Reading the observatory store…
Reading the observatory store…
Unverified
Version-based matches are potential exposures, not confirmed vulnerabilities.
Every row below carries the confidence of the version match and the evidence that produced it. A low-confidence match means the version string was inferred, not read.
The contract defines no filter parameters for GET /vulnerabilities, so this view sends pagination only.
| Identifier | Severity | CVSS | Product | Asset | Summary | Evidence | Match | Status | Detected |
|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-94057 | medium | 4.0 | Exim 4.100 | 103.250.133.231 | Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejec… | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:45 UTC 25m ago |
| CVE-2026-94056 | high | 7.5 | Exim 4.100 | 103.250.133.231 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory. | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:45 UTC 25m ago |
| CVE-2026-94055 | low | 3.7 | Exim 4.100 | 103.250.133.231 | Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:45 UTC 25m ago |
| CVE-2026-94054 | high | 7.0 | Exim 4.100 | 103.250.133.231 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:45 UTC 25m ago |
| CVE-2025-14180 | high | 7.5 | PHP 8.1.34 | 103.233.58.171 | In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver wit… | {"match_reason":"keyword match on \"PHP 8.1.34\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2025-14178 | medium | 6.5 | PHP 8.1.34 | 103.233.58.171 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_… | {"match_reason":"keyword match on \"PHP 8.1.34\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2025-14177 | high | 7.5 | PHP 8.1.34 | 103.233.58.171 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak un… | {"match_reason":"keyword match on \"PHP 8.1.34\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2026-94057 | medium | 4.0 | Exim 4.100 | 103.233.58.171 | Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejec… | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2026-94056 | high | 7.5 | Exim 4.100 | 103.233.58.171 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory. | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2026-94055 | low | 3.7 | Exim 4.100 | 103.233.58.171 | Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2026-94054 | high | 7.0 | Exim 4.100 | 103.233.58.171 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2026-94057 | medium | 4.0 | Exim 4.100 | 103.233.58.13 | Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejec… | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2026-94056 | high | 7.5 | Exim 4.100 | 103.233.58.13 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory. | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2026-94055 | low | 3.7 | Exim 4.100 | 103.233.58.13 | Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2026-94054 | high | 7.0 | Exim 4.100 | 103.233.58.13 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2026-94057 | medium | 4.0 | Exim 4.100 | 36.253.137.4 | Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejec… | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2026-94056 | high | 7.5 | Exim 4.100 | 36.253.137.4 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory. | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2026-94055 | low | 3.7 | Exim 4.100 | 36.253.137.4 | Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2026-94054 | high | 7.0 | Exim 4.100 | 36.253.137.4 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. | {"match_reason":"keyword match on \"Exim 4.100\"","note":"version-string match only; not a confirmed exposure","observe… | medium | potential · unverified | 22 Sep 2026 05:44 UTC 25m ago |
| CVE-2025-53020 | high | 7.5 | Apache HTTP Server 2.4.63 | 103.214.0.50 | Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are… | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.63\"","note":"version-string match only; not a confirmed exp… | medium | potential · unverified | 22 Sep 2026 04:26 UTC 2h ago |
| CVE-2025-49812 | high | 7.4 | Apache HTTP Server 2.4.63 | 103.214.0.50 | In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack… | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.63\"","note":"version-string match only; not a confirmed exp… | medium | potential · unverified | 22 Sep 2026 04:26 UTC 2h ago |
| CVE-2025-23048 | critical | 9.1 | Apache HTTP Server 2.4.63 | 103.214.0.50 | In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session re… | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.63\"","note":"version-string match only; not a confirmed exp… | medium | potential · unverified | 22 Sep 2026 04:26 UTC 2h ago |
| CVE-2024-47252 | high | 7.5 | Apache HTTP Server 2.4.63 | 103.214.0.50 | Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters … | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.63\"","note":"version-string match only; not a confirmed exp… | medium | potential · unverified | 22 Sep 2026 04:26 UTC 2h ago |
| CVE-2024-43394 | high | 7.5 | Apache HTTP Server 2.4.63 | 103.214.0.50 | Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expr… | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.63\"","note":"version-string match only; not a confirmed exp… | medium | potential · unverified | 22 Sep 2026 04:26 UTC 2h ago |
1–24 of 24 matches/page 1 of 1