Tag
IBM MQ Improper Validation Vulnerability (CVE-2026-11381)
1 CVEIBM MQ contains a vulnerability in the validation of message distribution list structures that allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.
XML External Entity Injection in IBM MQ Classes for Java
1 TTP 1 CVEAn XML external entity injection vulnerability (CVE-2026-12666) in IBM MQ Classes for Java allows authenticated attackers to perform denial-of-service attacks or disclose sensitive host information by manipulating MQRFH2 headers.
CVE-2026-85440: Heap Overflow in MOOS core-moos
5 TTPs 1 CVEA pre-authentication heap overflow vulnerability in the MOOSCommPkt packet handling of MOOS core-moos versions up to 10.4.0 allows remote unauthenticated attackers to perform arbitrary memory writes via crafted packets.
Buffer Overflow Vulnerabilities in MOOS-IvP
4 TTPs 1 CVEMultiple buffer overflow vulnerabilities in MOOS-IvP versions up to 24.8.1 allow for remote code execution via malformed IvP function strings.
Credential Guessing Vulnerability via WildFly Elytron Unicode Normalization
1 TTP 1 CVEA vulnerability in WildFly Elytron's password normalization logic allows attackers to bypass intended password character entropy, facilitating unauthorized access through dictionary-based credential guessing.
IBM WebSphere Application Server Security Bypass Vulnerability
1 TTPIBM WebSphere Application Server and Liberty are vulnerable to a security bypass flaw that permits remote, unauthenticated attackers to circumvent established security controls.
Next.js Middleware Authorization Bypass via Dynamic Route Parameter Injection (CVE-2026-44574)
2 rules 1 TTPA vulnerability in Next.js (CVE-2026-44574) allows for authorization bypass in applications that use middleware to protect dynamic routes, enabling attackers to render protected content without proper authorization by crafting specific query parameters.
@fastify/middie Middleware Bypass Vulnerability (CVE-2026-33804)
2 rules 1 TTP 1 CVEA middleware bypass vulnerability (CVE-2026-33804) exists in @fastify/middie versions 9.3.1 and earlier when the deprecated Fastify ignoreDuplicateSlashes option is enabled, potentially allowing unauthorized access.
Fastify/Express Middleware Path Doubling Authentication Bypass
2 rules 1 TTPA path handling bug in `@fastify/express` v4.0.4 `onRegister` function causes middleware paths to be doubled when inherited by child plugins, resulting in complete bypass of Express middleware security controls for all routes defined within child plugin scopes that share a prefix with parent-scoped middleware.