Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 17 April 2026

RSS

533 vulnerabilities published on 17 April 2026

Severity:
Rootio Python 3.13: Unauthorized Access to Sensitive Data
ROOT-OS-DEBIAN-13-CVE-2025-8194
The Rootio Python 3.13 package had a security issue that allowed an attacker to access sensitive data without permission. This could have let a hacker see or change important information they shouldn'...
Rootio Python Package for Debian 13 Has a Security Fix
ROOT-OS-DEBIAN-13-CVE-2025-6075
The Rootio Python package for Debian 13 has a security patch available to prevent unauthorized access. This is a fix for a previously known issue, and users are advised to update their Rootio Python p...
rootio-python3.13: Malicious code execution via arbitrary file read
ROOT-OS-DEBIAN-13-CVE-2026-3644
A patch has been released for rootio-python3.13 to prevent hackers from accessing sensitive files on your system. This issue affects servers running Root:Debian:13 and has been fixed in new versions o...
rootio-python3.13: Data Exposure Through Sensitive Function Misuse
ROOT-OS-DEBIAN-13-CVE-2025-12084
A security patch has been released for rootio-python3.13 on Root:Debian:13. If left unpatched, an attacker could potentially access sensitive data. Update to the latest version to ensure security.
rootio-python3.13: Unauthenticated Remote Code Execution Possible
ROOT-OS-DEBIAN-13-CVE-2026-0865
A security patch has been released for rootio-python3.13 to prevent unauthorized code from being executed on a remote system. This update is important for users running Root:Debian:13. We recommend up...
Old Versions of pypdf Can Be Hacked to Crash Your Computer
DEBIAN-CVE-2026-40260
Old versions of the pypdf library can be exploited by an attacker to create a PDF that uses up all your computer's memory, potentially causing it to crash. This can happen if someone sends you a malic...
Root.io Axios Data Exposure in Root npm Package
ROOT-APP-NPM-CVE-2026-25639
A security patch has been released for a vulnerability in the Root.io Axios package on Root npm. This issue allows unauthorized access to sensitive data. Update to the latest version to protect your a...
Root's axios Package Exposes Unsecured Data
ROOT-APP-NPM-CVE-2025-58754
A security patch has been released for the axios package, which is used in Root's npm repository. This patch fixes a vulnerability that could allow unauthorized access to sensitive information. If you...
Root's axios Library Allows Remote Code Execution
ROOT-APP-NPM-CVE-2026-40175
The axios library used in some Root applications contains a security flaw that could allow an attacker to run malicious code on your server. This could happen if an attacker injects malicious data int...
Root's Axios Library May Allow Data Exposure
ROOT-APP-NPM-SNYK-JS-AXIOS-9403194
A security patch has been applied to the Root's Axios library, which is used to handle HTTP requests in some applications. This patch addresses a potential issue where sensitive data could be exposed....
axios for Root:npm: Unauthenticated Data Exposure through Request Headers
ROOT-APP-NPM-CVE-2025-62718
The axios package for Root:npm allows an attacker to access sensitive data without needing a valid login. This issue affects users of Root's npm package and has been fixed in a newer version, which sh...
CGA-55qm-vfpv-pfvr
CGA-55qm-vfpv-pfvr
CGA-pqxr-g3q3-977c
CGA-pqxr-g3q3-977c
Ruby's zlib interface allows attackers to corrupt memory
DEBIAN-CVE-2026-27820
Old versions of the zlib Ruby interface can be tricked into overwriting memory with attacker-controlled data, causing unpredictable behavior. This issue affects Ruby applications using zlib for compre...
fio v3.41 Crashes When Parsing Malformed Job Files
DEBIAN-CVE-2026-30656
A security issue in fio v3.41 can cause the program to crash if it encounters a specific type of malformed job file. This could potentially be exploited by an attacker to disrupt fio operations. To pr...
rootio-pypdf Allows Unauthorized File Access on Root Devices
ROOT-APP-PYPI-CVE-2026-33699
An issue in rootio-pypdf allows hackers to access files they shouldn't, which could lead to sensitive data being stolen. This affects Root devices, so it's essential to update the software to the late...
Apache Tomcat: Unauthenticated Remote Code Execution
ROOT-APP-MAVEN-CVE-2026-34500
Apache Tomcat's embedded core library has a security issue that allows unauthorized access to your system. This could potentially allow attackers to execute malicious code on your server without needi...
Apache Tomcat: Unauthorized Access to Server
ROOT-APP-MAVEN-CVE-2025-49124
A security update has been released for Apache Tomcat that fixes a vulnerability that could allow an attacker to access your server without a password. This affects systems using Apache Tomcat, and it...
Apache Tomcat: Unauthenticated Data Exposure Through Unvalidated Input
ROOT-APP-MAVEN-CVE-2025-48988
Apache Tomcat's catalina package has a security issue that could allow an attacker to access sensitive data without being authenticated. This could lead to unauthorized access to your website or appli...
Apache Tomcat Embedded Core Software Can Be Hijacked by Attackers
ROOT-APP-MAVEN-CVE-2026-24734
Apache Tomcat Embedded Core software has a security weakness that could allow hackers to take control of a server. This affects systems using certain versions of the software. Update to a patched vers...
Apache Tomcat Core Has a Password Exposure Risk
ROOT-APP-MAVEN-CVE-2026-34487
Apache Tomcat is a widely used server software. A recent update fixed a critical issue where passwords might be exposed to unauthorized access. Update to the latest version to protect sensitive inform...
Apache Tomcat: Unauthorized Access to Internal Server Configuration
ROOT-APP-MAVEN-CVE-2026-34483
A security update has been released for Apache Tomcat, which could allow an attacker to access sensitive server configuration. This affects users who have not updated their Tomcat software. To fix the...
Apache Tomcat Core Update Needed to Prevent Data Exposure
ROOT-APP-MAVEN-CVE-2026-25854
A security patch has been released for Apache Tomcat, a popular web server software. This patch fixes a vulnerability that could allow unauthorized access to sensitive data. Update to the latest versi...
Apache Tomcat: Unauthenticated Code Execution via Malicious HTTP Request
ROOT-APP-MAVEN-CVE-2026-24880
Apache Tomcat users should update to a patched version to prevent an attacker from executing arbitrary code with elevated privileges via a specially crafted HTTP request. This vulnerability can lead t...
Apache Tomcat: Unpatched Servers May Be Hacked
ROOT-APP-MAVEN-CVE-2025-61795
Apache Tomcat servers may be vulnerable to a security weakness that allows hackers to break in. This issue affects servers using a specific version of Apache Tomcat, and it's recommended to update to ...