Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Vulnerability List - Page 12

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-103604 Quadratic-time escaping when converting X.509 distinguished names to strings Legion of the Bouncy Castle Inc. bc-csharp High 8.7 2026-10-02 07:11:04 Deep Dive
CVE-2026-103603 Unbounded HSS public key level count allows huge array allocation during signature verification Legion of the Bouncy Castle Inc. bc-csharp High 8.7 2026-10-02 07:10:34 Deep Dive
CVE-2026-103602 Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts Legion of the Bouncy Castle Inc. bc-csharp High 8.2 2026-10-02 07:10:04 Deep Dive
CVE-2026-103601 CcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output buffer after a failed tag check Legion of the Bouncy Castle Inc. bc-csharp High 8.2 2026-10-02 07:09:17 Deep Dive
CVE-2026-103600 Unbounded ASN.1 nesting depth causes process-terminating stack overflow Legion of the Bouncy Castle Inc. bc-csharp High 8.7 2026-10-02 07:08:52 Deep Dive
CVE-2026-63578 Unbounded PBE iteration count when decrypting PKCS#8 private keys Legion of the Bouncy Castle Inc. bc-csharp High 7.1 2026-10-02 07:08:16 Deep Dive
CVE-2026-63577 Name Constraints bypass: directoryName constraint matched at any position in the DN instead of as a prefix Legion of the Bouncy Castle Inc. bc-csharp High 8.2 2026-10-02 07:07:35 Deep Dive
CVE-2026-63576 URI name constraints checked against a mis-parsed host Legion of the Bouncy Castle Inc. bc-csharp High 8.2 2026-10-02 07:07:03 Deep Dive
CVE-2026-63575 PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration count Legion of the Bouncy Castle Inc. bc-csharp High 7.1 2026-10-02 07:06:32 Deep Dive
CVE-2026-63574 Unbounded allocation from OpenPGP signature and user attribute subpacket lengths Legion of the Bouncy Castle Inc. bc-csharp High 8.7 2026-10-02 07:06:01 Deep Dive
CVE-2026-63573 Bleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrap Legion of the Bouncy Castle Inc. bc-csharp High 8.2 2026-10-02 07:05:30 Deep Dive
CVE-2026-63572 Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files Legion of the Bouncy Castle Inc. bc-csharp High 7.1 2026-10-02 07:04:38 Deep Dive
CVE-2026-63571 Attribute certificate path validation does not verify the attribute certificate's signature Legion of the Bouncy Castle Inc. bc-csharp High 8.7 2026-10-02 07:04:17 Deep Dive
CVE-2026-63570 Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links Legion of the Bouncy Castle Inc. bc-csharp High 7.1 2026-10-02 07:01:18 Deep Dive
CVE-2026-63569 MTI/A0 DHAgreement does not validate the peer's ephemeral value Legion of the Bouncy Castle Inc. bc-csharp Critical 9.1 2026-10-02 07:00:24 Deep Dive
CVE-2026-63568 Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion Legion of the Bouncy Castle Inc. bc-csharp High 8.7 2026-10-02 06:59:31 Deep Dive
CVE-2026-63567 IesEngine block-cipher mode checks padding before MAC (CBC padding oracle) Legion of the Bouncy Castle Inc. bc-csharp High 8.2 2026-10-02 06:58:32 Deep Dive
CVE-2026-63566 DTLS handshake reassembler allocates buffer from unchecked 24-bit length Legion of the Bouncy Castle Inc. bc-csharp High 8.7 2026-10-02 06:57:22 Deep Dive
CVE-2026-92924 Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data Unknown Unlimited Elements for Elementor Medium 5.4 2026-10-02 06:56:54 Deep Dive
CVE-2026-97219 MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter Unknown MStore API Medium 4.3 2026-10-02 06:56:54 Deep Dive