026012920
SB20260216150
and 9 more
|
#VU120994 - Exposure of sensitive information to an unauthorized actor CVE-2025-69226 |
CWE-200 |
Low |
No
|
No
|
3.6.0-150100.3.32.1, 3.9.3-150400.10.36.1 |
06.01.2026 |
SB2026010643
SB20260216150
SB2026030633
and 8 more
|
#VU120993 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-69225 |
CWE-444 |
Low |
No
|
No
|
3.6.0-150100.3.32.1, 3.9.3-150400.10.36.1 |
06.01.2026 |
SB2026010643
SB2026012920
SB20260216150
and 9 more
|
#VU120992 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-69224 |
CWE-444 |
Low |
No
|
No
|
3.6.0-150100.3.32.1, 3.9.3-150400.10.36.1 |
06.01.2026 |
SB2026010643
SB20260216150
SB2026030633
and 8 more
|
#VU120990 - Improper Handling of Highly Compressed Data (Data Amplification) CVE-2025-69223 |
CWE-409 |
Medium |
No
|
No
|
3.6.0-150100.3.32.1, 3.9.3-150400.10.36.1 |
06.01.2026 |
SB2026010643
SB2026012661
SB2026012855
and 15 more
|
#VU113069 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-53643 |
CWE-444 |
Medium |
No
|
No
|
3.6.0-150100.3.27.1, 3.9.3-150400.10.33.1 |
18.07.2025 |
SB2025071857
SB2025090377
SB2025091303
and 15 more
|
#VU100600 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2024-52304 |
CWE-444 |
Medium |
No
|
No
|
3.6.0-150100.3.18.1, 3.9.3-150400.10.27.1 |
19.11.2024 |
SB2024111901
SB2024111916
SB2024111917
and 19 more
|
#VU89159 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2024-30251 |
CWE-835 |
Medium |
No
|
No
|
3.6.0-150100.3.21.1, 3.9.3-150400.10.30.1 |
06.05.2024 |
SB2024050618
SB2024061929
SB2024072506
and 12 more
|
#VU88804 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-27306 |
CWE-79 |
Medium |
No
|
No
|
3.6.0-150100.3.24.1 |
18.04.2024 |
SB2024041813
SB2024042444
SB2024042445
and 12 more
|
#VU85886 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-23334 |
CWE-22 |
High |
Available
|
Exploited
|
3.9.3-150400.10.14.1 |
30.01.2024 |
SB2024013007
SB2024013089
SB2024013101
and 18 more
|
#VU85884 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2024-23829 |
CWE-444 |
Medium |
No
|
No
|
3.9.3-150400.10.14.1 |
30.01.2024 |
SB2024013007
SB2024013089
SB2024013101
and 14 more
|
#VU83633 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-49082 |
CWE-444 |
Medium |
No
|
No
|
3.8.6-150400.10.11.1, 3.9.3-150400.10.14.1 |
04.12.2023 |
SB2023120404
SB2023120408
SB2023121355
and 16 more
|
#VU83632 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-49081 |
CWE-444 |
Medium |
No
|
No
|
3.6.0-150100.3.15.1, 3.8.5-150400.10.8.1, 3.9.3-150400.10.14.1 |
04.12.2023 |
SB2023120404
SB2023120408
SB2023121355
and 15 more
|
#VU83631 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-47627 |
CWE-444 |
Medium |
No
|
No
|
3.9.3-150400.10.14.1 |
04.12.2023 |
SB2023120403
SB2023120406
SB2023120407
and 15 more
|
#VU74188 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2023-28859 |
CWE-362 |
Medium |
No
|
No
|
3.9.3-150400.10.18.4 |
30.03.2023 |
SB2023033021
SB2023062140
SB2024013032
and 3 more
|
#VU74187 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2023-28858 |
CWE-362 |
Medium |
No
|
No
|
3.9.3-150400.10.18.4 |
30.03.2023 |
SB2023033020
SB2023042718
SB2023062140
and 3 more
|