Threats

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

46,314 CVEs · 1,734 known exploited · CVE data updated 46 min ago · EPSS 5 hours ago

163 results · page 1 of 9 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
8.7 high CVE-2026-74891 jahlives openssl_encrypt openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data. 0.52% 17 Aug 2026
9.3 critical CVE-2026-81696 jahlives openssl_encrypt openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users. 0.25% 27 Aug 2026
9.3 critical CVE-2026-81695 jahlives openssl_encrypt openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape sequences to repaint terminal output and forge authenticity verification blocks. 0.25% 27 Aug 2026
8.7 high CVE-2026-81688 jahlives openssl_encrypt openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the password to confirm guessed plaintexts offline or fingerprint identical plaintexts across separately-encrypted files. 0.27% 27 Aug 2026
9.3 critical CVE-2026-74895 jahlives openssl_encrypt openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules. 0.68% 17 Aug 2026
9.3 critical CVE-2026-74880 jahlives openssl_encrypt openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access. 0.56% 17 Aug 2026
8.7 high CVE-2026-81693 jahlives openssl_encrypt openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause denial of service through out-of-memory conditions. 0.49% 27 Aug 2026
8.7 high CVE-2026-81703 jahlives openssl_encrypt openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen plaintext with false integrity verification. 0.22% 27 Aug 2026
8.7 high CVE-2026-81691 jahlives openssl_encrypt openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to achieve full keyserver account takeover. 0.27% 27 Aug 2026
9.3 critical CVE-2026-74889 jahlives openssl_encrypt openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks. 0.35% 17 Aug 2026
8.7 high CVE-2026-74873 jahlives openssl_encrypt openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords. 0.32% 17 Aug 2026
9.3 critical CVE-2026-74899 jahlives openssl_encrypt openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands. 0.75% 17 Aug 2026
7.1 high CVE-2026-74881 jahlives openssl_encrypt openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them. 0.36% 17 Aug 2026
9.3 critical CVE-2026-74901 jahlives openssl_encrypt openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection. 0.40% 17 Aug 2026
8.7 high CVE-2026-74893 jahlives openssl_encrypt openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver and telemetry APIs. 0.45% 17 Aug 2026
8.7 high CVE-2026-74892 jahlives openssl_encrypt openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication. 0.51% 17 Aug 2026
9.3 critical CVE-2026-81698 jahlives openssl_encrypt openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing shell commands that execute when users copy the printed CLI block into a shell. 0.43% 27 Aug 2026
8.7 high CVE-2026-74882 jahlives openssl_encrypt openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified. 0.17% 17 Aug 2026
8.7 high CVE-2026-81721 jahlives openssl_encrypt openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily large Argon2, scrypt, or balloon KDF parameters to exhaust system memory and crash the process without authentication. 0.58% 27 Aug 2026
9.3 critical CVE-2026-81680 jahlives openssl_encrypt openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added. 0.20% 27 Aug 2026